Paper Betrays You Too: Printers, Copiers and Scans — the Traces We Forget

Back to the blog
9 September 202612 min read

Introduction: the letter that knew where it came from

You want to report something. A questionable practice at your company, an abuse in your building's management, a piece of information a journalist ought to know. You decide to avoid anything digital — no email, no messaging app, no account to create. You type the text, print it on the colour printer in the living room, slip it into a plain envelope and post it from a letterbox three neighbourhoods away.

You have just done exactly the wrong thing.

On that sheet, invisible to the naked eye, a pattern of yellow dots a few tenths of a millimetre across repeats, over and over, your printer's serial number along with the date and time of printing. This marking has existed since the 1990s. In real cases, it has been used to trace a document back to its author within days.

Laptop displaying a VPN app on a wooden desk, with a plant, glasses and a notebook

Paper has a reputation as the last refuge of discretion. It is a comfortable illusion. Between printer markings, the hard drives inside office copiers, the metadata in scanned files and the databases of online printing services, the physical document's journey is now every bit as talkative as a web browser. This guide takes stock of those traces, without scaremongering, and explains the measures that actually work.


Yellow dots: the invisible marking of colour printers

What it is

It is called the Machine Identification Code (MIC), or "tracking dots". It is a grid of tiny yellow dots printed across the whole surface of the page, repeated every few centimetres. Yellow on white is all but invisible to the naked eye and disappears in quick photocopies — but it shows up immediately under a blue light or after simple image processing.

The pattern typically encodes:

Encoded informationTypical precision
Printer serial numberIdentifies the exact device
Print dateDay, month, year
Print timeDown to the minute
Manufacturer identifierMake and model

The serial number is then enough to trace back to the distributor, and on to the buyer, if the device was paid for by card, registered for a warranty or linked to a manufacturer account.

Why it exists

This marking was never imposed by any public law. It emerged in the 1990s from agreements between colour laser printer manufacturers and central banks, as part of the fight against banknote counterfeiting. The same logic produced the Counterfeit Deterrence System, the mechanism that makes a printer or an image editing program flatly refuse to reproduce a picture of a banknote.

The Electronic Frontier Foundation (EFF) publicly documented the phenomenon from 2005 onwards, publishing a list of affected models and a decoding tool. The question has been put several times to European data protection authorities; the subject remains a grey area, since the marking is almost never mentioned in the documentation sold to the customer.

Key point: if a colour-printed document is circulating and someone has an interest in finding its author, the printer is often the weakest link in the chain.

What limits the risk

A few factors reduce the scope of the problem:

  • Monochrome printers (black-and-white laser, black-only inkjet) do not apply this marking: yellow toner is needed to print it.
  • A photocopy of a photocopy degrades the pattern, with no guarantee that it disappears entirely.
  • Scanning and then reprinting transfers the second printer's marking, but may erase the first one if the resolution is low.

In practice, for a document you do not want traced back to you, the rule is simple: monochrome laser printer, standard paper, no colour at all. An entry-level monochrome laser printer costs less than a colour inkjet and has the added advantage of not drying out between uses.


The office copier: a computer that keeps everything

This is the most underestimated trace of all. A modern multifunction copier — the one down the corridor, the one at the library, the one in the shop round the corner — is not an optical machine. It is a full computer, with an operating system, a network card and, very often, an internal hard drive or flash memory.

What it keeps

Every copy, every scan, every fax passes through a digital image stored temporarily on that medium. On many models, "temporarily" means "until the space is reused", which potentially means months. Add to that:

  • job logs: who printed what, when, from which workstation or badge;
  • the address books for scan-to-email, complete with recipients' addresses;
  • sometimes the network credentials saved for accessing shared folders.

A now-classic investigation by the American network CBS News in 2010 involved buying second-hand copiers from a warehouse and extracting their hard drives: police files, complete medical records and payroll documents were recovered within minutes. The scenario has lost none of its relevance: the second-hand market for professional copiers is huge.

What you can do

Depending on your situation:

  • At a service provider (copy shop, coworking space): assume that any document copied there leaves an image behind. For a sensitive document, use your own equipment.
  • At work: ask the IT department whether disk encryption and automatic erasure after each job are enabled. Most manufacturers offer these options; they are often disabled by default.
  • When returning a leased copier: insist in writing on being handed the hard drive or a certificate of secure erasure. The GDPR makes equipment leaving the premises a legitimate control point, and Article 32 requires the security of processing, including at the end of the equipment's life.

Person using a laptop with a VPN app active on the screen


Metadata: what your PDF says about you without asking

A digital document intended for printing or sent as an attachment carries an invisible layer of information: metadata.

The typical contents of an office file

FieldWhat it often reveals
Author / Last authorYour real name or your session username
CompanyYour employer's name
Creation / modification dateThe full timeline of the work
Producing softwareThe exact version of your office suite
File pathUsername, folder structure on the disk
Revisions / commentsDeleted passages sometimes still present

A scan produced by a multifunction device adds its own batch: device model, resolution, sometimes a serial number, and for documents photographed with a smartphone, the GPS coordinates of where the shot was taken, via EXIF data.

Several political and legal affairs, in France and elsewhere, have been cracked open by these innocuous fields: an "anonymous" file carrying its author's name in the properties, a press release PDF revealing the workstation it came from.

Cleaning up properly

Three habits are enough in the vast majority of cases:

  1. Check before sending. On Windows, right-click the file → Properties → Details → "Remove Properties and Personal Information". On macOS, the information inspector in Preview. On Linux, the free tool mat2 (Metadata Anonymisation Toolkit), recommended by several digital rights groups.
  2. Flatten the document. Converting to an image and then regenerating a PDF removes the text layer, revisions and comments. It is crude but effective.
  3. Never "redact" with a black rectangle in a word processor or PDF reader. The text remains underneath, selectable and copyable. The only reliable way to obscure content is to print it, mask it physically with a marker and rescan it — or to use a redaction function that genuinely deletes the characters.

For physical redaction, a document blackout marker (a dense-ink pen, opaque when backlit) does a far more reliable job than an ordinary black felt-tip, which often leaves the text readable when held up to the light.


Postal mail: what can be read without opening the envelope

Sending a letter remains one of the few channels that creates no account, no password and no history you can look up online. But that does not make it neutral.

What gets recorded

  • Postal sorting automatically photographs envelopes in order to read the addresses. These images are kept for a limited time, but they exist.
  • The dispatch postmark indicates the sorting centre, and therefore the geographical area the item was sent from.
  • Tracked or registered mail is nominative by design: tracking only makes sense if it links a sender, a recipient and a route.
  • Handwriting is de facto biometric data, comparable to a fingerprint in an expert's hands.

Useful measures

For a letter you do not want traced back to you:

  • standard envelope and paper, bought in a supermarket, with no identifiable pattern or watermark;
  • address printed on a label rather than handwritten, or in even block capitals;
  • no tracked mail, no registered mail;
  • a public letterbox far from your home and your workplace, at any random hour;
  • no stamp bought at a counter with your bank card just before posting.

An opaque-lined envelope (the kind with a blue or grey printed interior) also prevents sensitive contents from being read through the paper — a detail people overlook when sending a copy of an ID document or bank details.

When the message fits in a few lines and no attachment is needed, an anonymous SMS is often simpler and quicker than a letter: no handwriting, no postmark, no physical handling. The choice between the two depends on what the recipient needs to be able to keep as evidence.


Destruction: throwing away is not destroying

The last link in the chain is the most mundane and the most exploited. For a private investigator, an identity thief or a nosy neighbour, going through the bins remains a method of unbeatable cost-effectiveness.

Person drinking coffee in front of a laptop showing a search engine in a browser

What should always be destroyed

  • bank statements and card receipts,
  • prescriptions and letters from testing laboratories,
  • letters from insurers, health insurance schemes and social security bodies,
  • parcel labels (they carry your name, address, order number and often a traceable barcode),
  • printed drafts of a sensitive document, including the pages that went wrong.

Choosing the right level

The European standard DIN 66399 classifies shredders by security level, from P-1 to P-7:

LevelCut typeSuitable use
P-2Wide stripsNon-sensitive paper
P-4Particles ~4×40 mmEveryday personal documents
P-5Particles ~2×15 mmBanking and health data
P-7Micro-particlesProfessional secrecy, classified material

For a household, a P-4 level cross-cut shredder is the right compromise: the long strips from a P-1 are far too easy to reassemble, and a domestic P-7 is overkill and slow. Think of expired bank cards and CDs too: many models accept them.

For the associated digital media — old USB sticks, camera memory cards, replaced external drives — software erasure followed by physical destruction of the medium remains the only safe approach.


Summary: the discreet document checklist

StageThe habit
WritingClean the metadata before any distribution
RedactionNever a digital black rectangle; physical masking + rescan
PrintingMonochrome laser, no colour, no online service
Copying/scanningAvoid shared multifunction devices for sensitive documents
SendingPlain envelope, printed address, no tracking, distant letterbox
StorageLocked away, no visible piles
DestructionCross-cut shredder, P-4 minimum, drafts included

For a physical file you want to keep away from prying eyes at home — an ongoing separation, proceedings in preparation, medical documents — a lockable storage box or a small fireproof safe costs little and solves the most common problem: it is not the state that reads your papers, it is someone who lives or works with you.


Your rights, all the same

The GDPR applies fully to paper as soon as it forms part of a structured filing system. In practice:

  • you can exercise a right of access (Article 15) over a paper file held by a public body, an employer or a landlord;
  • Article 5 requires storage limitation: an organisation cannot keep your supporting documents indefinitely without a defined retention period;
  • Article 32 requires security measures including physical ones: a pile of client files at a firm's reception desk is a breach.

The CNIL publishes practical guidance on document retention and has repeatedly sanctioned organisations for security failings as trivial as an open cabinet or archives abandoned during a move. If you come across such a situation, filing a report online with the CNIL takes a few minutes and does not require you to be the person concerned.


Conclusion: paper is not the enemy — going on autopilot is

Nothing above should put you off using paper. In many respects it remains a superior medium: it does not sync, it notifies no one, it does not end up in a cloud after an update, and it cannot be searched remotely.

The problem is not paper: it is believing it to be neutral. A printed sheet carries the signature of the machine that produced it, a copier keeps an image of what it has seen, a PDF knows its author's name, and a bin is a public space.

Treat every document as a small physical trace of yourself, and most of the risk disappears — no software, no subscription, just a shredder and a little attention.

#Anonymat#Vie privée#Confidentialité#Sécurité#RGPD#Cas d'usage

On the same topic

// Anonymous SMS · Hidden number · To France

Envoyez votre message, gardez l'anonymat

Votre numéro reste masqué, aucune inscription, aucune trace. Rédigez, confirmez, et votre SMS part de façon totalement anonyme.

Envoyer un SMS anonyme