DRM-protected files, explained — for the people who receive them
Most writing about DRM-protected documents is addressed to the people who protect them. But the first real encounter most people have with document DRM is from the other side: a link arrives — courseware, a standards document, a board pack, a paid report — it opens in a viewer instead of downloading, and your own name is faintly printed across the pages. If that's you, this page explains what you're looking at, why it behaves the way it does, and what the sender can and cannot see. (If you're the one deciding whether to protect documents, start with the buyer's guide instead — though reading the recipient's side first is honestly good preparation.)
What "DRM protected" actually means
A DRM-protected document is one whose owner attached rules that stay enforceable after delivery. Instead of receiving a file that is fully and permanently yours, you receive access: the document opens through a controlled viewer, and each time you open it, the owner's policy is checked — are you still an authorized reader, is the access period still running, is this one of your authorized devices? When the answers are yes, the document renders, usually with your identity visible on the view. When one of them stops being yes, access ends — without the owner needing to reach your device at all.
None of this is aimed at you personally. It's how organizations can share valuable or confidential material with the people who need it — members, learners, buyers, partners — without every share becoming a permanent, anonymous, forwardable copy.
The access logic, from your side
Four things govern what you experience as a recipient. Identity: access was granted to you by name, which is why the link that works for you won't simply work for someone you forward it to. Time: access can end on a date, after a number of opens, or when your relationship with the sender changes — expiry is the policy, not a malfunction. Devices: you can typically read on a few devices of your own; each is authorized against a limit. Permissions: printing and copying are allowed or blocked per the policy — if the print button does nothing, that's the document's rules, not your software being broken.
Common questions from recipients
Because what you were sent is access, not a copy. The owner set rules — who can open it, until when, on how many devices — and those rules are checked each time you open it. That is what lets them share something confidential with you at all: they stay able to manage it after sending.
That is a reader watermark. Your authorized view is marked with your identity so that every copy in circulation is attributable to its reader. You are not being singled out — every authorized reader sees their own name on their own view.
Usually yes, within the device limit the owner set. Each device you use is authorized against that limit — a typical policy allows a few devices per reader. If you hit the limit or replace a device, ask the sender to adjust your authorization.
The most common reasons: the access period expired, an open limit was reached, or the owner revoked access — for example when a subscription, enrollment or project ended. The denial message reflects the policy working as intended; the sender can re-grant access if that was not intended.
Access events are recorded: when the document was opened, by which authorized reader, on which device, and whether access was allowed or denied. That is the accountability the owner is paying for. It is a record of access to the protected document, not surveillance of your device.
Honest answer: determined people can photograph a screen, and no DRM prevents that. What protection changes is that casual forwarding stops working and any capture is attributable — the view carries the reader's identity, and access can be ended. It raises the cost and traceability of misuse rather than promising impossibility.
If you're the sender
Everything above is the experience your recipients will have, and it's worth designing for: grant access to the right identity, set expiry that matches the real relationship, and leave the device limit humane. The mechanics of setting this up are covered in how MyPass DRM works, and the controls themselves on the features page.