True story.
A freelance designer I know was compressing client
contracts using a popular online PDF tool.
Invoices. NDAs. Client personal data.
All uploaded to a third-party server she'd never
heard of, in a country she didn't know, with a
privacy policy she'd never read.
Under GDPR Article 28, she was the data controller.
The PDF tool was an unauthorized data processor.
That's a violation — even if nothing went wrong.
The Problem Nobody Talks About
Every "free" online tool has a business model.
If you're not paying, your data is the product.
For tools processing files:
- Your PDF goes to their server
- Your image gets stored temporarily (or permanently)
- Your "private" document passes through their infrastructure
For European users and anyone handling EU citizen data —
this is a GDPR landmine hiding in plain sight.
What Client-Side Processing Actually Means
Browser-based processing means the tool runs
entirely in JavaScript inside your browser tab.
Your file:
- Gets read by your browser (not a server)
- Gets processed in browser memory
- Gets downloaded back to you
Zero network requests for the actual file data.
Zero server storage.
Zero third-party data processing.
The Technical Reality
Here's what a client-side PDF compressor looks like:
// File never leaves the browser
const file = event.target.files[0];
const arrayBuffer = await file.arrayBuffer();
// Processing happens in browser memory
const compressed = await compressPDF(arrayBuffer);
// Download directly to user's device
const blob = new Blob([compressed]);
const url = URL.createObjectURL(blob);
Compare this to server-side processing:
// File uploaded to external server
const formData = new FormData();
formData.append('file', file);
// Your file travels across the internet
await fetch('https://their-server.com/compress', {
method: 'POST',
body: formData // 👈 GDPR problem here
});
The difference is one network request.
The legal difference is enormous.
What I Built
I built OmniWebTool (omniwebtool.com) specifically
to solve this.
30+ tools. All client-side. All free.
- PDF compressor — files never leave your browser
- Image compressor — same principle
- Password generator — generated locally, never transmitted
- VAT Calculator — EU-27 rates, no data sent anywhere
- IBAN Validator — validated client-side using MOD 97
Tech stack:
- Next.js 14 (954 static pages, 4 languages)
- All tool logic in client-side TypeScript
- Zero API calls for file processing
- Cloudflare Workers for edge delivery
- Cookiebot CMP for GDPR consent
The GDPR Argument for Client-Side Tools
Under GDPR:
- Article 25: Privacy by design and default
- Article 32: Appropriate technical measures
- Article 28: Data processor agreements
Client-side processing satisfies all three
simultaneously. No data processor agreement needed
when there's no data processor.
This is why browser-based tools aren't just
a nice feature for privacy-conscious users —
they're the legally correct architecture for
anyone handling EU citizen data.
The Designer's Outcome
My friend switched to OmniWebTool.
No more unauthorized data processors.
No more GDPR exposure.
Same result — compressed PDF — in the same time.
The only difference: her files stayed on her computer.
omniwebtool.com — free, GDPR-compliant,
browser-based tools in EN/DE/FR/ES
Built by Ovrion (ovrion.xyz)
What tools do you use that you've never checked
the privacy policy for?
Top comments (0)