An illustration of a typical result. No real file, name or location is used.
Before — what you would be sending
subject-access-response.pdfPDF
Authora.whitfield
CompanyNorthgate Partners LLP
Comments and annotations5 found
After cleaning
subject-access-response-clean.pdfPDF
Authorremoved
Companyremoved
Comments and annotationsremoved
No transfer to a third party, because the file never leaves the browser.
Intent does not change the classification
GDPR defines personal data by what it is, not by whether it was disclosed deliberately. An author name, a device identifier and a set of coordinates embedded in a shared file are personal data being processed, and they fall inside the same obligations as any field in a database.
Where it tends to matter in practice
Files published on a website. Documents attached to emails leaving the organisation. Photographs of staff or premises. Data shared with a processor or a partner. Responses to subject access requests, which are frequently exported as documents carrying the properties of whoever compiled them.
Transfers and third-party tools
Uploading a document to an online processing service is itself a transfer to a third party, and possibly out of the region. That is a separate assessment to make before using any cloud-based cleaning tool. Processing entirely in the browser avoids the question, because nothing is transferred.
Not legal advice
This is a description of a common gap, not a compliance opinion. Your data protection officer or counsel should decide what your obligations actually are.
In practice
Where this surfaces in practice
The recurring case is a subject access request. An organisation compiles a response, exports it as a document, and sends it. The export carries the name of the employee who compiled it, the organisation's name, and how long the work took. None of that was part of the response, and all of it is personal data about a third party disclosed to the requester.
Photographs of premises and staff
Images published on a company site are frequently taken by staff on their own phones. The published files then carry the coordinates of the office and the device details of an employee. It is a small disclosure individually and a systematic one at scale, and it is entirely avoidable with a single step in the publishing process.
Making it a process rather than a rule
A policy saying documents should be checked achieves very little. What works is putting the check where the file leaves: in the export step, in the publishing workflow, or in whatever tooling handles outbound attachments. The organisations that do not have this problem have automated it, not trained for it.
Common questions
Is EXIF data personal data under GDPR?
Where it identifies an individual, directly or in combination with other information, it generally falls within the definition. Take advice on your specific case.
Does uploading a file to a cleaning tool count as processing?
It involves transferring the file to a third party, which typically requires its own assessment. Processing locally in the browser avoids the transfer.
Is this page a compliance tool?
No. It is a free utility. Treat it as one input to a process your own advisers define.