The best way to share confidential documents (it depends what's in them)

    · 7 min read

    The best way to share confidential documents is the one where you can control who opens the file and take that access away later. For most people that means a restricted link, not an email attachment. An attachment is a copy. Once it's sent, it sits in their inbox and goes wherever they forward it, and you have no say in any of that.

    The catch is that "confidential" covers a lot of ground. A salary letter, a signed NDA, a set of management accounts and an acquisition data pack all need different handling, and treating them all the same is how people end up either over-engineering a simple send or under-protecting something that really matters.

    Why email attachments are the weak spot

    I'm not going to pretend I've never attached something sensitive to an email. Years of sending decks, reports and pricing in growth roles means I've done it more times than I could count, usually because I was in a hurry and it was the path of least resistance.

    The problem with attachments isn't really that email is insecure in transit. Most business email is encrypted between servers these days. The problem is everything that happens after it arrives. You can't unsend it. You can't see whether it was opened. If the recipient forwards it to a colleague, or their account gets compromised a year later, your document goes with it.

    For low-stakes files that's fine. For anything you'd be uncomfortable seeing in the wrong inbox, it's the wrong tool. I've written more about the specific case of sending signed documents via email if that's what brought you here.

    Match the method to what's in the file

    The way I think about it is to ask two questions. What happens if this ends up with the wrong person? And do I need it back?

    Personal or HR documents: password-protected PDF

    Say you're sending a contractor their signed agreement with bank details on it. It's sensitive, but it's going to one person who needs to keep it. A password-protected PDF is fine here. Acrobat and most PDF tools can encrypt a file so it won't open without the password.

    The part people skip is sending the password separately. If the password is in the same email as the PDF, you've locked the door and taped the key to it. Text it or read it out on a call.

    The limitation is that once they've opened it, they have a copy forever. That's fine for their own contract. It's not fine for your pricing model.

    Deals and anything legally sensitive: a virtual data room

    If you're selling a business, raising a large round or handling a legal dispute, use a proper virtual data room. They're built for hundreds of documents shared with several parties, with permissions per folder and a record of who viewed what. They're also expensive and overkill for anything smaller. If you're asking whether you need one, you probably don't yet. The moment lawyers on both sides are involved, you will.

    A few habits that matter more than the tool

    Whichever method you pick, most leaks come from people rather than software. Check the recipient address twice before you send anything sensitive, because autocomplete is how most mis-sends happen. Share the least you need to: if they only need page four of the accounts, send page four. And when a project ends, go back and revoke the links. Nobody does this, and it's the easiest win on the list.

    If you work in a regulated area, your organisation's own policies come first. For UK businesses handling personal data, the ICO's guidance on security is worth a read, and it's more readable than you'd expect.

    FAQ

    What is the safest way to send confidential documents?

    The safest way to send confidential documents is through a restricted link where only named people can open the file and you can revoke access later. For the highest-stakes material, like M&A documents, a virtual data room adds audit trails and granular permissions. Email attachments are the least safe option because you lose control of the copy the moment you hit send.

    Is it safe to email a password-protected PDF?

    It's reasonably safe if you send the password through a different channel, like a text or a phone call. The encryption is only as good as the password and how you share it. Remember that once the recipient opens it, they have an unprotected copy you can't take back.

    Can I share confidential documents with Google Drive?

    Yes, as long as you share with specific people rather than "anyone with the link". Restricting access to named accounts stops forwarded links from working for anyone else. On paid Workspace plans you can also set an expiry date on someone's access.

    How do I stop someone forwarding a confidential document?

    You can't completely stop someone forwarding a file once they've downloaded it, which is why links beat attachments. With a restricted or trackable link, a forwarded copy either won't open for the new person or you can revoke the link entirely. Some tools also add watermarks to discourage sharing screenshots.

    If proposals and reports are most of what you're sending, the share a PDF as a link page covers how LiveDocument handles it, or you can see it at livedocument.com.

    About the Author

    Cameron James

    Cameron is the founder of LiveDocument. He writes about sharing documents, PDFs, decks and contracts, and why pairing a video walkthrough with a document beats sending it cold.