Documents and screenshots: remove sensitive data before sharing

A black rectangle can hide information without removing it. Prepare a sharing copy, then verify the actual file your recipient will receive.

Documents and note taking during a discussion Illustration · fictional scene

Six repeatable checks

  1. Minimise the content

    Define what the recipient needs to understand. Work on a copy; keep the original in an authorised location.

  2. Find identifiers

    Review names, addresses, references, browser tabs, notifications and filenames, not just the centre of the screenshot.

  3. Remove the underlying content

    Apply actual redaction to PDFs. An overlaid object or a hidden spreadsheet row does not remove its content.

  4. Inspect hidden information

    Check authors, comments, revisions and attachments with format-appropriate tools. Inspect again after exporting.

  5. Verify the final copy

    Reopen the exported file. Try searching and copying text that should be removed; review every page and its readability.

  6. Check sharing access

    Verify recipients, permissions and access duration. Test the link while signed out; record the exact approved version without repeating removed data.

Review record to retain

  • Reviewed file and version
  • Types of information removed
  • Tests on the exported file
  • Recipients, permissions and reviewer

This is a working method, not a statement of compliance. Adapt the scope and document exceptions.

Situations and suitable checks

On a small screen, scroll the table horizontally. With a keyboard, focus the table and use the arrow keys.

SituationWhat it indicatesUseful verification
A black rectangle hides a name, but search still finds the text.Visual masking may leave the underlying data intact.Apply actual redaction and test the exported file.
The preview looks clean, but comments or attachments remain.Information remains outside the visible page.Inspect the source file and every export intended for sharing.
The link works without signing in.Distribution may exceed the intended audience.Restrict access and test the link while signed out.
The document changed after approval.The earlier approval covers a different version.Recheck the final version and identify the approved file precisely.

Fictional example

A fictional team plans to share a project report and screenshot. Both contain a reviewer's name and an internal reference that the recipient does not need.

Work on a copy, remove unnecessary details and hidden data, then export. A second reviewer downloads that version, searches for removed terms and tests text copying. The record describes removed information categories without reproducing confidential values.

Acceptance criteria

  • The recipient, sharing purpose and necessary information are defined.
  • The downloaded version passes text, hidden-data and access checks appropriate to its format.
  • The approved version, reviewer and access conditions are recorded.

Practical questions

Is blurring enough?

Do not treat it as a guarantee. Remove information from the distributed copy and verify the final result.

Does PDF export remove everything?

No. Check the exported content and hidden information; capabilities vary between applications.

Should the original be deleted?

Follow the authorised retention policy. Separate the protected original from the sharing copy.

Is a preview enough to approve redaction?

No. Download the actual shared file and check its contents, search, text copying and relevant hidden data. The preview may differ from the export.

How can evidence be kept without copying sensitive data?

Record the information category removed, checks performed, version and reviewer. Avoid reproducing removed values in screenshots or widely accessible tickets.

Official references