Data breach question
Author
Discussion

Riley Blue

Original Poster:

23,205 posts

255 months

Thursday 14th July 2022
quotequote all
A public sector organisation has recently committed a data breach by sending an email in which all recipients' (who are members of the public and staff) email addresses are visible. They've apologised, reported themselves and the breach is under investigation.

One of the members of the public has replied to all drawing attention to the breach "before he takes further action". In 'replying to all', which has again revealed all email addresses, has he also committed a breach?

Before you ask - no, it wasn't me!

Freakuk

4,749 posts

180 months

Thursday 14th July 2022
quotequote all
No, he hasn't committed a breach as he didn't have all of their email addresses in the first place. What he has done is exploited the breach caused by the original sender.

I assume the ICO has been engaged and they will be investigating accordingly. Exposing email addresses isn't huge in itself and depending upon the content of the mail I doubt much will happen.

Gareth79

9,016 posts

275 months

Thursday 14th July 2022
quotequote all
Freakuk said:
Exposing email addresses isn't huge in itself and depending upon the content of the mail I doubt much will happen.
If it's a fairly innocuous list (eg. a council sending a circular to a list of licensed premises) then I agree nothing will happen. The problem comes if membership of the list is likely to reveal something about the recipient, eg. a while back an HIV clinic CCd all patients onto an email rather than BCC.

matchmaker

9,036 posts

229 months

Thursday 14th July 2022
quotequote all
I received an e-mail at work from an organisation which included hundreds of addresses in the "To" field. One recipient furiously replied stating that this was a disgraceful data breach.

Unfortunately, they used "Reply all". rofl

Riley Blue

Original Poster:

23,205 posts

255 months

Thursday 14th July 2022
quotequote all
matchmaker said:
I received an e-mail at work from an organisation which included hundreds of addresses in the "To" field. One recipient furiously replied stating that this was a disgraceful data breach.

Unfortunately, they used "Reply all". rofl
Rather like the example I mentioned in my original post you mean?

KaraK

13,787 posts

238 months

Thursday 14th July 2022
quotequote all
Riley Blue said:
One of the members of the public has replied to all drawing attention to the breach "before he takes further action". In 'replying to all', which has again revealed all email addresses, has he also committed a breach?
No - he might be bang to rights on the crime of being a bit thick but everyone's probably done things of similar levels of stupidity (including me!). But from that description he's not the Data Controller or a Processor just a regular old private citizen so what he did was no different to hitting reply-to-all on the amusing photo of a cat trying to walk in socks that his friend Darren sent all his mates last Friday.

matchmaker

9,036 posts

229 months

Thursday 14th July 2022
quotequote all
Riley Blue said:
matchmaker said:
I received an e-mail at work from an organisation which included hundreds of addresses in the "To" field. One recipient furiously replied stating that this was a disgraceful data breach.

Unfortunately, they used "Reply all". rofl
Rather like the example I mentioned in my original post you mean?
Yes.

sim72

4,998 posts

163 months

Thursday 14th July 2022
quotequote all
A member of staff in a school in our Trust did similar, and sent an email to every parent exposing 1100-odd email addresses of every other parent.

The number of people that complained was ... one.

The ICO slapped them on the wrist.

williamp

20,387 posts

302 months

Thursday 14th July 2022
quotequote all
An nhs trust did simmilar and were fined over £78k recently

https://ico.org.uk/action-weve-taken/enforcement/t...