Most PDF security features are requests that readers are free to ignore. Two are real. Knowing which is which saves a lot of wasted effort.
The honest split
| Feature | Real? | Why |
|---|---|---|
| Open password (encryption) | Yes | Content is unreadable without the key |
| Digital signature | Yes | Any byte change is detectable |
| Permissions: no printing | No | Advisory; many readers ignore it |
| Permissions: no copying | No | Advisory; and OCR bypasses it anyway |
| Expiry date | No | Enforced by the viewer, not the file |
| Screenshot prevention | No | A camera exists |
| Watermarking | Partly | Deters and traces; prevents nothing |
| ZIP password around a PDF | Partly | Real encryption, but only in transit |
The pattern is simple: anything enforced by mathematics holds, and anything enforced by the viewer's goodwill does not. Vendors sell the second category hard because it demos well.
What encryption genuinely gives you
An open password encrypts the page content with AES. Without the password there is nothing to read — not slowly, not with effort, not at all. This is the one PDF protection that stands up.
It answers exactly one question: can someone who intercepts this file read it? No. It says nothing about what an authorised recipient does with it afterwards.
The weak point is never the cipher, it is the password and how you send it. Emailing an encrypted PDF and then emailing the password to the same address protects against nothing. The detail is in how to password protect a PDF.
Why expiry dates do not expire anything
A self-destructing PDF sounds useful and is not what is being sold.
A PDF is a file. Once it is on someone's disk, nothing in it can delete it, and nothing can stop them opening it in a reader that ignores the expiry. The feature works by having the document check a date — either an embedded one, which is trivially editable, or a server, which means the document is really a viewer stub and the content lives elsewhere.
That second architecture — a DRM platform where the "PDF" is a shell that streams content from a server — genuinely can revoke access. It is also not a PDF in any useful sense: recipients need the platform, it fails offline, and the content is only as available as the vendor. That may be a reasonable trade for high-value material. It is not a checkbox on a normal file.
Screenshot and copy prevention
These are sold together and neither survives contact with a determined person, or an undetermined one with a phone.
Copy prevention is the permission flag, which many readers ignore. Even where honoured, a screenshot plus OCR recovers the text in about a minute — Image to Text would do it. Screenshot blocking depends on the operating system cooperating, works on some platforms and not others, and is defeated entirely by pointing a camera at the screen.
The honest framing: these raise the effort from trivial to slightly annoying. If your threat model is a colleague casually forwarding a paragraph, they help a little. If it is anyone who actually wants the content, they do nothing, and believing otherwise is worse than knowing they are weak.
What digital signatures actually promise
A digital signature is the other genuinely cryptographic feature, and it is routinely misunderstood as protection.
It does not prevent modification. It makes modification detectable. The signature covers a hash of the file, so changing one byte invalidates it and any reader will say so.
That is a strong guarantee and a different one from what people expect. It answers "has this been altered since signing, and by whom was it signed" — not "can this be altered". For a contract or a filing, that is exactly the right question. The distinction between this and a drawn signature is in how to sign a PDF electronically.
A workable approach
Given all that, what actually protects a document is mostly not a PDF feature.
- Send less. The narrowest useful extract, not the whole file. Nothing protects a page you did not send.
- Encrypt in transit, with the password on a different channel — or better, use the recipient's own upload portal and skip email.
- Sign anything whose integrity matters, so alteration is detectable.
- Watermark for traceability, not prevention. A recipient name in a faint diagonal makes a leaked screenshot attributable.
- Use contracts for the rest. An NDA is the actual control over what someone does with a document they are allowed to read.
That last point is the one people resist and it is the truth of the subject. Every technical control ends at the moment an authorised person opens the file. After that it is a legal question, and no checkbox changes it.
Frequently asked questions
Can I stop someone printing or copying my PDF?
Not reliably. Those are permission flags the specification asks readers to honour, and many ignore them entirely. Even where honoured, a screenshot plus OCR recovers the text in about a minute. They raise the effort slightly; they do not prevent anything.
Can I set a PDF to expire?
Not in the file itself. A PDF cannot delete itself, and an embedded expiry date is trivially editable. Products that do this are DRM platforms where the "PDF" is a viewer stub streaming from a server — which works, but is not a normal file and fails offline.
Does password protection actually work?
An open password does — it encrypts the content with AES, so without it there is nothing to read. An owner password does not; it only sets advisory flags. The weak point is never the cipher, it is the password strength and how you transmit it.
Is a digital signature a form of protection?
It makes modification detectable rather than preventing it. The signature covers a hash of the file, so any change invalidates it and readers say so. That answers "has this been altered since signing" — a different and often more useful question.
Is zipping a PDF with a password secure?
ZIP AES encryption is genuine, so it protects the file in transit. But it only protects until someone extracts it — after that you have an unprotected PDF on their disk. It also saves almost no space, since a PDF is already compressed.
What actually protects a confidential document?
Sending less of it, encrypting in transit with the password on a separate channel, signing it so alteration is detectable, watermarking for traceability, and an NDA for everything after that. Every technical control ends when an authorised person opens the file.