Sending sensitive documents: a twelve-point checklist

Passports, payslips, contracts and medical letters get sent with about as much thought as a holiday photo. Run this before you attach anything, and know what to do in the first ten minutes if it goes wrong.

4 min read

Passports, payslips, contracts, medical letters, a spreadsheet of staff details. These get sent constantly, usually by email, usually with no more thought than a holiday photo — and they are exactly the files where a mistake is expensive and permanent.

This is a checklist rather than an essay. Run it before you send.

Before you attach anything

1. Does this need to be sent at all? The safest file is the one that stayed where it was. Can the recipient verify what they need by looking at something they already have, or by being told a number rather than shown a document?

2. Are you sending more than was asked for? This is the most common and most avoidable error. Someone asks for proof of address and receives twelve months of bank statements showing every transaction. Send the single page, redacted where it can be.

3. Is the recipient who you think? Invoice fraud works because a plausible email arrives from a lookalike address at exactly the moment one was expected. If the request arrived by email and involves money or identity, confirm it through a channel you chose — a number you already had, not one in the message.

4. Does the file contain more than it appears to? Documents carry metadata: author names, revision history, comments, tracked changes, and in the case of photos, GPS coordinates. Spreadsheets carry hidden columns and other sheets. A PDF exported flat is safer than the original document.

When you send

5. Encrypt end to end. The file should be sealed before it leaves your machine, so the service storing it holds bytes it cannot read. If your provider can preview the file in a dashboard, it is not this.

6. Split the key from the link. For genuinely sensitive material, do not let one message be enough. Send the link by email, the key by phone or a different app. Anyone who intercepts one has nothing.

7. Set the shortest workable expiry. A day is right for most identity and financial documents. If it is missed, send another — that costs seconds, and it means the link is not still live next year.

8. One recipient per message. Never a shared inbox, never a group, never CC. If three people need it, send three transfers, so the record shows who received what.

9. Say what you are sending and what you expect. A one-line message — what the file is, what it is for, and that the key is coming separately — prevents the recipient assuming it is phishing and ignoring it, which happens more than you would think.

Afterwards

10. Confirm it arrived. Download counts and delivery receipts turn "I sent it" into something you can check. More downloads than there are recipients is worth a question.

11. Revoke when the job is done. The moment the mortgage application is submitted or the contract is signed, kill the link. Do not leave it to the expiry.

12. Clean up your own copies. The version in your Sent folder, the export on your desktop, the copy in Downloads. The transfer being deleted does not help if the file is still in three places on your laptop.

What to avoid

  • The password in the same message as the file. It protects against nothing and gives a false sense that it does.
  • "Anyone with the link" on a permanent cloud folder, created for one hand-off and never reviewed again.
  • Messaging apps for identity documents. The transport may be encrypted; the copy sitting in the other person's photo roll, backed up to their cloud account, is the problem.
  • Screenshots of documents. They strip nothing, add device metadata, and are usually less legible than the original.
  • Sending the whole folder because finding the one file was tedious.

If it goes wrong

Assume speed matters more than embarrassment.

  1. Revoke the transfer immediately. If the bytes are deleted, the link is worthless from that moment on regardless of who has it.
  2. Tell the person whose data it was. Quickly, and specifically about what was exposed.
  3. Check whether it was opened. A download count is the difference between a near miss and an incident.
  4. If it involves other people's personal data, there may be a reporting obligation with a deadline measured in hours, not weeks. Check rather than assume.

The reason expiry and revocation matter so much for this category is that they are the only controls that still work after the mistake. Everything else has to be right in advance.

Related: how to send files securely covers the general case, end-to-end encryption explained covers what sealing does and does not do, and our privacy policy states what is stored and for how long.