Online PDF tools at work: a rule you can defend
By the getPDF team · Published 11 October 2026
The short answer
A rule that holds up: sort files by what is in them, not by the tool. Public files may go to any tool. Internal files go only to tools IT has approved. Files with personal or client data never go to a tool that uploads them, unless the company has a data processing agreement with that vendor. A tool that provably runs on the device sends nothing, so it fits all 3 classes once IT has checked it.
This page is for both sides of the desk: the employee whose usual converter is suddenly blocked, and the admin who has to write the rule. It explains how such a rule works in practice; it is not legal advice.
Why IT blocks online PDF converters
Most online PDF tools work the same way: your browser uploads the file, their servers do the work, you download the result, and the server copy is deleted later. iLovePDF says within 2 hours; Smallpdf says after 1 hour for ordinary tasks (both checked on 11 October 2026). From the company’s side, 3 things go wrong with that model:
- Data leaves the network without a record. The upload looks like any other web traffic. Nobody in the company can later say which contract went where.
- Retention is a promise, not something IT can check. The deletion policy may be honest; backups, logs and mistakes are invisible from outside. In July 2024, Cybernews researchers found that 2 converter sites, PDF Pro and Help PDF, had left more than 89,000 uploaded files open in cloud storage, among them passports and contracts.
- The legal duty stays with the employer. Under the GDPR, the company is responsible for personal data it handles, including what an employee uploads to a free tool on a Tuesday afternoon. The GDPR guide explains the articles involved.
So the block is rarely about PDFs. It is about the upload.
The traffic-light rule
The rule below sorts by document, because that is what an employee can judge in a second. Paste the table into a company wiki as it is.
| Class | Examples | Allowed tools | Why |
|---|---|---|---|
| Green: public | Published brochures, price lists, forms downloaded from a public site, your own CV | Any tool, upload or not | Nothing in the file that is not public already |
| Amber: internal | Internal reports, draft offers, meeting minutes, anything marked internal | Approved tools only | Business data, but no personal data of others; leaking it hurts the company |
| Red: personal or client data | Contracts, payslips, HR files, CVs of applicants, medical or bank documents, anything with a name and a number | Never a tool that uploads, unless a data processing agreement covers it; tools that run on the device after IT has verified them | Personal data under GDPR; an upload makes the vendor a processor |
Two habits make the rule easier to keep. First, when unsure, treat the file as red. Second, shrink the problem: if only 1 page carries personal data, remove that page or redact it before any tool sees the file.
What “approved” should mean
An approved tool is one that meets 1 of 2 conditions, and IT can say which:
- Route A, a contract. The vendor signs a data processing agreement with the company (GDPR Article 28 requires one when a processor handles personal data for you), states where its servers are, and states how long files are kept. This is the route for cloud tools such as a company Acrobat or Microsoft 365 licence.
- Route B, nothing leaves the device. The tool processes files on the employee’s machine: an installed desktop app, or a web tool whose processing runs in the browser. There is no upload, so there is no file on someone else’s server to govern. IT verifies this once with the tests below instead of trusting the vendor’s wording.
A tool that is neither (free online converters with no agreement) stays limited to green files.
A 4-line policy to copy
- Public files may be processed with any PDF tool.
- Internal files may be processed only with tools on the approved list.
- Files containing personal data of customers, applicants or staff must not be uploaded to any service without a data processing agreement.
- Tools on the approved list either run entirely on the device (verified by IT) or are covered by a data processing agreement.
Short is the point. A policy people can recite gets followed; a 12-page one gets an exception request.
How IT verifies a local tool before approving it
A vendor saying “nothing is uploaded” is a claim. These 3 checks turn it into evidence, and none needs special software. The Wi-Fi off guide walks through each in Chrome, Edge, Firefox and Safari.
- The offline test. Open the tool, run it once on a test file so its engine loads, then disconnect the network and run it again on another file. A tool that uploads fails; a local tool finishes.
- The network panel. With the browser’s developer tools open on the Network tab, run the tool on a file of a known size, say 5 MB. No request should carry anything near that size away from the machine. On getPDF you see the page’s own files, the engine (
pdfium.wasm, 4.6 MB, about 2 MB as transferred) on the first file, and after the job 1 small POST to/api/countwith a body like{"tool":"compress-pdf","ok":true,"ms":"lt3s","mb":"lt5"}. - The content security policy. The site’s response headers say which addresses the page may connect to. getPDF sends
connect-src 'self' blob: data:, so the browser itself refuses connections to any other host. A technical reviewer can read it in the network panel or with 1 line:
curl -sI https://getpdfs.app/ | grep -i content-security-policy
On Windows, findstr /i content-security-policy takes the place of grep -i. The privacy page explains which engine files the site fetches and when, and names the code that sends the counter and the code that receives it.
For employees: the converter is blocked and the job is due
You do not need an exception or an install. If the file is red or amber, and your company has not said otherwise, a tool that runs in the browser does the common jobs on your machine: compress, merge, split, convert, redact, protect. Drop the file, run the tool, download the result.
Try it here, nothing is uploaded
Before sending anything outside, Inspect shows what the file carries besides its pages: the author name, dates, attachments, scripts. It reads the file without changing it.
If IT has blocked browser tools too, respect it and ask. A 5-minute verification is a small request; a policy breach is not.
The honest part
getPDF fits this policy by architecture: the processing runs in the browser, the content security policy forbids other connections, and the counter that does reach the server carries a tool id, success or failure, a duration bucket and a size bucket, never a file or a file name. Still, IT should verify it like any other tool, not trust this page.
A local tool also does not close every gap on a work machine:
- Browser extensions are not bound by a web page’s content security policy. An extension allowed to read the pages you visit can read what a page shows. Keep extensions on work browsers to an approved list.
- The downloaded result lands in your Downloads folder, which some companies sync to cloud storage. That is usually fine and approved, but it is a copy all the same.
- What happens next is outside any tool: sending a perfectly processed contract to the wrong address is still a breach.
For the legal side, with the GDPR articles by number, read GDPR and online PDF tools.
Questions
Can I use iLovePDF or Smallpdf at work?
Only if your employer allows it. For public documents it is rarely a problem. For files with client or staff data, an upload makes the converter a processor under GDPR, which normally needs a data processing agreement with that company. Ask IT whether one exists; if not, use a tool that runs on your device.
Why does my company block PDF converter sites?
Because an upload sends company data to a server IT does not control, with no log on the company side and a retention promise nobody can check. The block is usually about the upload, not about PDFs.
Is a tool that runs in the browser allowed when converters are blocked?
Technically it often works, because nothing is uploaded. Whether it is allowed is your employer's rule, not ours. Ask IT to verify it with the tests on this page; that takes about 5 minutes.
Do I need to install anything to use getPDF at work?
No. It is a web page; the engine loads in the browser tab with the first file. That also means no admin rights and no exception for an installer.
The tools for this job
Keep reading
- GDPR and online PDF tools: what is allowed at work, in plain wordsGDPR and online PDF tools: uploading a client PDF to a converter is processing personal data.
- Prove a PDF tool is local: the Wi-Fi off test, and what the network panel showsPDF tools without uploading: turn Wi-Fi off and a truly local tool keeps working.
- Is it safe to upload a PDF to an online converter? The honest answerUsually, but you cannot check it from the homepage.
- Send a confidential PDF by email: 6 options, ranked by what they protect6 realistic ways to send a confidential PDF by email, from a password sent by text to an expiring link, ranked by what each protects against and the effort.
- PDF privacy and protection: the complete guideWhat a PDF password really protects, how true redaction works, what metadata leaks, and how to send files safely.