· by L'équipe EnvoiFaxGratuit
Faxing while working from home: a secure home setup
How to send and receive faxes from home without exposing documents: equipment, workstation, network, paper destruction and GDPR rules.

Short answer: faxing from home is neither forbidden nor inherently risky — it's the environment around the fax that causes problems. A confidential document sent from a shared living room passes through four leak zones in succession, all of which the corporate office neutralised without anyone giving it a thought: a screen visible to third parties, a home Wi-Fi network administered by no one, a paper tray left lying around, and a municipal recycling bin where the originals end up. The countermeasure comes down to four moves: switch to an online fax service (no document ever sits in a machine's memory again), lock the session and the screen, isolate the work computer from the family network, and physically destroy every intermediate sheet of paper. Add a traceability rule on top: every transmission must produce a confirmation report archived in the same place as if it had been sent from head office. Remote work creates no exception to the GDPR or to professional confidentiality — it simply shifts the burden of proof onto you.
What the office was doing for you without saying so
In professional premises, a dozen protections exist by design. The fax machine sits in a room that is locked at night. The network is administered, segmented, kept up to date. Confidential waste bins are collected by an approved provider that issues a certificate of destruction. Visitors are greeted, badged, escorted.
At home, those layers vanish all at once — and no one warns you. France's data protection authority, the Commission nationale de l'informatique et des libertés (CNIL), regularly points this out in its guidance on remote working: the employer remains the data controller, including for data handled on an employee's sofa. The self-employed professional, meanwhile, is directly responsible, with no safety net at all.
Fax deserves particular attention because it concentrates, almost by definition, the most sensitive documents: prescriptions, hospital discharge summaries, court filings, powers of attorney, bank statements. These are precisely the documents people still fax in 2026, precisely because they are sensitive.

The four leak zones of the home
| Zone | Concrete risk | Immediate countermeasure |
|---|---|---|
| Screen | Read by a partner, a child, a visitor, a video call | Privacy filter + automatic locking |
| Network | Shared router, connected devices, guests on the same SSID | Dedicated SSID or guest VLAN, employer VPN |
| Paper | Output tray, drafts, test pages | Cross-cut shredder, zero stock |
| Device | Unencrypted laptop, forgotten USB stick | Disk encryption, encrypted backups |
Step 1 — remove the physical fax machine from your home
This is the most counter-intuitive and the most effective piece of advice: do not install a fax machine at home.
A conventional fax machine keeps the last pages sent and received in memory. Some multifunction models even contain an internal hard drive where months of scans accumulate. If it breaks down, you hand that memory over to a repair technician. At the end of its life, you drop it off at the recycling centre. In both cases, you have lost control of documents for which you remain legally responsible.
Online fax removes the problem at the root: the document leaves your computer, travels encrypted to the platform, and it is the platform that handles conversion to the T.30 protocol on the telephone network side. Nothing sits in a cabinet in your hallway. Our complete guide to sending faxes online explains how it works end to end, and the list of available countries sets out which destinations are covered.
If your organisation nonetheless requires paper reception, opt for a virtual number with delivery by email: you only print what you genuinely need to handle. The topic is covered in detail in the article on receiving faxes without a machine.
Step 2 — make your screen unreadable to others
The first confidentiality incident in remote work is not a cyberattack: it's a pair of eyes.
Three measures are enough in the vast majority of cases.
Positioning. Back to the wall, screen facing away from the door and from windows overlooking the street or a neighbouring building. It costs nothing and eliminates 80% of the risk.
The filter. A screen privacy filter — that thin polarising sheet that blacks out the display beyond a thirty-degree viewing angle — turns a shared living room into an acceptable workspace. It comes in adhesive or magnetic versions for laptops; fitting takes about two minutes.
Locking. Windows + L, or Ctrl + Cmd + Q on macOS, should become as automatic a reflex as closing the bathroom door. In addition, set automatic locking to five minutes, not thirty.
If you share the room with other people on video calls, add a noise-cancelling headset with microphone: it stops you from reading out a social security number at the top of your voice to be heard over background noise. Sound confidentiality is the poor relation of remote work, even though a medical practice devotes entire partition walls to it.
Step 3 — separate the work network from the family network
Your ISP router generally hosts everything: the games console, the voice assistant, the connected vacuum cleaner, the school laptop and your work computer. Each of those devices is a potential way in.
The bare minimum, in order:
- Change the router's administration password — many are still set to the factory value printed on the back.
- Enable WPA3 (or WPA2-AES failing that) and permanently ban WEP and WPS.
- Create a separate guest SSID for connected devices and visitors, and put everything that isn't your work computer on it.
- Use your employer's VPN whenever you access internal resources, including a corporate fax web interface.
- Prefer cable: a USB-C Ethernet adapter and a simple RJ45 cable beat every Wi-Fi setting in the world for stability and discretion.
ANSSI, France's national cybersecurity agency, publishes a set of remote-working recommendations that covers these points and goes further on update management and the use of personal equipment; it is the reference to cite if your employer asks you to justify your setup.
A word on mobile tethering: it is often safer than the Wi-Fi in a coworking space or a hotel, because the cellular network is encrypted and you control the access point. For frequent travel, a high-capacity power bank avoids the dubious trade-off between finishing a transmission and keeping a signal.
Step 4 — treat paper as data
Faxing from home almost always generates paper: the original you scan, the cover page printed out of habit, the courtesy copy, the annotated draft.
The rule is simple: nothing goes into the recycling bin. Municipal waste sorting offers no confidentiality guarantee whatsoever; bins are put out on the pavement, opened, sometimes knocked over.
Get yourself a cross-cut document shredder rated at least P-4 under the DIN 66399 standard — its 4 mm by 30 mm particles are considered impossible to reconstruct by reasonable means. Level P-3, with strip cuts, remains acceptable for ordinary mail but not for health data or court documents. A manual-feed desktop model is enough for individual volumes; just check that it accepts staples, otherwise you'll spend your time removing them.
For scanning itself, a duplex sheet-fed document scanner is life-changing for anyone who faxes more than three documents a week: it produces a straight, high-contrast, usable PDF, whereas a smartphone photo gives skewed pages that the receiving fax machine will render illegible. The quality requirements for a legally usable scan are detailed in our article on digitising paper documents.

Interim storage, remote work's blind spot
Between the scan and the transmission, the file exists somewhere. Three precautions:
- Enable full-disk encryption (BitLocker on Windows Pro, FileVault on macOS, LUKS on Linux). Without it, a laptop stolen on a train gives everything away.
- Ban ordinary USB sticks. If removable media is essential, use a hardware-encrypted USB drive with a PIN code that wipes itself after a set number of attempts.
- Delete temporary files after sending, and empty the recycle bin. A "to fax" folder that piles up over six months is a dormant GDPR incident.
Step 5 — maintain the same traceability as at the office
This is the point most remote workers forget, and the one that costs the most in the event of a dispute.
A transmission sent from home must produce exactly the same evidential elements as one sent from head office:
- the timestamped transmission report, showing the number dialled, the page count and the status;
- the preview of the first page, which most services generate automatically;
- the exact PDF file that was transmitted, kept unmodified;
- a record of the sender's identity if several people share the account.
These items belong in the organisation's document management system, not in the "Downloads" folder of your personal computer. The question of retention periods and conditions is developed in the article on archiving faxes with evidential value, and that of the report's legal weight in does a fax count as evidence.
One practical detail: if your online fax service lets you choose the address for delivery receipts, point it at your work mailbox, never a personal address. A receipt landing in a consumer email account falls outside the employer's scope of responsibility and becomes very hard to produce three years later.
The special case of professions bound by confidentiality
Doctors, self-employed nurses, lawyers, notaries, chartered accountants: remote work suspends neither medical confidentiality (article L.1110-4 of the French public health code) nor lawyer–client privilege (article 66-5 of the Act of 31 December 1971).
Three additional requirements apply:
A dedicated room. Ideally with a door that closes. Failing that, a time slot when the room is genuinely empty, plus lockable storage — a lockable desk pedestal will do — for paper files between sessions.
Health data hosting. If health documents pass through a platform, the question of HDS certification (approved health data host) arises, regardless of where you are working from. The subject is developed in our article on medical faxing and health data.
Logging. Who sent what, when, to whom. It is the first thing a data protection officer will ask for after an incident, and the first thing you will be unable to reconstruct if you have been working from a shared account.
Frequently asked questions
Can my employer require me to install a fax machine at home?
They can ask you to carry out document transmission duties, but the equipment and its security are their responsibility, as with any work tool. In practice, the solution adopted is almost always access to a corporate online fax service rather than a physical machine, precisely to avoid scattering unmanaged hardware across employees' homes.
Does a fax sent from my home carry the same weight as one sent from the office?
Yes. A fax's evidential force depends not on where it was sent from but on the quality of the records kept: transmission report, content sent, consistency with the surrounding correspondence. A judge will weigh up all the indicators together. Location is only an unfavourable factor if it comes with degraded traceability — a personal account, no record on the employer's side, an untraceable file.
Can I use my personal all-in-one printer to scan work documents?
Technically yes, legally it is inadvisable without written approval. These devices often keep copies in memory, are updated irregularly and are reachable from the entire home network. If you have no choice, disable network access, wipe the memory after use and check your employer's policy.
Does remote work have to be declared in the record of processing activities?
Remote work is not in itself a processing activity, but it changes the security measures described in the record. The data controller must update the "security measures" section and, where applicable, the impact assessment when sensitive data is handled outside company premises. The CNIL treats this update as a routine obligation, not an exceptional formality.
What should I do if a confidential document has been seen by a third party at my home?
Treat it as a data breach: record the facts (date, document, person, circumstances), inform the data protection officer or your employer without delay, and let the organisation assess whether to notify the CNIL within 72 hours. Accidental viewing by a family member not bound by confidentiality is indeed a breach of confidentiality, even if the actual risk is low.
In summary
- No physical fax machine at home: online fax avoids any document memory outside your control.
- Neutralise the screen: positioning, privacy filter, automatic locking after five minutes.
- Separate the networks: guest SSID for connected devices, WPA3, employer VPN, Ethernet cable where possible.
- Treat paper as data: cross-cut shredder rated P-4 minimum, zero stock, never the recycling bin.
- Encrypt the device and delete intermediate files after sending.
- Keep the same traceability as at the office: transmission report, exact PDF, receipt sent to the work mailbox.
- Professions bound by confidentiality: dedicated room or lockable storage, HDS-certified hosting for health data, logging of every transmission.
Remote work does not weaken the value of your transmissions. It simply moves the confidentiality boundary from the office door to your front door — and that door is one you close yourself. For practical sending questions, our FAQ brings together the most requested answers.


