DELUMA
PDF editing and GDPR: understand your document workflow
A PDF can contain contact details, financial records or health information. Choosing a tool starts with understanding which operations use the document locally and which send it to a service.
Reviewed on · Deluma
Reduce unnecessary processing
The European Commission describes data minimisation, storage limitation, security and accountability among the GDPR principles. Keeping a document on a controlled device can reduce some transfers, but an organisation must still assess the lawful purpose and other obligations for its processing. European Commission — Principles of the GDPR.
What Deluma processes locally
Merging, splitting, editing, compression and OCR run in your browser. These operations do not require uploading PDF bytes to the server. The account and allowance may be checked by the API without transmitting the document itself.
Optional actions and service data
Saving to the online library or sending by email transfers the file when you choose that action. Office conversion modes using a server have a separate consent step. Account services, billing and website delivery also involve remote systems. Read the privacy policy before adopting these workflows for personal data.
A practical review for your organisation
Start with a fictional document. Identify the minimum data required, restrict access to the device and decide where exports will be stored. Set a retention period and a deletion process. Check OCR text and edited pages before professional use. Assess provider agreements and any applicable transfer requirements when enabling remote features.
Local processing is not a compliance certificate
Using Deluma does not automatically make an organisation GDPR compliant. It can reduce a particular transfer while leaving responsibilities for the device, account, legal basis and exported files with the organisation. This is a product workflow guide, not a legal opinion or certification.