The most reliable way to prevent editing is strong encryption paired with controlled access: a real password, locked permissions, and a file you only share with people you trust. For casual sharing, flattening your PDF or converting it to an image removes the editable layer entirely. Basic permission flags and simple passwords deter casual edits, but screenshots, print-to-PDF, and noncompliant tools can bypass them with little effort.
TL;DR:
- Permission passwords depend on viewer compliance, so they deter accidents, not attackers; screenshots, print to PDF, command line tools, and OCR can bypass them.
- Flattening or converting pages to images blocks text selection and copy and paste, but removes screen reader access, increases file size, and cannot defeat OCR.
- For legal or financial documents, use authenticated encryption across the full file, and consider licensed DRM for revocable, device specific access and access logs.
- Digital signatures can show whether a document changed after signing, but they do not restrict reading, so pair them with encryption when secrecy matters.
- For sensitive sharing, use recipient authentication, encrypted storage, logged links, and expiry dates; avoid public links and revoke access when it is no longer needed.
Table of Contents
- Quick checklist: which protection fits your goal
- How to prevent editing using built-in tools and local browser tools
- Why basic PDF permissions fail against determined bypasses
- Stronger controls: DRM, authenticated encryption, and signatures
- Sharing and organizational best practices to complement file-level protections
- How to test a protected PDF before you share it
- FlowPDF: how a no-upload local tool fits this workflow
- Author's perspective: realistic expectations and a final recommendation
- Prepare and protect your PDFs locally with FlowPDF
- FAQ
- Sources
Quick checklist: which protection fits your goal
Before you touch any settings, match the protection to the actual risk. A contract shared with a colleague needs less than a financial record shared outside your organization.
- Low-risk, internal sharing: a permission password and restricted editing in Adobe Acrobat or Microsoft Word is usually enough to stop accidental changes.
- Stopping copy-paste and text selection: flatten the PDF or convert pages to images, which removes the underlying text layer entirely.
- High-value or targeted risk: use authenticated encryption or a licensed DRM viewer that supports revocation and per-device access.
- Sharing controls to pair with any file protection: set link expiry, require per-user authentication, and keep a log of who opened the file.
None of these choices are mutually exclusive. A sensitive document benefits from flattening and encryption and a controlled sharing link. A low-stakes internal memo probably only needs the first option. The goal is to spend effort where the risk actually lies, not to apply maximum protection to every file by default.
How to prevent editing using built-in tools and local browser tools
You don't need specialized software to stop most casual editing. Adobe Acrobat, Microsoft Office, and local browser-based tools each offer a path, and the right one depends on how much control you need and whether you're comfortable uploading a file to someone else's server.
- In Adobe Acrobat: open File > Protect Using Password, choose Restrict Editing, and set a permissions password separate from the one needed to open the file. This blocks editing, copying, and printing depending on which boxes you check.
- In Microsoft Word before exporting to PDF: use File > Save As > PDF, click Options, and under security settings restrict editing permissions so the exported file carries those limits forward.
- In a local browser tool: load your file into a no-upload editor like FlowPDF's editing tool, make your final edits, remove any metadata you don't want shared, then export before applying a password at the viewer level.
- To remove the editable layer entirely: print the PDF to a new PDF file, or flatten it, which converts selectable text into a static image. This stops copy-paste cold, though it also removes accessibility features like screen-reader text.
- To limit printing or add a watermark: most permission dialogs let you cap print resolution or add a visible watermark, which discourages redistribution without blocking it outright.
A local tool matters here for one practical reason: sensitive drafts, contracts, or redacted documents never leave your device during editing. FlowPDF's redaction feature works the same way, letting you black out text permanently before you ever think about passwords or permissions.
Pro Tip: Flatten a document only after you're certain you're done editing it. Once text becomes an image, you can't search or select it anymore, which also affects how recipients can interact with it.
A few caveats apply across all of these methods. Permission passwords set in Acrobat or Office are easy to apply but rely on the viewer software respecting them, which not every PDF reader does. Flattening is the most dependable way to stop text extraction, but it increases file size and can make documents inaccessible to screen readers. Watermarks and print limits work as a deterrent and a traceability measure, not as hard security.

Why basic PDF permissions fail against determined bypasses
Permission flags inside a PDF are just metadata, not a technical lock. A compliant viewer reads that metadata and disables certain menu items, but a noncompliant viewer, a command-line tool, or a script can simply ignore it and extract the content anyway.
- Metadata flags are stored in the file and only restrict behavior in software that chooses to honor them.
- Screenshots and print-to-PDF recreate the visual content regardless of what permissions say, defeating copy-paste restrictions entirely.
- OCR tools can extract text from a flattened image, undoing one of the few protections that otherwise holds up well.
- Command-line utilities can strip permission flags from a PDF in seconds if the file isn't also encrypted.
Research into PDF encryption has found deeper problems than permission flags alone. A Pdf-insecurity describes gadget and exfiltration attacks built into weaknesses of the PDF standard itself, meaning permission settings are not sufficient protection for documents that genuinely need to stay confidential. A related CCS paper on breaking PDF encryption shows that legacy encryption modes and partial encryption allow active attacks that can pull content out of a document an attacker shouldn't be able to read.
The practical takeaway: permission flags change what a casual user can do by accident. They do nothing against someone who wants the content badly enough to open a terminal. If your document holds financial records, legal evidence, or anything with serious consequences if altered or leaked, you need stronger controls than just a permissions checkbox.
Stronger controls: DRM, authenticated encryption, and signatures
When the stakes go up, the toolbox needs to change. Permission passwords and flattening solve the casual-misuse problem. For a document that genuinely cannot be altered or leaked, you need controls built around cryptography and access management rather than viewer settings.
- DRM and licensed viewers let you revoke access after the fact, limit a document to specific devices, cap printing, and log every open event, which a standard PDF password cannot do.
- Authenticated encryption protects both confidentiality and integrity at once, closing the malleability gap that affects older encryption modes like AES-CBC used without authentication.
- Full-document encryption is stronger than partial encryption, since partial schemes have been shown to leave exploitable gaps, as described in the CCS paper on PDF encryption.
- Digital signatures solve a different problem than encryption: they prove a document hasn't been altered since signing, but they don't stop someone from reading it.
The trade-off is friction. DRM systems require a compatible viewer on the recipient's end, which can break compatibility with anyone outside your organization's software ecosystem. Authenticated encryption and full-document encryption are stronger by design, but they add setup complexity most individuals don't need for everyday sharing. Digital signatures are worth adding when you care about proving a document is unaltered, such as a signed contract or an official record, but they should be paired with encryption, not treated as a substitute for it. For most individuals and small teams, the right move is matching the control to the actual threat: DRM and authenticated encryption for documents with real stakes, a signature for anything where tampering matters more than secrecy, and simpler permission-based protection for everything else.
Sharing and organizational best practices to complement file-level protections
A protected PDF is only as secure as the way you send it. A strong password means little if the file sits in a public cloud folder or gets forwarded as an email attachment with no expiry.
- Store the file in encrypted storage and require authenticated access rather than relying on an anonymous download link.
- Use per-user sharing links with logging instead of attaching the file directly to an email, so you know exactly who opened it and when.
- Set an expiry date on shared links where your platform supports it, and revoke access once the recipient no longer needs it.
- Avoid public or unauthenticated links for anything sensitive, even if the PDF itself is encrypted.
This approach lines up with PDPC guidance on data protection practices for ICT systems, which frames file-level protections as one layer in a broader security arrangement rather than a standalone fix. The guidance points to encryption at rest, access controls, and vendor security checks as reasonable arrangements organizations should combine with document-level measures. For a practical walkthrough of combining expiry controls, access authentication, and encrypted transfer, BabyLoveRaise's guide to sending a PDF securely covers the sharing side of this in more depth.
Before sending anything sensitive, run through a short mental checklist: is the file encrypted, is access limited to named people, does the link expire, and would you be comfortable if the recipient forwarded it without asking you first.
How to test a protected PDF before you share it
Protection settings only matter if they survive contact with a real recipient and a real device. A quick test before sending saves you from assuming a password worked when it didn't.
- Open the file in more than one viewer (Adobe Reader, Preview, a browser PDF viewer) to see whether permission restrictions behave consistently across all of them.
- Try printing to a new PDF and attempt a screenshot to confirm whether your print and copy restrictions actually block those actions.
- Attempt to select and copy text directly from the page to check whether flattening or text restrictions are working as expected.
- Check the encryption details in your viewer's document properties panel to confirm the algorithm and version applied, since older modes are weaker than current ones.
Pro Tip: Send yourself a test copy through the same channel you plan to use for the real recipient. A link that works fine locally can behave differently once it passes through an email gateway or a shared drive.
Testing methodology from PDF security research supports this two-layer approach: user-level checks like screenshots and copy attempts catch the obvious gaps, while technical verification of the encryption algorithm and signature metadata catches the ones a casual test would miss, a distinction raised directly in the CCS research on PDF encryption weaknesses.
FlowPDF: how a no-upload local tool fits this workflow
Preparing a PDF before you protect it matters as much as the protection itself. If sensitive text, metadata, or stray pages are still in the document when you lock it down, encryption just protects the wrong thing more tightly.
FlowPDF's editing tool runs entirely in your browser, so your document never leaves your device during editing, redaction, or cleanup. We built it this way because the most private step in any protection workflow is the one where you're still making changes, not the final password dialog. Use the redaction feature to permanently remove sensitive text before sharing, and the metadata removal built into our editing flow to strip author names, revision history, and other details most people forget are sitting inside a file.
We recommend FlowPDF for quick local edits before you apply viewer-level protection, for privacy-sensitive drafts you don't want touching a server, and for anyone working from a Chromebook or browser-only setup where installing desktop software isn't practical. Once your file is clean, flattened if needed, and free of stray metadata, apply your password and permissions at the viewer level and run through the testing checklist above to confirm everything holds.
Author's perspective: realistic expectations and a final recommendation
File-level protections deter casual misuse. They stop a coworker from accidentally editing a contract or a nosy recipient from easily copying a paragraph. They do not stop someone determined to extract your content, and treating a permission password like a vault is where most people get burned.
My recommendation is straightforward: prepare the document locally first. Remove metadata, redact anything sensitive, and flatten if you don't need the text layer anymore. Then apply encryption and real access controls, not just a permission checkbox, especially for anything with legal or financial weight. If you're dealing with a genuinely high-stakes document, that's when enterprise DRM, authenticated encryption, or legal agreements around document handling earn their complexity. For everything else, a careful combination of local prep and sensible sharing habits covers nearly every real scenario you'll run into.
— Ronald Ang
Prepare and protect your PDFs locally with FlowPDF
Before you lock down a document, get it clean. FlowPDF's editing tool lets you make last changes, remove metadata, and fix layout issues entirely in your browser, with nothing uploaded to a server. The redaction tool permanently removes sensitive text, and our full suite of free PDF tools covers merging, splitting, compressing, and more, all free and without watermarks.

Try preparing a file in FlowPDF, then apply your password and permissions at the viewer level, and run it through the verification checklist above before you hit send.
FAQ
Can I remove PDF password protection online?
Removing password protection depends on whether you know the password: if you do, a tool like FlowPDF's unlock feature can strip it locally in your browser without uploading the file anywhere. If you don't know the password, legitimately removing protection usually requires the original file owner's permission or software designed for authorized recovery.
How can I merge multiple PDF files for free?
You can merge multiple PDFs for free using a browser-based tool like FlowPDF's merge feature, which combines files locally without uploading them to a server. Most merge tools let you reorder pages before combining, so check the final order before saving.
How can I compress a PDF file online for free?
A free compression tool reduces file size by optimizing images and removing redundant data inside the PDF, and local tools do this without sending your file to a remote server. Compression works best on files with large embedded images, since text-heavy documents are already small by comparison.
How can I password protect a PDF file for free?
You can add a password and set editing or printing restrictions for free using Adobe Acrobat's security settings, Microsoft Word's export options, or a local browser tool that applies permissions without uploading your file. Always set a permissions password separate from the file-opening password if you want to restrict editing while still letting people view the content.
Sources
- Guide to data protection practices for ICT systems — PDPC
- PDF encryption security analysis — PDF Insecurity project
