E-mail Security Que...
 

  You don't need to be an 'investor' to invest in Singletrack: 6 days left: 95% of target - Find out more

[Closed] E-mail Security Question

10 Posts
10 Users
0 Reactions
121 Views
 irc
Posts: 5188
Free Member
Topic starter
 

I have just had a work related e-mail from an HR manager in which mine and every other recipient's private email addresses are visible. Am I correct that this is not just poor practice but a possible data protection breach.

I am not hugely bothered but was going to send her a reply requesting this be done with non visible emails. This is a NHS email account it has come from not a small company so I would have thoiught they would do better.

Anyway for my info just bad practice or data breach.


 
Posted : 14/06/2020 9:56 am
Posts: 22922
Full Member
 

This is a NHS email account it has come from not a small company

Are all the recipients, including yourself, NHS employees? Or is this an email from HR to people outside the organisation - such as prospective employees?


 
Posted : 14/06/2020 9:59 am
Posts: 13164
Full Member
 

If it's an office email to direct employees no harm, no foul. If there are contractors on the list more of a commercial confidentiality problem.


 
Posted : 14/06/2020 10:26 am
Posts: 493
Free Member
 

So are you normally allowed to know the private email addresses of all your colleagues?

What if one colleague used this info to harass another one?

Yes, not using bcc is sadly very common (I think email clients should make it the default offering frankly) but they screwed up.


 
Posted : 14/06/2020 10:31 am
 irc
Posts: 5188
Free Member
Topic starter
 

All recipients are other employees which is why I'm not hugely bothered. I've not fallen out with anyone on the list but I still don't think they should be sharing it.


 
Posted : 14/06/2020 11:08 am
Posts: 4170
Free Member
 

If it's people's private email addresses and sent by an employer I think it's a breach of GDPR, irrespective of whether the recipients are employees.


 
Posted : 14/06/2020 11:30 am
Posts: 77347
Free Member
 

Holding private email addresses in the first place is probably in breach of GDPR.


 
Posted : 14/06/2020 1:50 pm
 beej
Posts: 4120
Full Member
 

This says... maybe (towards the bottom): https://www.towerwatchtech.com/5-ways-your-emails-could-breach-gdpr/


 
Posted : 14/06/2020 3:57 pm
Posts: 17779
Full Member
 

If it’s an office email to direct employees no harm, no foul.

If internal email addresses OK, but not home email addresses.


 
Posted : 14/06/2020 6:08 pm
Posts: 6762
Full Member
 

Wife did something similar by accident, she normally uses bcc, from a school to external exam candidates, had to email them all an apology and it got logged as a GDPR breach.


 
Posted : 14/06/2020 6:31 pm
 poly
Posts: 8699
Free Member
 

Its not automatically "OK" even if they were all @nhs.uk addresses - depending on the nature of the email - especially given its "HR". e.g. if the email was about sickness/absence/mental health/grievance process etc - even if it doesn't explicitly say why you were included if others could infer that this was only going to people who had say been off sick for a certain period.


 
Posted : 14/06/2020 11:39 pm

6 DAYS LEFT
We are currently at 95% of our target!