GDPR and PDF tools: why browser-based processing matters
This is not legal advice, but the shape of the issue is straightforward and worth understanding before you drop a document containing someone else's personal data into a website.
Drag and drop here, or choose from your device.
Up to 50 MB per file. Files are processed in your browser.
Full options and FAQs on the PDF Metadata Editor page.
The processor problem
Under the GDPR, if your organisation controls personal data and a third party handles it on your behalf, that third party is a processor. Processors normally need a written agreement, a lawful basis, and a place in your records of processing activities.
Uploading a document full of names, addresses or salary details to an online converter creates precisely that relationship, informally and usually without anyone's knowledge. The risk is rarely a breach; it is an unrecorded transfer nobody approved.
Where local processing changes the analysis
- If the file never leaves the device, no third party receives the data, so no processor relationship is created by the tool.
- There is no international transfer to assess, because nothing crosses a border.
- There is no retention period to document and no deletion request to make.
- The data stays inside infrastructure your organisation already controls and has already assessed.
What still needs attention
Local processing is not a blanket exemption. The device itself must be secure, downloads land in a folder that may be synced to cloud storage, and the website still sets cookies and may serve advertising — all of which belong in your own privacy notice.
Metadata deserves a specific mention: PDFs routinely carry the author's name, their software, and the original file path from their machine. Strip that before publishing a document externally.
Step by step
- 1Establish whether the document contains personal data about identifiable people.
- 2If it does, avoid tools that upload, or get the transfer approved through the proper channel.
- 3Prefer browser-based processing so no third party receives the file.
- 4Check where your downloads folder syncs to before saving sensitive output.
- 5Use the tool below to remove author and software metadata before sharing externally.
Frequently asked questions
- Does browser-based processing make us automatically compliant?
- No. It removes one specific risk — an unassessed transfer to a third-party processor. Your own storage, retention and access controls still apply.
- Does the website see the contents of my file?
- No. The page contains code that runs on your device; the file is opened locally and never transmitted, which is why the tools work offline once loaded.
- What personal data hides in PDF metadata?
- Typically the author's name, the creating application, creation and modification timestamps, and sometimes the full file path from the original computer.