Hmmmm.
On the one hand you want to store the data inside a file format which is a known malware propagation vector and send it on a round trip to the client, or on the other hand you want to embed this file inside another file which is also a known malware vector. Leaving aside the question of whether the content will actually be editable when embedded in the PDF file, it looks to me like you have increased the attack surface.
Speaking with my programmer hat on, if I want to send and receive tabular data, then (any of the) MS Excel format(s) would be well down my list of choices for a container. In addition to the known dangers of malware, it is horrendously difficult to parse and process compared with CSV, JSON, XML.
OTOH I recognize that for most mortals, trying to edit an XML or JSON file must seem like rocket science (but CSV isn't that much of a pain considering you need them to maintain the appropriate encryption for the return trip). But if its small amounts data then why not just use an online form over HTTPS which solves the problem of how the user manages the clear text as well as the issue of proprietary file formats and the issue of malware injection.
Maybe sharing an online spreadsheet is not an ideal solution.