Why you should share less personal information online

Every detail you type into a form, attach to a sign-up, or upload to a website is a copy you no longer control. Where it goes next depends on that organisation's retention policy, its security, and sometimes its business model, none of which you can see from the outside. The one piece of personal information that can't be leaked, sold, or used against you is the piece you never handed over in the first place.

The regulators say the same thing on both sides of the Tasman

Australia's Office of the Australian Information Commissioner (OAIC) puts it bluntly: "the more personal information you share online, the greater the risk that your privacy might be compromised." Its guidance is to share contact details only with people and services you know and trust, and, when a form has optional fields, to leave them blank.

New Zealand's Office of the Privacy Commissioner frames it as a question worth asking out loud. When someone asks for your information, stop and think about whether they actually need it, a newsletter needs an email address, it does not need your home address. In its words, "it's okay to question why people are asking for certain information and to say no if you don't want to hand it over."

"They'll probably delete it" is not reassuring

Once your information is in an organisation's database, its safety is their problem to get right, not yours, and plenty don't. The OAIC recorded 1,113 data breach notifications in 2024, a 25% jump on the year before and the most since the scheme began, with malicious or criminal attacks behind roughly seven in ten of them in the second half of the year. Phishing and impersonation, tricking staff into handing data over, were the leading causes of the cyber incidents.

It doesn't take much to matter. The OAIC notes that "even if a thief only accesses a small amount of your personal information, they may be able to steal your identity if they can find out more about you from public sources." A single old sign-up, plus a breach, plus whatever is public on your social media, your date of birth, your family, your photos, can be enough to impersonate you.

A practical filter before you fill in a field

You don't have to become a hermit about it. Before entering something, run it past three quick questions:

  • Does this service actually need this to do the job? A discount code doesn't need your birthday. A file converter doesn't need an account.
  • Is the field required or optional? If it's optional and you're not sure why they want it, leave it blank.
  • Would I be comfortable if this exact set of details turned up in a breach next year? If not, that's a reason to share less, or to use something that doesn't ask.

Documents are personal information in bulk

It's easy to think of "sharing personal information" as filling in forms, but uploading a document is the same thing at a larger scale. A single PDF can carry your full name, your address, your signature, an account or reference number, and medical or legal detail, all at once. If a tool works by uploading that file to a server, you've handed every one of those details to whoever runs it, and to anyone who later gets into their systems. We went into how to tell the difference in is it safe to use free online PDF tools?

Where this site stands

The tools here don't ask for anything. There's no account, no email field, no upload. Your file is read and processed by JavaScript running in the browser tab you already have open, using your own device's memory, and its contents are never sent anywhere. There's no field to overshare into and no server holding a copy. What is and isn't collected beyond that, currently nothing: no analytics, no accounts, no cookies, is set out in the Privacy Policy.

Sort a document without handing it over

Browse the tools

Frequently asked questions

Isn't some data sharing unavoidable?

Yes. Your bank needs your details, your employer needs your tax file number, a shipping company needs an address. The point isn't to share nothing, it's to notice the difference between information a service genuinely needs and information it's collecting because the form had room for it. The second kind is where you can cut back with no downside.

What counts as "sensitive" personal information?

Anything that identifies you or could be used to impersonate you or reach your money: full name with date of birth, address, phone number, government ID numbers, bank or card details, signatures, and health or legal information. Australian and New Zealand privacy law give some of these categories extra protection, but from a risk point of view, treat any combination of them as something to guard.

I already gave a site more than I needed to. What now?

If it was just an email address, the OAIC and NZ's Privacy Commissioner both suggest changing the password on any account tied to that address and turning on multi-factor authentication. If it was identity or financial detail and you think the site was dodgy, see what actually happens when you hand a dodgy website your details for the reporting steps.

Related guides

Sources