Hidden data in Excel files
A spreadsheet is the format most likely to be shared without being read. Someone hides a column, saves, and sends the file — and the column is still there, one right-click away.
This is the format behind a long run of accidental disclosures: salary columns hidden rather than deleted, a "Notes" sheet nobody meant to include, a pivot cache still holding the source data.
Not switched on yet. Excel and CSV scanning are built and tested in our engine but are not available in the website today — the checker currently accepts photos and Word documents. Join the waitlist to hear when spreadsheets are live.
Where spreadsheets hide things
Hidden is a display setting. The data stays in the file.
- Hidden worksheets, including "very hidden" ones that do not appear in the unhide menu at all
- Hidden rows and columns, which are one right-click from visible
- Cell comments and notes, each with an author name
- Document properties — author, company, last editor
- Column headings that reveal what the data is even when the cells are gone: "Salary", "DOB", "National Insurance"
- Defined names and formulas pointing at data that was supposedly removed
Why we will not delete a hidden sheet for you
This is a deliberate design decision and it is worth explaining, because it is the one place our cleaner stops and asks.
Deleting a hidden worksheet can break the workbook. Formulas elsewhere may reference it, and removing it turns those cells into reference errors — a working spreadsheet becomes a broken one, and the person may not notice until someone else opens it.
So hidden sheets are reported rather than removed. Properties and comments are cleaned automatically; the structural decision stays with the person who understands the workbook.
The heading problem
Sometimes the sensitive thing is not a value but a label. A column headed "Disciplinary outcome" tells you what the file is about even if every cell under it is blank, and a sheet of employee IDs next to a column headed "Grievance" is disclosive on its own.
Detection therefore looks at headings as well as cell contents.
What to do today
Until Excel support is switched on here: unhide everything before sending — select all rows and columns and unhide, then right-click a sheet tab and check for hidden sheets. If a sheet does not appear there, it may be "very hidden" and only visible in the VBA editor. Then delete what should not travel, rather than hiding it.
Better still, copy the cells you actually want into a new workbook. A fresh file carries none of the old one’s history.
Hear when this is switched on
One message when it launches. Nothing else, ever.
Questions
No. Excel and CSV are implemented in the engine and tested, but not switched on in the website. Photos and Word documents work today.
A visibility state that hides a worksheet from the normal unhide dialog entirely. It can only be changed from the VBA editor, so a sheet can sit in a workbook that its own author has forgotten about.
Not necessarily. Pivot caches, defined names and formulas can still reference the original values, and a chart can keep its own copy of the series. This is why copying what you need into a fresh workbook is more reliable than deleting what you do not.
Yes, in the same release. A CSV has no metadata to speak of, but it very often has columns of personal data and headings that say what they are.
Related
- File privacy scannerScan a file for personal data, hidden metadata, author names and edit history before you share it. Runs in you…
- Redact PDF metadata onlineWhat PDF metadata reveals, why drawing a black box over text does not redact it, and how to remove document pr…
- Remove the author from a Word documentStrip the author, last-edited-by, company and comments from a .docx file, and accept tracked changes so delete…
We report no issues found, never “safe”. Absence of detections is not proof of absence, and detection is best-effort.