Skip to content

Online PDF tools at work: a rule you can defend

By the getPDF team · Published 11 October 2026

The short answer

A rule that holds up: sort files by what is in them, not by the tool. Public files may go to any tool. Internal files go only to tools IT has approved. Files with personal or client data never go to a tool that uploads them, unless the company has a data processing agreement with that vendor. A tool that provably runs on the device sends nothing, so it fits all 3 classes once IT has checked it.

Inspect PDFFonts, images, metadata, why it is big. Free, runs on your device.

This page is for both sides of the desk: the employee whose usual converter is suddenly blocked, and the admin who has to write the rule. It explains how such a rule works in practice; it is not legal advice.

Why IT blocks online PDF converters

Most online PDF tools work the same way: your browser uploads the file, their servers do the work, you download the result, and the server copy is deleted later. iLovePDF says within 2 hours; Smallpdf says after 1 hour for ordinary tasks (both checked on 11 October 2026). From the company’s side, 3 things go wrong with that model:

  1. Data leaves the network without a record. The upload looks like any other web traffic. Nobody in the company can later say which contract went where.
  2. Retention is a promise, not something IT can check. The deletion policy may be honest; backups, logs and mistakes are invisible from outside. In July 2024, Cybernews researchers found that 2 converter sites, PDF Pro and Help PDF, had left more than 89,000 uploaded files open in cloud storage, among them passports and contracts.
  3. The legal duty stays with the employer. Under the GDPR, the company is responsible for personal data it handles, including what an employee uploads to a free tool on a Tuesday afternoon. The GDPR guide explains the articles involved.

So the block is rarely about PDFs. It is about the upload.

The traffic-light rule

The rule below sorts by document, because that is what an employee can judge in a second. Paste the table into a company wiki as it is.

Class Examples Allowed tools Why
Green: public Published brochures, price lists, forms downloaded from a public site, your own CV Any tool, upload or not Nothing in the file that is not public already
Amber: internal Internal reports, draft offers, meeting minutes, anything marked internal Approved tools only Business data, but no personal data of others; leaking it hurts the company
Red: personal or client data Contracts, payslips, HR files, CVs of applicants, medical or bank documents, anything with a name and a number Never a tool that uploads, unless a data processing agreement covers it; tools that run on the device after IT has verified them Personal data under GDPR; an upload makes the vendor a processor

Two habits make the rule easier to keep. First, when unsure, treat the file as red. Second, shrink the problem: if only 1 page carries personal data, remove that page or redact it before any tool sees the file.

What “approved” should mean

An approved tool is one that meets 1 of 2 conditions, and IT can say which:

  • Route A, a contract. The vendor signs a data processing agreement with the company (GDPR Article 28 requires one when a processor handles personal data for you), states where its servers are, and states how long files are kept. This is the route for cloud tools such as a company Acrobat or Microsoft 365 licence.
  • Route B, nothing leaves the device. The tool processes files on the employee’s machine: an installed desktop app, or a web tool whose processing runs in the browser. There is no upload, so there is no file on someone else’s server to govern. IT verifies this once with the tests below instead of trusting the vendor’s wording.

A tool that is neither (free online converters with no agreement) stays limited to green files.

A 4-line policy to copy

  1. Public files may be processed with any PDF tool.
  2. Internal files may be processed only with tools on the approved list.
  3. Files containing personal data of customers, applicants or staff must not be uploaded to any service without a data processing agreement.
  4. Tools on the approved list either run entirely on the device (verified by IT) or are covered by a data processing agreement.

Short is the point. A policy people can recite gets followed; a 12-page one gets an exception request.

How IT verifies a local tool before approving it

A vendor saying “nothing is uploaded” is a claim. These 3 checks turn it into evidence, and none needs special software. The Wi-Fi off guide walks through each in Chrome, Edge, Firefox and Safari.

  1. The offline test. Open the tool, run it once on a test file so its engine loads, then disconnect the network and run it again on another file. A tool that uploads fails; a local tool finishes.
  2. The network panel. With the browser’s developer tools open on the Network tab, run the tool on a file of a known size, say 5 MB. No request should carry anything near that size away from the machine. On getPDF you see the page’s own files, the engine (pdfium.wasm, 4.6 MB, about 2 MB as transferred) on the first file, and after the job 1 small POST to /api/count with a body like {"tool":"compress-pdf","ok":true,"ms":"lt3s","mb":"lt5"}.
  3. The content security policy. The site’s response headers say which addresses the page may connect to. getPDF sends connect-src 'self' blob: data:, so the browser itself refuses connections to any other host. A technical reviewer can read it in the network panel or with 1 line:
curl -sI https://getpdfs.app/ | grep -i content-security-policy

On Windows, findstr /i content-security-policy takes the place of grep -i. The privacy page explains which engine files the site fetches and when, and names the code that sends the counter and the code that receives it.

For employees: the converter is blocked and the job is due

You do not need an exception or an install. If the file is red or amber, and your company has not said otherwise, a tool that runs in the browser does the common jobs on your machine: compress, merge, split, convert, redact, protect. Drop the file, run the tool, download the result.

Try it here, nothing is uploaded

PDF · any size

Before sending anything outside, Inspect shows what the file carries besides its pages: the author name, dates, attachments, scripts. It reads the file without changing it.

If IT has blocked browser tools too, respect it and ask. A 5-minute verification is a small request; a policy breach is not.

The honest part

getPDF fits this policy by architecture: the processing runs in the browser, the content security policy forbids other connections, and the counter that does reach the server carries a tool id, success or failure, a duration bucket and a size bucket, never a file or a file name. Still, IT should verify it like any other tool, not trust this page.

A local tool also does not close every gap on a work machine:

  • Browser extensions are not bound by a web page’s content security policy. An extension allowed to read the pages you visit can read what a page shows. Keep extensions on work browsers to an approved list.
  • The downloaded result lands in your Downloads folder, which some companies sync to cloud storage. That is usually fine and approved, but it is a copy all the same.
  • What happens next is outside any tool: sending a perfectly processed contract to the wrong address is still a breach.

For the legal side, with the GDPR articles by number, read GDPR and online PDF tools.

Questions

Can I use iLovePDF or Smallpdf at work?

Only if your employer allows it. For public documents it is rarely a problem. For files with client or staff data, an upload makes the converter a processor under GDPR, which normally needs a data processing agreement with that company. Ask IT whether one exists; if not, use a tool that runs on your device.

Why does my company block PDF converter sites?

Because an upload sends company data to a server IT does not control, with no log on the company side and a retention promise nobody can check. The block is usually about the upload, not about PDFs.

Is a tool that runs in the browser allowed when converters are blocked?

Technically it often works, because nothing is uploaded. Whether it is allowed is your employer's rule, not ours. Ask IT to verify it with the tests on this page; that takes about 5 minutes.

Do I need to install anything to use getPDF at work?

No. It is a web page; the engine loads in the browser tab with the first file. That also means no admin rights and no exception for an installer.

The tools for this job