ICO warns of the email data breach risks

The Information Commissioner’s Office (ICO) has warned of the risks of breaching data protection laws when using the carbon copy (CC) option to multiple email recipients.
The ICO recently issued a reprimand to an independent healthcare body in the UK for inappropriately sharing personal data via email. No personal information was shared in the body of the email, but the use of the CC group email option meant that all email addresses were visible to all recipients. In addition, they could infer certain information about other recipients due to their inclusion in the group email. As this might have been information that recipients would not have wished to have been shared, it constituted a breach of data protection law. John Edwards, UK Information Commissioner, explained: “Even if the content of an email is not sensitive or confidential, identifying people who have received it could reveal sensitive or confidential information about them.”
On investigation, the ICO concluded that the use of CC was inappropriate; the organisation therefore did not have sufficient guidelines in place to ensure that personal data would be secure in bulk email communications. “This type of data breach is all too common but is easily avoidable,” Edwards said, “Organisations must take responsibility for training their staff properly and for putting appropriate systems and policies in place to avoid such incidents.”
In this particular case, the use of blind carbon copy (BCC) would have avoided a data breach as it simply would not have disclosed the recipients’ email addresses. Alternatively, the use of a proper mailing process would have ensured there was no risk of data leakage – such as a mail merge (which sends an individual message out to each recipient) or an Electronic Direct Mail (EDM) platform.
Although this incident involved the medical history of individuals, which is clearly personal data, it serves to illustrate how easy it can be to inadvertently breach data protection. It is vital to have appropriate policies in place within your organisation to suit your handling of personal data and thereby prevent data breaches.
We are a certified Cyber Advisor with the government’s National Cyber Security Centre (NCSC) – please get in touch for a review of or discussion on your organisation’s data protection and cyber security, or to get your organisation certified to UK and global standards including Cyber Essentials, ISO, NIST, and more.