Click or drag to resize
Pdf Library for .NET

Encrypting Regulated Data

Regulations that cover personal, medical or financial data - HIPAA, GDPR, PCI DSS - do not certify file formats or libraries. Where they ask for encryption they point to current guidance, which names AES (NIST SP 800-111 for stored data). This topic says how to produce pdf documents that meet that bar, and what pdf encryption does and does not protect.

AES-256 is the default

Setting a password is enough: the document is encrypted with AES and a 256-bit key (revision 6 of the pdf security handler, EncryptKey256BitRevision6 with AES). This applies to a new document, to an existing document that is not encrypted, and to the html to pdf converter's SecurityOptions. A document that is already encrypted keeps its own settings.

Every current pdf viewer opens these documents. Viewers older than Adobe Acrobat X (2010) do not; if you must support them, choose AES with a 128-bit key rather than RC4.

An existing document is encrypted the same way with PdfSecurityManager, whose EncryptionKeySize, EncryptionAlgorithm and EncryptMetadata have the same defaults.

What to avoid
  • RC4, with a 40-bit or a 128-bit key. It is broken and is supported only for old viewers.

  • An owner password without a user password. Anyone can then open the document; the permissions (printing, copying, editing) are honoured by compliant viewers, but they are not what keeps the content confidential. The user password is.

  • Passwords written into source code or configuration files in plain text.

AES-256-GCM (AESGCM) is available as well. It is defined by PDF 2.0, so choosing it writes the document as PDF 2.0, which only recent viewers open.

Metadata

By default everything is encrypted. Set EncryptMetadata (or EncryptMetadata for a conversion) to false to leave the document's XMP metadata packet readable - by a search index or a document management system - while the content stays encrypted. Leave it true when the metadata itself identifies a person: a title such as a patient's name is personal data too. The document information entries (title, author, keywords) are encrypted either way.

On a document that is already encrypted, the metadata encryption can be changed only when both passwords are set again, because the encryption keys depend on it.

Archiving

PDF/A does not allow encryption, and a PDF/A document with a password is refused. Protect an archived document at the storage level instead.

Code Sample
// html to pdf: a password is enough for AES-256
HtmlToPdf converter = new HtmlToPdf();
converter.Options.SecurityOptions.UserPassword = userPassword;
converter.Options.SecurityOptions.OwnerPassword = ownerPassword;
converter.Options.SecurityOptions.CanCopyContent = false;
PdfDocument doc = converter.ConvertUrl(url);
doc.Save(file);
doc.Close();

// an existing document
PdfDocument existing = new PdfDocument(existingFile);
existing.Security.UserPassword = userPassword;
existing.Security.OwnerPassword = ownerPassword;
existing.Save(protectedFile);
existing.Close();
See Also