RAZIBINTERNET INDEX Suggest a resource

Email privacy

How to send sensitive files without losing control of the copy

Choose a suitable sharing method, verify the recipient, remove unnecessary details and manage access after sending a sensitive document.

A sensitive file can end up in the wrong hands without any complicated attack. An address selected from autocomplete, a folder shared with too many people or a forgotten public link can be enough.

Before choosing an encryption feature, work out what the recipient needs and how they are expected to receive it. A university upload portal, a company's approved document system and a personal message are different situations. The most elaborate method is not useful if the recipient cannot open it or is not allowed to use it.

Keep the original document unchanged in a secure place. Prepare a separate delivery copy so you can remove unnecessary information without damaging the record you need to retain.

Decide whether the file needs to be sent at all

Ask what information the recipient actually requires. A whole statement or complete identity scan may contain details unrelated to the task. A requested date, page or reference may sometimes be sufficient, but confirm that with the recipient rather than guessing.

Do not remove information required for an official application or alter a document so it becomes misleading. Ask whether a redacted copy is accepted and which fields must remain visible.

For a document you are allowed to reduce, use proper PDF redaction rather than covering text with a drawing. For an editable document, review comments, revisions and document properties before creating the delivery copy.

Smaller disclosure is useful even when the transfer method is strong. A file that never contains an unnecessary account number cannot expose that number through a later forwarding mistake.

Prefer the recipient's verified upload route

An official portal can give the recipient a familiar way to associate the file with the correct case or application. Reach it through the organization's known website, not an unexpected message that happens to contain its logo.

Check the accepted file format, size limit and document naming instructions before preparing the upload. If the portal belongs to a third-party processor, confirm the relationship through the institution's own guidance.

Do not send a second copy by email merely because the portal does not immediately show a response. Save the submission confirmation and follow the stated support process.

For education paperwork, the university application privacy guide explains how to keep a document list and check requests without creating unnecessary copies.

A link can be restricted to particular people or available to anyone who receives it. Those are very different permissions, even if the URL looks equally long and unguessable.

Choose the specific recipient and the least access they need. Reading a document does not usually require permission to edit it. Check whether the containing folder grants broader access than the individual file.

Google's sharing controls describe restricted access, removal and folder-related permissions. The exact controls vary by service, account and plan, so inspect the resulting access list rather than relying on a remembered default.

Where available, use an appropriate expiry date. Otherwise, add a reminder to remove the share when the task is complete. Expiration limits later access through the service; it does not erase copies already made by a recipient.

Understand what a confidential-message feature does

A mail feature called confidential, secure or protected may control access without providing every protection you expect. Read what it covers before using the label as reassurance.

Gmail's confidential-mode documentation describes expiry and revocation controls, while explicitly warning that recipients can still take screenshots or photographs. Those limitations matter when the file contains something that would be damaging if copied.

For highly sensitive work material, use your organization's approved method and ask its support team when the requirement is unclear. Do not improvise a consumer sharing system around an existing security policy.

End-to-end encryption also does not make the recipient trustworthy or protect a file after they open it on an insecure device. Decide who should receive the information before concentrating on how it travels.

Use a password-protected file only with a workable plan

If the agreed method is an encrypted file, choose software that actually encrypts its contents and a format the recipient can open. A PDF's editing restriction is not automatically the same thing as encryption that requires a password to read it.

Use a strong, unique password. Send it through a separately verified channel rather than placing it in the same message as the attachment. That separation helps only if the second route is genuinely under the intended recipient's control.

Run a harmless test file first when the recipient has not used the method before. Confirm that it opens in their approved software, then prepare the real delivery copy.

Avoid a complicated archive that forces the recipient to install an unknown application or bypass a security warning. Compatibility should be resolved before the sensitive file is involved.

Inspect the last screen before sending

Check the full recipient address, not just the display name. Remove unnecessary copied recipients and avoid replying inside a long thread that contains unrelated people or attachments.

Open the exact file attached to the draft. Verify the page count, visible content, filename and any redaction. A clean copy sitting beside the original is easy to confuse with the original in an upload dialog.

Keep the subject line and message body modest. A carefully protected attachment loses some value if the subject includes the same private identity number. The filename checklist covers another easy place to overlook unnecessary details.

A useful message can simply identify the task, name the attachment and explain the agreed access method. There is no need to repeat every sensitive field in the email.

Close the sharing loop

Keep the sent record or portal receipt you need for the task. Confirm receipt through the usual channel when appropriate, then remove temporary links and access when their purpose ends.

Do not delete the only evidence needed for an application or dispute simply to make the folder look tidy. Separate required records from temporary working copies.

If you send the wrong file or use the wrong recipient, revoke access where possible and contact the appropriate recipient or support team promptly. Do not assume an email recall or deletion request removes every copy.

The File Upload directory lists related services, but choose a provider based on its actual controls and the sensitivity of your material. The safest practical workflow is the one that sends the right information to the right person and has a clear end to the sharing period.

Sources and further reading

  1. Google Drive Help: Stop, limit, or change sharing Consulted 28 September 2026.
  2. Gmail Help: Send and open confidential emails Consulted 28 September 2026.

Consult the linked documentation for current details. Settings, availability and interface labels may change.

Spotted something that needs correcting? Send a correction with this article’s title and the relevant source.