· Written and maintained by Nonimo
To redact an Excel spreadsheet, you have to take the data out of the file, not out of sight. Make every hidden sheet, row and column visible again, delete what the task does not need, replace the names you keep with codes, clear the comments, notes, headers and footers, and then copy the values that are left into a new workbook.
Hiding a column, shrinking it to nothing or colouring a cell black changes what you see on screen. The file still carries every value.
This guide is for whoever is about to hand a workbook, or rows copied from one, to ChatGPT, Claude, Gemini or Copilot: the HR lead with a leave tracker, the practice manager with a client list, the bookkeeper with a payroll export. What those sheets hold is personal data, and passing it to an outside provider has consequences of its own, which we cover in a guide on client data and ChatGPT.
A few neighbouring jobs have guides of their own. Letters and reports go through the Word guide, and a PDF needs a different method. The author and company stored in a file’s properties are covered under metadata, and the full list of Irish identifiers to take out has its own page.
How to redact an Excel spreadsheet: delete it, do not hide it
Excel is built for hiding things without losing them. A column you do not want to print can be hidden and the totals still add up; a sheet of workings can be tucked away and the formulas that point at it keep working. That is useful in a busy office and exactly wrong for redaction, because every one of those features is designed to keep the data in the file.
So the working rule is simple. If a value should not reach the AI tool, it has to be deleted or replaced in the copy you send. Anything else is a display setting.
| What you do in Excel | What you then see | What the file keeps |
|---|---|---|
| Hide a row or column | a gap in the numbers or letters | every value in it |
| Hide a sheet | one tab fewer | the whole sheet |
| Format a cell with ;;; | an empty cell | the value, in the formula bar |
| Fill a cell black | a black bar | the text under it |
Sources: Microsoft Support pages on hiding sheets, rows and cell values; the DPC’s note on redaction, on colour and highlighting.
Why an upload is different from a screen share
When you show someone a spreadsheet on screen, they see what Excel draws. When you upload the file, a program opens it. Anthropic’s help centre, for example, says that uploading an XLSX file to Claude needs code execution switched on, and describes a private computing environment where Claude writes and runs code. What a provider keeps afterwards is a separate question, answered tool by tool in separate guides on what ChatGPT keeps and whether Claude trains on your data.
The next section shows what a program gets when it opens a workbook that looks tidy.
One test workbook, opened as a file
To see it for ourselves, we built a small leave summary for an invented company. Set up the way it is, it shows one sheet, Summary, with four columns: team, headcount, days taken and a Reviewer column that says Reviewed on every row. No names, no numbers that could point at anyone. It is the kind of sheet a manager would happily upload with a request to spot a trend.
Underneath, it carries six things that a quick look does not show:
- a hidden column E naming the reviewer, a colleague in accounts;
- a cell that looks empty but holds a mobile number, blanked by its number format;
- a note on one cell, with its author’s name, mentioning an employee’s sick leave;
- a hidden sheet, Staff list, with names, a PPS number and an email address;
- a very hidden sheet, Pay, with an IBAN and an Eircode;
- the sheet names themselves, which travel with the file.
Every detail is invented, and each number is picked so that no real person could hold it: the PPS number is seven zeros with its check letter, the mobile is all zeros after 087, the email address uses a domain kept for examples, the Eircode starts with A00, which is not a routing key, and the IBAN is the public sample from the IBAN registry.
Irish law puts extra rules on a real PPS number, and the PPSN guide walks through them.
What a short script got back
We then read the file with a short Python script of about seventy lines that uses only the standard library: no Excel, and no tool of ours. It unzips the workbook and prints what each part holds. All six came back, along with the state of each sheet and the name of the note’s author.
The point is not that someone would go looking. It is that no looking is needed. A program that opens the workbook reads the hidden parts in the same pass as the visible ones, because to the file they are the same kind of thing. A sick leave note is also health data, which brings in the stricter Article 9 rules explained separately.
What a workbook holds that the grid does not show
An .xlsx file is really a zip archive of XML parts. Microsoft’s documentation of the format says a separate XML file is created for each worksheet, and lists other parts that can sit alongside them: tables, charts, pivot table definitions and a cache of the source data behind each pivot table. Rename a copy from .xlsx to .zip and you can open it like a folder.
Whether a sheet shows up in Excel is one attribute in the workbook part. The data in the sheet’s own part does not change when you hide it, and the same goes for the other hiding places below. The Word guide describes the same pattern with hidden text, and file properties are another layer again, covered in the metadata guide.
Hidden and very hidden sheets
A hidden sheet is a right click away: on the sheet tab, Hide, and to bring it back, Unhide from any visible tab. Microsoft’s own page makes the key point in one line: the data in hidden worksheets is not visible but can still be referenced from other worksheets and workbooks.
The very hidden state is the one that trips people up. Microsoft’s Visual Basic reference describes it as hiding the sheet so that the user cannot make it visible; only code can. Its support page adds that the Unhide command will not display such sheets. So a workbook can pass the Unhide test and still carry a sheet nobody in the office has seen, as our test file did.
Hidden rows and columns
What holds for sheets holds here too. To bring them back, select the rows or columns either side of the gap, right click and choose Unhide, or double click the double line where they meet. Filters do something similar: rows a filter leaves out are still in the sheet, and Microsoft lists filters among the things the Document Inspector cannot remove.
Microsoft’s Document Inspector page also notes that it does not detect charts, shapes or pictures sitting in hidden columns. A column narrowed until it disappears is also still a column. If a sheet has a gap in its letters, from D straight to F, find out what E is before anything else.
A cell that looks empty
Formatting can hide a value in plain sight. Microsoft documents a custom format made of nothing but semicolons, ;;;, for this: cells with that format appear blank on the worksheet, and their values remain in the formula bar. White type on white fill does the same, and so does black fill over black text, which is how people often try to mimic a redaction bar.
The DPC’s 2021 note on redaction makes the same point about highlighting and colour in general: the text underneath is untouched and reappears once pasted into a text editor. In a spreadsheet, click into any cell that looks blank inside a table and read the formula bar.
The sheet names
Sheet tabs are labels people write in a hurry: a surname, a client code, “Cian sick leave”. They sit in the workbook part, and an AI tool reading the file will see them. Rename any tab that carries a name before you send the copy.
Comments, notes and whoever wrote them
Excel has two kinds of annotation now, and Microsoft’s comparison of them includes one line that matters here: what happens to the name.
| Threaded comment | Note | |
|---|---|---|
| Looks like | a white box | a yellow box |
| Replies | yes | no |
| The author’s name | stays, and you cannot change it | can be changed or removed |
Source: Microsoft Support, The difference between threaded comments and notes.
Either way, each one carries text a colleague wrote about a row, and often about a person.
In our test file, the note on one cell came out of the script with its full text and its author’s name. That is two people named in a sheet whose visible cells named nobody: the employee in the note and the colleague who wrote it. The Word guide covers how comments behave in a document, and the author field more generally is part of a file’s metadata.
To delete them, right click the cell and choose Delete Comment or Delete Note, or use Review, Comments, Delete. Read them first: a note is often where the one sensitive fact in the sheet lives. Word has a single command that clears every comment in a document at once, explained along with the tracked changes in our guide to removing comments from a Word document.
Headers and footers
A worksheet’s header and footer only appear in Page Layout view, in Print Preview and on paper. Microsoft’s page on them says so directly, which is why they are easy to forget. They are added through Insert, Header & Footer, and many offices put the file name, a client reference or the initials of whoever prepared the sheet there. The Document Inspector reports them, and you can also clear them by hand in Page Layout view.
Pivot tables, charts and links that keep a copy
Some parts of a workbook keep their own copy of data from somewhere else. They are the hardest to spot, because the copy never appears in a cell.
A pivot table works from a cache of its source data stored inside the file; Microsoft’s format documentation calls the part exactly that, a cache of the source data of the PivotTable.
Its PivotTable Options include a setting called Save source data with file, and Microsoft’s own page on the options warns against leaning on it to keep data private. If you delete the source sheet but keep the pivot table, the cache can still hold the rows.
Charts point at cells, and those cells can sit on a hidden sheet. A chart of absence by employee takes its category labels from the name column, so the names come along with the picture.
Links to other workbooks
An external link is a reference that reaches into another file, from a cell, a name, a chart title or a chart’s data series. Microsoft’s page on finding them shows the path and file name stored in the reference, and they can be listed from Data, Queries and Connections, Workbook Links.
The Document Inspector page adds that the names of the worksheets holding the linked data are saved with your workbook, where you do not see them. A folder called after a client travels with every link.
The Document Inspector will tell you most of this is there. It will not take all of it out:
| In a workbook | Inspect Document |
|---|---|
| Comments, headers and footers | finds and removes |
| Hidden rows, columns and worksheets | finds and removes |
| Document properties and personal information | finds and removes |
| PivotTable cached data | finds, cannot remove |
| External links and embedded files | finds, cannot remove |
| Filters, scenarios and hidden names | finds, cannot remove |
Source: the Excel section of Microsoft Support’s Document Inspector page.
When the tool on the other end is a work assistant with access to your files, the stakes change again, as our Copilot guide explains. Which providers offer terms fit for client data is a question we answer provider by provider.
Clearing a workbook in Excel, step by step
The order below is built so that each step makes the next one easier. The menus are those of Excel for Microsoft 365 on Windows, with Microsoft’s English names for them.
- Make a copy and do all the work on it. The DPC’s redaction note insists on this, and Microsoft recommends it before any use of the Document Inspector, since its removals cannot always be undone.
- Unhide every sheet. From the shortcut menu of any sheet tab, choose Unhide. If the count of sheets still looks short, or formulas refer to a sheet you cannot find, assume a very hidden sheet and use the last step of this list.
- Unhide rows and columns, and clear filters. Look for gaps in the row numbers and column letters, and for filter buttons in the header row.
- Check cells that look empty. Click into them and read the formula bar.
- Delete what the task does not need. Right click the column letter and choose Delete. If the AI tool only needs days taken per team, the name, PPS number and contact columns go entirely.
- Replace what the task does need with codes, as described in the next section.
- Delete comments and notes, and clear headers and footers. Rename any tab that carries a name.
- Run Inspect Document, which sits under File, Info, Check for Issues, and choose Remove All for each category that should go. Read the list of what it found but could not remove.
- Copy the values into a new workbook. Select the finished range, copy it, and in a blank workbook use Paste, Paste Special, Values. The new file has no hidden sheets, no pivot cache, no links and no formulas pointing back.
Deleting hidden data can also break the sums that depend on it, and Microsoft’s Document Inspector page says as much about hidden rows, columns and sheets. That is one more reason to do the work on a copy and to finish with the values only.
Saving a CSV instead
The DPC’s guidance mentions exporting to plain text or CSV, because those formats disclose or strip out hidden content such as concealed tables. Microsoft adds that when you save as CSV, only the current worksheet goes into the new file. Here is how the three possible last steps compare:
| Last step | What it leaves behind | What you still check |
|---|---|---|
| Paste Special, Values into a new workbook | other sheets, formulas, pivot caches, links, comments | the range you copied, row by row |
| Save As CSV | every sheet but the current one | rows and columns hidden on that sheet |
| Inspect Document | the categories it can remove | what it finds but cannot remove |
Sources: Microsoft Support pages on paste options, on text and CSV files and on the Document Inspector.
Whichever you choose, read the result once more before it leaves: a CSV in Notepad or TextEdit, a new workbook tab by tab.
If the sheet ends up as a PDF instead, the traps are different, and they are in the PDF guide.
On a Mac
Microsoft’s Document Inspector page does not cover Excel for Mac. Microsoft’s page on hiding sheets gives a route that works on both, through Home, Format, Visibility, Hide & Unhide, where the Unhide dialog lists the hidden sheets. The new workbook step works the same on both, which makes it the most reliable last step wherever you are working. File properties on a Mac are covered in the metadata guide.
Swapping names for codes, and keeping the key elsewhere
Often the AI tool needs to tell people apart without knowing who they are: to count absences per person, or to spot the same client in two months of invoices. Deleting the name column would lose that. Replacing each name with a code keeps it.
A lookup table does the job. On a separate workbook, list each name once with a code beside it, E01, E02 and so on, and use XLOOKUP or VLOOKUP in the working copy to bring the code in next to each row. Then paste the codes as values and delete the name column, so nothing in the copy points back to the list.
Where the key lives
The list that links codes to people is the key, and it should not travel with the sheet. A hidden tab in the same workbook is the worst place for it, for every reason earlier in this guide. The DPC’s 2019 guidance quotes the legal definition of pseudonymisation, which the GDPR and Ireland’s 2018 data protection law share: the extra information that would reidentify people has to be held apart and protected.
The same guidance is clear about what codes do not achieve. If the office keeps the raw data or a key, the data is pseudonymised rather than anonymised and remains personal data. It also warns that reusing the same pseudonyms lets records from different releases be linked, so use fresh codes for each upload.
What that means once the file reaches the provider, and the 2025 ruling of the Court of Justice on it, is the subject of our pseudonymisation guide.
Birth year, townland and job title in one row
A spreadsheet can give a person away without naming them anywhere. The DPC’s anonymisation guidance calls this singling out, and gives an example that fits any HR export: there may be many people who are 160cm tall and many born in 1990, but only one person in the dataset who is both. A row does in one line what a letter needs a page to do, because every column sits next to every other.
Ireland makes this sharper. A county, a job title and a year of birth can be enough in a small workforce, and a full Eircode points to a single address, as our PPSN guide explains. The answer is to make the columns coarser rather than to delete everything:
| Column | Keep it as |
|---|---|
| Date of birth | age band, or leave it out |
| Eircode | county, or the routing key only if the task needs it |
| Job title | job family or grade |
| Exact salary | a band |
| Start date | year, or length of service in years |
When the rows are few
The fewer the rows, the more each column gives away. A sheet with three people in the warehouse and one supervisor is not made safe by any coding. In that case, send totals rather than rows, or ask whether the AI tool needs the sheet at all. If the detail that remains is about health, a trade union or similar, the Article 9 guide covers the extra conditions.
Concealed columns and worksheets: the DPC’s warning
The DPC published its redaction note in August 2021 with access requests in mind, but its section on electronic files reads like a checklist for spreadsheets. It says that files produced by spreadsheet programs typically include considerably more information than appears on screen, and that spreadsheets may contain concealed columns, tables or worksheets.
Its practical advice lines up with this guide: keep the original untouched, “do not rely on highlighting and/or changing the colour of text”, swap each redacted passage for a marker, [REDACTED] in its own example, and consider exporting to plain text or CSV.
None of it was written with AI tools in mind. It applies all the same, because the question is the one the DPC asks: what goes out with the file. Public bodies in particular handle this daily, as our guide for councils and other public bodies sets out.
A hidden tab north of the border
The clearest case of what a hidden worksheet can do happened in Northern Ireland, under the UK GDPR, and the regulator was the ICO rather than the DPC. On 8 August 2023, Northern Ireland’s police service, the PSNI, answered a freedom of information request with a spreadsheet posted online. Its visible tabs had been deleted; a hidden worksheet had not, and it listed the surnames, initials, ranks and roles of the entire workforce, 9,483 officers and staff.
The file went up at 14:31 and the website hid it at 16:51. On 3 October 2024 the ICO fined the PSNI £750,000, and its account says the original worksheet remained unnoticed and was not picked up despite quality assurance.
Nobody in that office meant to publish anything. The hidden sheet simply went with the file, which is what a hidden sheet does when a workbook is uploaded to an AI tool as well. The PDF guide sets out what the DPC’s note adds for documents with black boxes.
Nonimo on a staff leave sheet
Nonimo takes the text out of the sheet for you and covers the details on the way. Select the Excel file in Finder on a Mac or in File Explorer on Windows, press your Nonimo shortcut, and the text of the sheet arrives on your clipboard with the details already covered; that is what you paste into the AI tool. When you paste the answer back, Nonimo puts the names back in. It pseudonymises: the details become labels, not blanks.
We tried it on an invented leave sheet with the Nonimo app on 28 September 2026. It has one sheet, a hidden fourth row, and a last column that is a formula; Nonimo read each cell’s value, the stored result rather than the formula.
| Row | In the sheet | What the model would see |
|---|---|---|
| 1 | Employee · PPS number · Mobile · Email · IBAN · Days taken · Days left | the same |
| 2 | Orlaith Mac Giolla Rua · 0000000W · 6 · 15 | [PERSON_1] · [REFERENCE_1] · 6 · 15 |
| 3 | Cian Ó Seanacháin · 087 000 0000 · 11 · 10 | [PERSON_2] · [PHONE_1] · 11 · 10 |
| 4, hidden | Sadhbh Cuffe · sadhbh.cuffe@example.com · IE29AIBK93115212345678 · 3 · 18 | [PERSON_3] · [EMAIL_1] · [IBAN_1] · 3 · 18 |
Invented data; empty cells left out and the columns joined with a dot. Tested in the Nonimo app on 28 September 2026.
The shortcut gives you text; drop the workbook into Nonimo’s window and you can also download the masked copy in the same format, as an .xlsx; on a Mac the save dialog opens in the original’s folder. Have an older .xls? Save it as .xlsx and it works the same way. The security page sets out exactly what stays on your computer.
A last look at the copy before it leaves the office
The person who did the redaction is the worst placed to check it, because they know what the sheet is supposed to say. A second pair of eyes on the finished copy takes a few minutes and asks six things:
- Count the sheet tabs, and compare the count with what the file is supposed to contain.
- Scan the row numbers and column letters for gaps, and the header row for filter buttons.
- Click into two or three cells that look blank and read the formula bar.
- Open the Review tab and check that no comment or note is left.
- Look at Page Layout view once for headers and footers.
- Ask whether what remains, a job, a county and a year, still points to one person.
No menu in Excel answers the sixth. It takes someone who knows the people behind the rows, and offices that upload spreadsheets every week usually put the check in their written AI policy so it happens each time. For the two professions that pass the most client workbooks around, see what we built for accountants in Ireland and solicitors in Ireland.
Sources
- Microsoft Support, Remove hidden data and personal information by inspecting documents, presentations, or workbooks. Inspect Document, reached from Check for Issues on the Info page; the Excel categories; the items it finds but cannot remove, including PivotTable cached data and external links; the warning about formulas; the versions it applies to. support.microsoft.com
- Microsoft Support, Hide or show worksheets or workbooks. Hide and Unhide from the sheet tab; data in hidden worksheets can still be referenced; sheets set to xlSheetVeryHidden do not appear under Unhide; the Mac route. support.microsoft.com
- Microsoft Learn, XlSheetVisibility enumeration. A very hidden sheet cannot be made visible by the user, only by code. learn.microsoft.com
- Microsoft Support, Hide or show rows or columns. Select the adjacent rows or columns and choose Unhide, or double click the double line. support.microsoft.com
- Microsoft Support, Hide or display cell values. The custom format
;;;; values remain in the formula bar. support.microsoft.com - Microsoft Support, The difference between threaded comments and notes. Comments allow replies and keep your name; notes can have the name changed; Delete Comment, Delete Note. support.microsoft.com
- Microsoft Support, Headers and footers in a worksheet. Insert, Header & Footer; shown only in Page Layout view, Print Preview and on paper. support.microsoft.com
- Microsoft Support, PivotTable options. Save source data with file; the setting should not be used to manage data privacy. support.microsoft.com
- Microsoft Support, Find links (external references) in a workbook. Data, Queries and Connections, Workbook Links; the source path and file name in the reference. support.microsoft.com
- Microsoft Support, Import or export text (.txt or .csv) files. Save As CSV; only the current worksheet is saved. support.microsoft.com
- Microsoft Support, Paste options. Paste Special, Values pastes the results of formulas without the formulas. support.microsoft.com
- Microsoft Learn, Structure of a SpreadsheetML document. A separate XML file for each worksheet; pivot cache records as a cache of the source data; renaming .xlsx to .zip. learn.microsoft.com
- Claude Help Center, Upload files to Claude, and Create and edit files with Claude. XLSX uploads need code execution and file creation enabled; a private computing environment where Claude writes and runs code. support.claude.com, support.claude.com
- Data Protection Commission, Redacting Documents and Records (August 2021). Spreadsheets may contain concealed columns, tables or worksheets; work on a copy; do not rely on highlighting or colour; replace with a marker; exporting to plain text or CSV. dataprotection.ie
- Data Protection Commission, Guidance on Anonymisation and Pseudonymisation (June 2019). The definition of pseudonymisation in the GDPR and the Data Protection Act 2018; singling out, with the height and year of birth example; a retained key means the data is pseudonymised and remains personal data; fresh pseudonyms to prevent linkage. dataprotection.ie
- Information Commissioner’s Office, What price privacy? Poor PSNI procedures culminate in £750k fine (3 October 2024). The hidden worksheet; 9,483 officers and staff; published at 14:31 and hidden at 16:51 on 8 August 2023; the fine. ico.org.uk
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT. No account needed, and the app does it without your files leaving your machine.
Common questions
Can you redact an Excel spreadsheet?
Yes, but only by deleting or replacing the data, not by hiding it or colouring it black. Bring everything hidden back into view first, delete what the task does not need, swap names for codes, clear comments and notes, then copy the values into a new workbook. The DPC's redaction guidance warns that spreadsheets can hold concealed columns and worksheets. Nonimo then covers names and numbers in the text taken from the file.
Is the data still there when you hide a column in Excel?
It is, every last value. Hiding changes what your monitor draws, not what the file holds, and anything that opens the file itself can read the column in full. Microsoft's Document Inspector lists hidden rows and columns as a separate category for exactly that reason, and warns that removing them can change your formulas. Delete the column instead. In the text Nonimo takes from a sheet, hidden rows are included, so their details are covered too.
What does very hidden mean for an Excel sheet?
It means the sheet's visibility was changed through code, so it is left off the list that Unhide gives you. Microsoft's reference for Visual Basic says that for a very hidden sheet the user cannot make it visible from the menus; only code can. The sheet and its data are still in the file. The simplest way round it is to copy the rows you need into a fresh workbook.
Which workbook items can Inspect Document not remove?
Microsoft lists several things the Document Inspector finds but cannot remove from a workbook: external links, embedded files, macros, PivotTable cached data, scenarios, filters and hidden names. It also cannot clear comments or document properties from a workbook saved as a shared workbook. Treat its report as a list of jobs, then deal with each one by hand or rebuild the sheet with values only.
Can a pivot table still hold data you deleted?
It can, because a pivot table works from a cache of its source data stored inside the workbook, and the Document Inspector cannot remove that cache. Microsoft also warns that its Save source data with file setting is no privacy control. If a summary from a pivot table is what you need, paste the result as values into a new workbook and send that.
Is saving the sheet as CSV a safe shortcut?
It helps, and the DPC's guidance mentions exporting to CSV because it strips out concealed tables and other hidden content. Microsoft notes that the CSV holds just the sheet that was active when you saved, so the rest drop out. Rows and columns hidden on that sheet are still data, though, so read the CSV in a plain text editor before it goes anywhere, and delete there anything that should not travel.
Do staff codes instead of names make a sheet anonymous?
Not while anyone in the office keeps the list that links each code to a person. The DPC's guidance says that if a key is retained, the data is only pseudonymised and remains personal data. Codes still reduce what an AI tool is given, which is worth doing. Store the key well away from the sheet, in a file of its own, and use new codes each time so two uploads cannot be matched.
Can Nonimo read an Excel workbook?
Yes, a .xlsx file. Select it in Finder or File Explorer and press your Nonimo shortcut, and the text of the sheet lands on your clipboard with names, PPS numbers, phone numbers, emails and IBANs replaced by labels, and you paste that into the AI tool. Hidden rows are read too. Drop the workbook into Nonimo's window instead and, from the preview, you can also download a masked copy as an .xlsx. Have an older .xls? Save it as .xlsx and it works the same way.