A photo of an identifiable person, a scanned ID, a payslip or a medical document is personal data under the GDPR. Uploading it to an online converter is not a neutral technical step: it is a disclosure of that data to a third party.
On paper, that disclosure has to be governed. The provider becomes a processor, which calls for a data processing agreement (Article 28). If its servers sit outside the EU, an international transfer is involved, which needs its own safeguards (Chapter V). And the retention period is whatever the provider's terms say — assuming anyone read them. In practice, none of this happens when an employee converts a file on the first site returned by a search engine.
Local conversion removes the question rather than answering it. Pixloc runs entirely in your browser, using its built-in image engine. No file, no filename and no metadata is transmitted, so there is no processor to contract with, no transfer to safeguard, and no retention period to audit — there is simply no disclosure. You can verify it in three seconds: disconnect from the network and convert anyway.
Because the whole site is static, it can also be published on an internal network or intranet, where it keeps working with no outbound connection at all. If that is useful to your organisation, write to [email protected].
This page explains how the tool works; it is not legal advice. Your DPO or counsel remains the right person to assess your specific obligations. Related conversions: HEIC to JPG, PNG to JPG.