ITIT Lunchroom
Privacy and Sensitive Data Handling

Secure File Sharing and Permission Checks

Learn when a plain email attachment is the wrong way to send a file, what to use instead to keep it private, and how to check who can actually open what you send.

Share only what the person actually needs, only with them, through a way you trust to send files.

Last reviewed 2026-06-17 by the IT Lunchroom Editorial Team. General guidance, not professional security or legal advice.

What you will learn

I can tell when a plain email attachment isn't safe, and send the file a safer way instead.

You'll walk away knowing when a file is too private for a plain attachment, and how to send it a safer way instead. You'll also know how to check who can open it, and what they can do with it, before you hit send, so it reaches the right people and no one else.

safer ways to send a file vs. plain attachmentssharing only what the person actually needschecking who can open it, and what they can do with it, before you sendsharing by link, and setting it to stop working laterthe warning signs that you're about to share too much

What it means to share a file safely

Sharing a file safely just means getting it to the right person in a way that controls who can open it, and for how long. A safer way to send files keeps it limited to the people you choose. A plain email attachment doesn't: once you send it, anyone who gets it can forward it, save it, or pass it along.

Why a plain attachment can be risky

A plain attachment is out of your hands the moment you send it. Once a private file is attached to an email, the person who gets it can forward it, save it anywhere, or even send it to the wrong address, and there's no taking it back. A safer way to send files keeps it tied to the exact people you picked, and lets you cut off their access later if you need to.

Signs a file needs to go a safer way

Send a file the safer way when it holds personal details, money matters, health or student records, or anything else that should stay private — when it's going to a lot of people or to someone outside your team, or when you're not sure where it'll end up. Vague asks like "just send it to everyone," or someone pushing you to skip the careful way, are also good reasons to slow down.

Check who can open it before you send

Before you send, check exactly who will be able to open the file, and what they'll be able to do with it. Make sure the link goes to specific people, not "anyone with the link," turn off any access that isn't needed, and let people only view it rather than change it unless they truly need to edit. That quick check heads off the most common way files end up where they shouldn't.

A simple routine you can reuse every time

Use the same steps every time: figure out the least you can send that still does the job, pick a way to send it that fits how private it is, double-check exactly who can open it and what they can do, and, if you can, set it to stop working after a while. If anything's unclear, like whether this person should even be getting the file, pause and ask whoever owns the file, or whoever handles tech where you are, before you send.

How this plays out

Say a coworker asks you to email a spreadsheet of customer records to someone outside the company. You stop and think about what they actually need: it turns out they only need three columns, the file is private, and the person is outside your team. So instead of attaching the whole thing, you send a copy with the extra details taken out, set it so that one person can only view it, send it a safer way, and double-check their address first.

Practice and evidence

Practice lets you rehearse the send-it-or-stop decision, and the who-can-open-it check, on safe pretend files, so you're never touching a real private document.

Write yourself a short note: how private the file was, how you chose to send it, and who you made sure could open it, without copying anything that's actually inside the file.

Common questions

When should you send a file the safer way instead of as a plain attachment?

When the file holds private information, or it's going to a lot of people or someone outside your team. How private the file is, and who's getting it, decide the choice. A plain attachment can be forwarded and passed on past anything you can control.

When you share a file, how much of it should you send?

Only the information the recipient actually needs. Sending only what they need means less can go wrong if the file ever lands in the wrong hands.

What should you check before sending a file?

Exactly who can open it, and what they can do with it. Checking who can open it, and what they can do with it, is what keeps a file from reaching people who shouldn't have it.

What should you do if someone asks you to share a folder of sensitive files by sending a link that anyone with the link can open, so people can grab what they need?

Say no to the open link. Share it only with specific people, give them the least access they need, send it a safer way, and double-check who's on the list before you send. Once a link works for anyone, you can't control who ends up with it. Sharing it only with specific people, a safer way, keeps it small.

What should you do if someone outside your company needs a few details from a file that also has other people's personal information in it?

Send only the details they need, a safer way, and take out the personal information about everyone else that they don't need to see. Sending only the details they need keeps everyone else's information out of it, and sending it a safer way means you stay in control of where it goes.

Make it stick

Do the hands-on version of this lesson, then create a free account to save your progress. Finish a whole track and you earn a shareable certificate you can add to a résumé or job application. No payment, no catch.