[nonimo]
EN
Download

Redact an Excel spreadsheet before AI sees it

· Written and maintained by Nonimo

To redact an Excel spreadsheet before ChatGPT, Claude or Copilot sees it, make a separate copy and remove the personal data from the workbook itself, not merely from view. Unhide every sheet, row and column, clear the filters, delete comments and notes, and remove pivot tables and links to other workbooks. Then delete the columns the tool does not need, replace the rest with codes, and run Inspect Document before you upload.

Hiding, black fill and white text do none of this. A workbook stores far more than the grid on your screen, and a program that opens the file reads all of it.

This guide is meant for anyone in a UK office who keeps client, tenant or staff lists in Excel and would like an AI assistant to sort, total or summarise them: bookkeepers, lettings teams, HR and payroll staff, practice managers. The menus are named as they appear on Microsoft’s UK support pages. What the providers do with an upload once it arrives is another matter, covered by does ChatGPT share your data and Copilot and confidential information.

How to redact an Excel spreadsheet: six steps, in this order

Sequence matters more in a workbook than in a letter. Replace a surname before you unhide the rows and the hidden rows keep it; delete a sheet before you look at its pivot table and the table may still carry the data. Here are the six steps, and the sections below take them one at a time. Even in a Word letter, the first step is to settle the tracked changes and delete the comments before any name is replaced.

  1. Save a copy for the AI. Give it a name nobody could mistake for the working file, and make every change below in that copy.
  2. Show what is hidden. Unhide sheets, rows and columns, and clear every filter, so that the whole workbook is in front of you.
  3. Clear the margins. Delete comments and notes, rename any sheet whose tab carries a name, and check the page header and footer.
  4. Cut the ties to other data. Remove pivot tables, break links to other workbooks, and check what each chart is drawn from.
  5. Delete or replace. Delete the columns the task does not need, and swap the ones it does need for codes, with the key kept in a separate file.
  6. Inspect, then check. Run Inspect Document, then look at the copy a second way before it leaves your machine.

If the spreadsheet is heading for a tool nobody at the firm has signed off, redaction is the second question; the first belongs in a firm policy on approved AI tools. If you are unsure which columns count as personal data in the first place, the UK checklist of details to strip out goes through them one by one.

Hiding is not removing: what a workbook keeps out of sight

Excel offers several ways to make something vanish from the screen, and none of them takes it out of the file. The ICO’s guidance on personal information hidden in spreadsheets states the risk directly: hidden rows, columns and worksheets let people disclose personal information without realising it is there, and whoever receives the file can often bring it back by unhiding it.

To see what that means with a real file, we built a small client list with invented details and hid things in it the ways people usually do. Then we opened it with openpyxl, a free Python library for reading .xlsx files, which pays no attention to how the sheet is displayed. On screen, the workbook shows two clients and not one National Insurance number. The file holds five people and five NI numbers.

2clients visible on screen
5people saved in the file
5NI numbers, none of them visible
Our test workbook, invented data, read with openpyxl on 28 September 2026

None of this depends on which AI tool you use. Anthropic’s help centre says that to upload an XLSX file to Claude you must first switch on code execution and file creation, which tells you the tool works on the file itself and not on a picture of your screen.

We have not tested how any particular assistant treats a hidden sheet, and we do not claim to know. The safe reading is the ICO’s: whatever is in the file travels with the file. For what one provider keeps after an upload, see what Claude keeps from your chats.

Here is each hiding place in the test file, what reading the file returned from it, and how to bring it back in Excel:

Where we hid itWhat Excel showsWhat the file gaveTo show it in Excel
Row 4, hiddenA double lineA third client, fee, mobile, NI numberSelect rows 3 and 5, right click, Unhide
Column C, hiddenA double lineThree mobile numbersSelect B and D, right click, Unhide
Column D, format ;;;Empty cellsThree NI numbersSelect a cell, read the formula bar
Sheet “Former clients”, hiddenNo tabTwo former clients, NI numbersHome, Format, Hide & Unhide, Unhide Sheet
Sheet “Lookup”, very hiddenNo tab, not in UnhideA code next to a full nameNot listed: ask the workbook’s owner

Sources: our test .xlsx, generated by a script from invented details, then opened with openpyxl; Microsoft Support, Hide or show rows or columns, Hide or show worksheets or workbooks, Hide or display cell values.

The value behind the format

Two of those hiding places are ones people rarely think of as hiding. A custom number format of three semicolons makes a cell look empty. Microsoft’s page on hiding or displaying cell values describes exactly this, and notes that the value still appears in the formula bar when you select the cell. In our file, a column of NI numbers sat under a heading with apparently nothing beneath it.

Filters are the other. An AutoFilter, a slicer or a timeline hides whole rows that do not match what someone ticked, and the ICO points out how easy it is to send a file without noticing that a filter is switched on. The person at the other end clears it and sees the lot. Some of these features also keep a cache, a temporary copy of data, inside the workbook. Clear every filter on every sheet before you go further.

A very hidden sheet, and an empty Unhide list

A sheet hidden from the menu comes back with Unhide. A sheet can also be set to very hidden, which is done in code, and Microsoft’s page on hiding or showing worksheets says that sheets hidden by VBA with the property xlSheetVeryHidden are not listed by Unhide at all. Its advice is to contact the owner of the workbook. Our very hidden sheet held the worst thing to send: the key that turns a client code back into a client.

So an empty Unhide list is not proof of an empty workbook. The ICO’s spreadsheet checklist adds a crude test that works surprisingly well: check that the size of the file matches the amount of data you expect it to hold. A two column summary that weighs several megabytes is carrying something.

Once everything is on screen, delete from the copy any sheet the AI does not need rather than hiding it again. Microsoft warns that removing hidden rows, columns or worksheets that hold data can change the results of calculations, so check any total the task depends on.

The PSNI workbook and the worksheet nobody scrolled to

The best known spreadsheet breach in the UK did not involve a hidden sheet in the strict sense, and that is exactly why it is worth knowing. The Police Service of Northern Ireland received two freedom of information requests on 3 August 2023, asking for officer and staff numbers by rank. According to the ICO’s penalty notice, a member of the workforce planning team built the answer from a file downloaded from the HR system.

They added worksheets for the analysis, then deleted every tab visible on their screen except the one with the final figures. The original download, a worksheet called SAP DOWNLOAD, was still in the workbook. Its tab had simply scrolled out of view, and the only sign of it was three small dots to the left of the remaining tab.

9,483
officers and staff listed in the worksheet that nobody reviewing the file saw. ICO penalty notice to the PSNI, October 2024

Colleagues checked the file before it was released, and none of them noticed the dots or knew what they meant. It was uploaded to the WhatDoTheyKnow website at 14:31 on 8 August and was publicly available for about two hours and twenty minutes. The worksheet held surname and initials, rank or grade, role, department and place of work for all 9,483 people employed by the PSNI.

The ICO’s announcement put the penalty at £750,000 and said it would have been £5.6 million without the approach the ICO takes to public bodies. The check that would have caught it takes seconds: use the arrows beside the sheet tabs to scroll to both ends, and compare what you find with what you meant to send.

What the notice says about Excel files in general

The notice goes further than the one incident. It observes that spreadsheet files make it particularly easy to hold data nobody can see, and lists the usual ways: worksheets that do not show as tabs, sheets, rows and columns hidden on purpose, and source data carried inside a pivot table. It also records that the PSNI’s procedures at the time gave staff no instruction to check attachments for hidden data at all.

Swap the freedom of information requester for a chat window and the mechanics are the same: you choose a file, and the whole file goes. Whether the upload is itself a breach, and who must be told, is dealt with in this guide to breach rules for client data in ChatGPT. Councils answer the same kind of requests, and AI in local government sets out what council staff can and cannot use.

Comments, notes, sheet names and page headers

Excel has two kinds of margin note. Microsoft’s page on the difference between threaded comments and notes explains that threaded comments are conversations with replies, while notes are the older yellow boxes. Both are where people write the things they would never type into a cell: a reminder to chase a client, the name of whoever referred them, a line about a dispute.

Both kinds also carry the name of the colleague who wrote them. For a threaded comment, Microsoft says you cannot remove or change your name; the only way to get it out of the file is to delete the comment. You can delete comments and notes from the Review tab. If you need to read them first, Find and Replace will search inside them: set Within to Workbook and Look in to Comments, then to Notes.

A sheet tab is a label everyone reads

Sheet names are easy to overlook because nobody thinks of them as content. A tab called Harwood dispute or Thackeray 2025 names a client on every screen of the workbook, and it goes wherever the file goes. Excel allows up to 31 characters in a sheet name, which is plenty for a full name and a year.

31
characters allowed in an Excel sheet name, enough for a client's full name and a year. Microsoft Support, Rename a worksheet

Renaming a worksheet takes a second: double click the tab and type, or right click it and choose Rename. The same thinking applies to the file name, which is often the first thing an AI tool is told about your upload.

Headers, footers and the file’s properties

Page headers and footers do not show while you work in the grid, which is why they are forgotten, and firms often put a client or matter name there for printing. Inspect Document finds them and can remove them. The workbook’s properties (who created it, who saved it last) are the file’s metadata; our guide to removing metadata covers that layer for Word and PDF, and in Excel the same Inspect Document step clears it.

If a spreadsheet mixes these notes with health or sickness details, as some HR trackers do, removing a name does not change what the rest of the row is; the rules for health and other special category data explain why.

The features that summarise data are the ones most likely to carry the detail you meant to leave out. The ICO’s spreadsheet guidance warns that a pivot table and pivot chart stay linked to their source even if you copy them into a new workbook, delete the worksheet the data came from, or remove columns and rows from the summary. It adds that Excel saves a cache of information for pivot tables and charts, slicers and cube formulas.

FeatureWhat it keeps in the fileFor the copy you send
Save source data with fileA copy of the pivot’s source dataPaste the pivot into a new workbook as values
Enable show detailsDrill down from a total to its rowsPaste as values, as above
Pivot chartA tie to its pivot tableRedraw it from the pasted values
Link to another workbookA cache of that data, and its file nameBreak the link

Sources: Microsoft Support, PivotTable options and Manage workbook links; ICO guidance on spreadsheets. The last column is our advice.

Why unticking the option is not enough

Microsoft’s page on PivotTable options is blunt about the first setting: it should not be used to manage data privacy. Pasting as values, one of Excel’s paste options, is the route that keeps the figures and leaves the rows behind. A bookkeeper sending management accounts built from pivot tables is exactly this case, and accountants have a page of their own.

The ICO notes that a link can keep working, to some extent, even after the source file is deleted, because of the cache. Microsoft’s page on managing workbook links gives the route, Data, Queries and Connections, Workbook Links, and explains that breaking a link turns the formulas that use it into their current values. In desktop Excel that cannot be undone, so do it in the copy.

An ordinary chart is simpler: it is drawn from cells in the workbook, so its labels are whatever those cells say. A bar per client puts a client’s name on the axis, and once you deal with the cells, the chart follows.

Delete the column, or swap it for a code kept elsewhere

With the whole workbook in view, decide column by column what the task needs. Minimisation, the rule in UK GDPR, Article 5(1)(c), asks that personal data be kept to what the purpose actually needs, and no document makes that easier to apply than a spreadsheet. Most jobs you would give an AI need the figures, dates and categories. Very few need the mobile numbers.

Delete what the job can do without rather than emptying it, so that no heading is left promising a column of NI numbers: select the column letter, right click, Delete. Then save, reopen the copy and look again, because a column you deleted on one sheet may be repeated on another.

Replacing names with a code

When the AI has to tell rows apart, which client owes what or which tenant is in arrears, replace each name with a code such as C-001 instead of deleting it. Find and Replace (Ctrl+H) does this across every sheet if you set Within to Workbook. Tick Match entire cell contents, so that a search for Ann does not also change the letters inside Hannah.

Keep the list of which code is which in a separate file, never on a hidden sheet of the same workbook. The ICO’s page on pseudonymisation says coded data remains personal data for anyone who also holds the key, and that the key must be stored apart and kept secure. What coding does and does not change in law is set out in the guide to pseudonymisation in UK law.

Black fill is formatting, not redaction

Black shading, a font coloured to match the fill, or a shape laid over a range all change how the grid looks. The value stays in the cell, the formula bar shows it, and any program reading the file receives it as ordinary text. Shading can mark a cell you have already emptied, nothing more. The PDF version of this trap, a black box over text that is still there, gets its own treatment in redacting a PDF properly.

Columns that identify someone without a name in them

Take the names out of a staff list, leave the date of birth, postcode and job title, and in many firms you have left the person. The ICO, in its guidance on indirect identification, makes the point that separate pieces of information can single a person out once combined, and that the combination may draw on information held outside your organisation.

A spreadsheet makes these combinations easy, because every row lines the details up side by side. The test is not whether a column contains a name. It is whether someone who knows your office, your clients or your town could work out who a row describes.

ColumnWhy it can point at one personWhat to send instead
Date of birthWith a postcode or a start date, often uniqueAge band, or the year alone
Full postcodeTypically about 15 addresses (ONS)The postcode district, the first half
Job titleOften only one holder in a small teamA grade or a department
Start or leaving dateWith a job title, often uniqueMonth and year, or the year
Free text notesCan hold anything at allDelete, or read every cell

Sources: ICO guidance on indirect identification; ONS, Postal geography. The suggested replacements are ours.

Generalise, then read three rows as a stranger

Generalising keeps a column useful for the job. A payroll question about age bands works as well with 35 to 44 as with a date of birth, and a question about where tenants live works with a postcode district. Afterwards, pick three rows at random and ask whether a colleague outside the team could name the person. If the answer is yes for any of them, something in that row still needs to change.

Why a mix of ordinary details can identify someone is explored further in the explainer on what to mask for AI tools. GP practices, where a small patient list makes every combination sharper, have their own page.

Inspect Document in Excel, and what it leaves to you

Inspect Document is the check Microsoft builds into Excel. In the copy, open the File tab, choose Info, then Check for Issues, and pick Inspect Document. Tick every box, run it, and press Remove All beside each result you would rather not send. Microsoft’s page on inspecting workbooks splits what it looks for into three groups.

Be deliberate with Remove All against hidden rows, columns and worksheets. It deletes them, and if a visible total was built from a hidden row, the total changes. In a throwaway copy for the AI that is acceptable, provided you know it has happened.

A second look, the ICO’s way

The ICO suggests turning a spreadsheet into a plainer format like CSV to see everything it can display. It is a good check with one catch: Microsoft’s page on importing and exporting text files says that only the current worksheet is saved to the CSV. Save one CSV per sheet you intend to send, open each in Notepad or TextEdit, and read it alongside the workbook.

Finally, read the copy the way an outsider would, looking for details that give a person away without a name. If the figures will end up in a report or a court bundle, the redaction continues in the document they land in, as our guide to redacting a Word document explains.

A client list with a hidden row, through Nonimo

Select the workbook in File Explorer on Windows, or in the Finder on a Mac, and press your Nonimo key. Your clipboard then holds the text of the sheet with the details covered, ready to paste into the AI tool; paste the answer back and the names return. That route gives you text; drop the workbook onto Nonimo’s window instead and you can also download a covered copy as an Excel workbook, with the save dialog opening in the original’s folder on a Mac. Working from an old .xls file? Save it as .xlsx first and Nonimo takes it from there.

Our invented list has one sheet, row 3 hidden and a formula in the last column. Reading the file, then the clipboard from Nonimo, exactly as printed:

Reading the file (row 3 is hidden in Excel)
Client	NI number	Mobile	Email	Fee (£)	Fee with VAT (£)
Imogen Thackeray	PZ 12 34 56 A		imogen.thackeray@example.com	1250	1500
Nkechi Harwood		07700 900233		1640	1968

On the clipboard from Nonimo
Client	NI number	Mobile	Email	Fee (£)	Fee with VAT (£)
[PERSON_1]	[REFERENCE_1]		[EMAIL_1]	1250	1500
[PERSON_2]		[PHONE_1]		1640	1968

The hidden row is covered like the visible one, and the formula arrives as the value Excel saved, 1500. The fees stay, because they are what the AI is there to work on. The details are invented; PZ is an NI prefix HMRC has not used since 2002. What Nonimo stores and what leaves your machine is on the security page.

Sources

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT. No account needed, and the app does it without your files leaving your machine.

Common questions

How do I redact an Excel spreadsheet so no client names reach AI?

Work on a copy. Unhide every sheet, row and column, clear the filters, delete comments and notes, and remove pivot tables and workbook links. Then delete the columns the task does not need and replace the rest with codes, keeping the key in a separate file. Run Inspect Document last. The ICO's spreadsheet guidance asks for the same checks before any disclosure, and an upload to an AI tool is one.

Does hiding a column in Excel remove the data?

No. A hidden column is still in the workbook, and whoever receives the file can unhide it, as the ICO points out in its guidance on personal information hidden in spreadsheets. A program that reads the file reads it too: in our test, a free Python library printed a hidden column of mobile numbers without being asked. Delete the column from the copy you send instead of hiding it.

What is a very hidden sheet in Excel?

It is a worksheet hidden in code rather than from the menu. Microsoft explains that sheets hidden by VBA with the property xlSheetVeryHidden do not appear when you use Unhide, so a colleague can open the workbook, check the Unhide list and see nothing. The sheet is still saved in the file. If a workbook comes from a system export or a macro user, ask its owner before you send it.

Does the Document Inspector take names out of the cells?

No. Inspect Document looks for kinds of content, such as comments, document properties, headers and footers, hidden rows, columns and worksheets, and it can remove those. It does not read the visible cells for names, and for pivot tables, workbook links and embedded objects it only reports them, leaving you to remove them. A client's name typed in a visible cell stays until you delete or replace it.

Can a pivot table keep rows I have deleted?

Yes. The ICO warns that a pivot table stays linked to its underlying data even after you copy it into a new workbook or delete the worksheet the data came from, and Excel saves a cache of that data in the file. When the summary is all the AI needs, paste the pivot table into a fresh workbook as values, which keeps the figures and leaves the source rows behind.

Should I delete comments and notes before sharing a workbook?

Yes, from the copy you send. Comments and notes are where colleagues write the names and reminders they would not put in a cell, and each one carries its author's name. Microsoft says you cannot remove or change the author name on a threaded comment. Find and Replace can search inside comments and notes first, if you need to see what they say before you delete them.

Does black cell shading redact anything in Excel?

No. Black fill, white text on white, or a shape laid over a range changes what the grid shows, not what the cell holds. Click the cell and the value is in the formula bar, and a program reading the file gets it as plain text. To redact a spreadsheet, delete the value or replace it with a code. Shading can mark where something was removed, but only after the value itself has gone.

Will saving the workbook as CSV get rid of hidden data?

Not reliably. Microsoft says that only the current worksheet is saved to a CSV file, so the other sheets, hidden ones included, are simply left out of it, which is not the same as checking them. The ICO suggests converting a spreadsheet to a simpler format as a way of seeing what it holds. Use a CSV of each sheet as a check on your copy, not as the redaction itself.