Preview build. Draft guides are included and labelled; nothing here is published.
TaskStep 14 of 20 in Data room

Protect downloads with a watermark and password

Decide which external groups may download, and add a watermark and an open password to every PDF they take away.

Updated 29 Sep 20263 min read

Viewers, which is what buyers are, read documents in the browser and cannot download by default. Turn downloads on per group and per folder, and protect the PDFs that leave the room with a watermark and a password. Editors and owners can always download.

Before you start

  • You are a project owner.
  • You know which groups may keep copies and of what.

Steps

  1. Go to Teams, open the external group and select Data room access. In the row of a folder the group can see, tick Can download. The other boxes work the same way: No watermark and No password exempt the group from the protections below, and View unredacted shows original documents where redacted versions exist.
    Download rights and their exemptions are set per folder, row by row.1.Data room access tab2.Can download3.No watermark4.No password
  2. Go to Project Settings › Security Settings.
  3. Under Document Watermark, enter the Watermark Text, for example Confidential, and set Position (diagonal, header or footer), Color and Opacity. The watermark is stamped on every PDF the project serves, together with the downloader's email address and the time, as outlines that cannot be selected or removed. Clear the text to disable it.
  4. Under Download Password, enter or Generate a password that downloaded PDFs will require to open, and share it with the recipients outside the data room. Viewing in the browser is not affected.
    Both protections apply to PDFs; groups with No watermark or No password are exempt.1.Watermark Text2.Download Password

Check the result

In the Deal Portal, the group's members see a download icon next to each document in the folders you allowed, and can tick several items and use Download selected to receive them as a ZIP. Downloads appear in Analytics under the group's Downloads count and in each document's Access History, and in the project's activity log.

What is protected, and what is not

  • Watermark and password apply to PDF files, including the PDF the viewer shows for Word and PowerPoint documents. A buyer allowed to download a Word or PowerPoint file without redactions receives the original file without a watermark; one with redactions arrives as a watermarked PDF. Excel, CSV, image and text files are never watermarked. If a document must carry the watermark when it leaves the room, share it as a PDF.
  • No password can only be granted to a group that already has Can download.
  • A ZIP download watermarks each PDF inside it. When the project has a download password, the whole ZIP is protected with it instead of each file.
    • For your own team, the ZIP skips the password when every file in it is exempt.
    • For buyers downloading from the Deal Portal, the watermark and password always apply to a ZIP; No watermark and No password only affect single-file downloads.
  • A ZIP contains only the files the downloader may download. Documents with redactions are included in the version the downloader is cleared for. Files that cannot be included are left out and listed under Details, with a reason such as no download permission or still processing. If nothing is left, the downloader sees Nothing to download. The selection contains no downloadable files.
  • Files inside a ZIP carry the names of the view the download started from: Dataroom names with their index numbers, or the uploaded file names from the Workspace. Renamed files keep their file extension.
  • A downloaded file cannot be recalled. Revoking access stops new downloads only.
  • A newly granted download right or a changed exemption can take several minutes to show for the buyer; ask them to reload after a short wait before assuming it failed.

If something goes wrong

A buyer cannot download

Check the folder row in the group's Data room access tab: Can download is per folder. A role of Viewer without that box means view only. A buyer denied a download sees You do not have permission to download this item and usually emails you; grant the folder rather than sending the file.

The downloaded PDF asks for a password

The project's download password applies. Share it with the recipient outside the room, or tick No password for their group on that folder.

A buyer says files were missing from their ZIP

Ask what Details listed for the download. Files without Can download for their group, or still processing, are left out on purpose; grant the folder or wait for processing to finish, then they download again.