Skip to content
Not switched on yet

Hidden data in Excel files

A spreadsheet is the format most likely to be shared without being read. Someone hides a column, saves, and sends the file — and the column is still there, one right-click away.

This is the format behind a long run of accidental disclosures: salary columns hidden rather than deleted, a "Notes" sheet nobody meant to include, a pivot cache still holding the source data.

Not switched on yet. Excel and CSV scanning are built and tested in our engine but are not available in the website today — the checker currently accepts photos and Word documents. Join the waitlist to hear when spreadsheets are live.

Where spreadsheets hide things

Hidden is a display setting. The data stays in the file.

  • Hidden worksheets, including "very hidden" ones that do not appear in the unhide menu at all
  • Hidden rows and columns, which are one right-click from visible
  • Cell comments and notes, each with an author name
  • Document properties — author, company, last editor
  • Column headings that reveal what the data is even when the cells are gone: "Salary", "DOB", "National Insurance"
  • Defined names and formulas pointing at data that was supposedly removed

Why we will not delete a hidden sheet for you

This is a deliberate design decision and it is worth explaining, because it is the one place our cleaner stops and asks.

Deleting a hidden worksheet can break the workbook. Formulas elsewhere may reference it, and removing it turns those cells into reference errors — a working spreadsheet becomes a broken one, and the person may not notice until someone else opens it.

So hidden sheets are reported rather than removed. Properties and comments are cleaned automatically; the structural decision stays with the person who understands the workbook.

The heading problem

Sometimes the sensitive thing is not a value but a label. A column headed "Disciplinary outcome" tells you what the file is about even if every cell under it is blank, and a sheet of employee IDs next to a column headed "Grievance" is disclosive on its own.

Detection therefore looks at headings as well as cell contents.

What to do today

Until Excel support is switched on here: unhide everything before sending — select all rows and columns and unhide, then right-click a sheet tab and check for hidden sheets. If a sheet does not appear there, it may be "very hidden" and only visible in the VBA editor. Then delete what should not travel, rather than hiding it.

Better still, copy the cells you actually want into a new workbook. A fresh file carries none of the old one’s history.

Hear when this is switched on

One message when it launches. Nothing else, ever.

For the mobile app and browser extension. One message when they launch.

Questions

  • No. Excel and CSV are implemented in the engine and tested, but not switched on in the website. Photos and Word documents work today.

Related

We report no issues found, never “safe”. Absence of detections is not proof of absence, and detection is best-effort.