A quick PDF privacy review can catch information that metadata removal alone will never see. Use this checklist before publishing, emailing or uploading an important document.

1. Check document metadata

Inspect title, author, subject, keywords, creator, producer, dates, XMP and document identifiers. Remove or edit fields that are accidental, outdated or unnecessary for the recipient.

2. Read the visible pages

Look for names, email addresses, phone numbers, addresses, customer identifiers, internal project codes, signatures and screenshots. If visible information should not be shared, use a proper redaction workflow rather than simply drawing a shape over it.

3. Review annotations and form fields

Comments, sticky notes, highlights and form values can contain information that is not obvious during a quick page scan. Flattening or deleting annotations may be appropriate depending on the workflow, but keep an original copy first.

4. Check attachments and links

PDFs can contain embedded files and external links. Make sure an attachment was not included accidentally and that links do not point to internal resources that recipients should not access.

5. Review the file name

The filename itself is metadata from a practical privacy perspective. Avoid names that include personal identifiers, internal case numbers or phrases such as final_secret_clientname.pdf when a neutral public filename would work.

6. Verify signatures and permissions

If a PDF is digitally signed, modifying it may invalidate the signature. Confirm whether the signed original must be preserved and distributed unchanged.

7. Open the final copy as a recipient

After cleaning, editing, splitting or merging, close the source file and open only the final copy. Check its properties and visible content again. This simple last step catches many workflow mistakes.

Metadata is only one layer

A good PDF sharing workflow combines metadata review, visual review and appropriate redaction when sensitive content is involved.