Copied on Mail - Data Protection
Copied on Mail - Data Protection
Author
Discussion

tighnamara

Original Poster:

2,822 posts

182 months

Thursday 26th August 2021
quotequote all
Not sure if the correct forum.....

Received 3 mails this afternoon (copied) from a car dealer, none of the mails are for me. These mails include finance details, mobility refusal, scanned documents for reg transfer with names addresses etc.

Now I will delete and nothing to do with me, but should I inform the person who sent them incorrectly, the company or the persons whose details they have disclosed or just do nothing.

I’m swayed to inform the individual so they can act on it rather than the company who will most likely not inform them.

I am copied on all and the other recipients are all internal to the dealer, can’t see how I would be copied unless there is a glitch in their system. I would not be happy with any of my details being sent out incorrectly to someone’s e mail address.

As I said the mails are of no interest to me but want to make sure they act on the mistake to ensure this can’t happen again and wondering what else has been sent by mistake previously.

All are from the salesman I was dealing with, just can’t see how he would have picked up my name incorrectly on the mail.

Dealer is a large national company and are known to be quite ruthless........



The Rotrex Kid

34,742 posts

189 months

Thursday 26th August 2021
quotequote all
Your email probably starts in the same way as one of their internal emails.

You can let them know, I’m sure they’ll apologise, but personally, just delete and move on.

bitchstewie

67,440 posts

239 months

Thursday 26th August 2021
quotequote all
Nice way might just be to reply-all.

Not so nice way would be ask who the chain's Data Protection Officer is.

Are they all from the same sender and are they "template" emails or have they obviously been individually composed and does your name look anything like the people they're meant to go to?

Wondering if it's as simple as Outlook Auto-Complete (catches a lot of people out).

2 sMoKiN bArReLs

32,006 posts

264 months

Thursday 26th August 2021
quotequote all
I was once copied in an email chain where I knew none of the recipients. It was a drama about a cracked wall that rumbled on for years. Every now and again I'd pipe up with a pithy comment, or who the hell are you people? It took years for them to remove me. Now I'm left wondering who eventually paid for the repair hehe

Ham_and_Jam

3,677 posts

126 months

Thursday 26th August 2021
quotequote all
It’s happened to me, where I’ve sent an email to the wrong person and company from my work account. It’s a bit embarrassing and fortunately I’ve never disclosed anything confidential.

It’s a bit like when you make a phone call and you’ve hit the wrong contact, can be quite funny if you know the person well enough.

OP, I reckon if you’ve never done any of those things in your life then make a massive song and dance about it. Maybe they could even take him down the disciplinary route. Or you could discreetly let him know that he’s dropped a clanger and not too worry you’ve securely disposed of the emails. Your choice.

tighnamara

Original Poster:

2,822 posts

182 months

Thursday 26th August 2021
quotequote all
Thanks all, enough feedback for me, just wondered others opinions, will just drop him a mail and leave it at that.

TonyRPH

13,538 posts

197 months

Thursday 26th August 2021
quotequote all
I believe that technically it's a breach of GDPR and depending on the severity the ICO should be notified - however that is the 'nasty' approach.

At the very least, the data protection officer of the company concerned should be notified, and hopefully the sender of the email will be educated to ensure that the same mistake is not made again.

You also need to look at it as a way of protecting yourself - you wouldn't want any accusations of sharing data from the parties concerned, should they find out you received their email.

Riley Blue

23,205 posts

255 months

Friday 27th August 2021
quotequote all
I once received an email from my financial adviser's office that had been sent to all their clients, each of whose email address was visible, including local business men, politicians, some celebrities etc. etc.

I wrote back, pointing out the magnitude of their error and received a profound apology and thanks for bringing it to their attention. Any repercussions were theirs to deal with.

tighnamara

Original Poster:

2,822 posts

182 months

Friday 27th August 2021
quotequote all
TonyRPH said:
I believe that technically it's a breach of GDPR and depending on the severity the ICO should be notified - however that is the 'nasty' approach.

At the very least, the data protection officer of the company concerned should be notified, and hopefully the sender of the email will be educated to ensure that the same mistake is not made again.

You also need to look at it as a way of protecting yourself - you wouldn't want any accusations of sharing data from the parties concerned, should they find out you received their email.
Just back from bike run this morning so not contacted anyone yet, received another 3 mails this morning with scanned driving licenses and finance details.
Was just going to mail the person but think I will contact the data protection contact at the company themselves, quite uncomfortable with the information being received.

ian in lancs

3,853 posts

227 months

Friday 27th August 2021
quotequote all
tighnamara said:
Just back from bike run this morning so not contacted anyone yet, received another 3 mails this morning with scanned driving licenses and finance details.
Was just going to mail the person but think I will contact the data protection contact at the company themselves, quite uncomfortable with the information being received.
Contact the company data protection officer so cause can be properly investigated and corrective measures put in place. Thats their job. Just replying to sender might brush it under the carpet.

romeogolf

2,112 posts

148 months

Friday 27th August 2021
quotequote all
It is a breach of GDPC and the ICO should be informed - However if the dealer themselves informs them it's usually just for notification purposes and little will come of it as a first offense. Unless you have a reason to believe this is a habitual mistake and they're likely to do it with your own details etc, I would leave it to them.

I would reply to the email and let them know it wasn't intended for you but you have deleted it. I'm on the fence as to whether to reply all or just to the sender.

Reply all might embarrass the sender unnecessarily, but it would also stop anyone else copied in from replying again with further details. It's highly unlikely anyone is going to get more than a "just be more careful in future" email from their data officer.

mmm-five

12,331 posts

313 months

Friday 27th August 2021
quotequote all
I was on the other end of this once...but I blame my boss.

We'd finally finished a drawn-out contract re-negotiation, and had spotted something in the old contract that meant we didn't have to pay any compensation for terminating (if we chose to).

The boss came out of the session, asked me to type up the notes, and send them to all the attendees...which I did!

A day later the boss comes back to me fuming, and asking why I'd told the other party that we'd spotted that clause about no compensation for early termination...I replied that's that what he asked, and he pointed out that he only meant it to be sent out to "all our side of the team".

Luckily, it came to naught, as the other party replied to the email, directly to my boss, telling him that they should find the signed copy of the contract, as that error was spotted years ago and there was a £10-£100m early-termination clause (depending on the term) in the final version.

matchmaker

9,039 posts

229 months

Friday 27th August 2021
quotequote all
I received an e-mail at work where the sender had put all 150 recipients e-mail addresses into the "to" field, instead of using "bcc". One recipient took umbrage at their e-mail address being sent out to 149 other people and e-mailed the sender to express their concern at this breach of their privacy.

Unfortunately, they compounded the error by using "reply all" rolleyes

wrong_turn

509 posts

219 months

Friday 27th August 2021
quotequote all
I've been guilty in the past, not with confidential data though.

I got a reply back saying "I think you need the other Tony" or something like that. The addresses were something like Tony@ and Tony.L@, as the company hadn't accounted for there being more than one Tony until the second one turned up.

If it seems like a mistake I'd inform the sender and confirm the data is not at risk and will be deleted.

Nickyboy

6,824 posts

263 months

Friday 27th August 2021
quotequote all
I had the same recently, an estate agent i had used in the past copied me instead of another colleague with a similar name into a conversation with a customer with attachments including proper details contact details etc of tenants. Obviously in breach of GDPR, i emailed them back pointing out their mistake and the consequences, they apologised profusely, i deleted the emails and got on with my life. Honest mistake, no harm done

55palfers

6,367 posts

193 months

Friday 27th August 2021
quotequote all
Nobody takes 2 minutes to proof read their work any more.


PhilboSE

6,117 posts

255 months

Saturday 28th August 2021
quotequote all
romeogolf said:
It is a breach of GDPC and the ICO should be informed
It is a breach and the business Data Protection Officer should be informed. The business DPO then has to create an entry into their incident log, and the business policy will define the procedure from there.

The ICO does not have to be informed, the DPO is allowed to make a judgement on whether the scale of the breach requires notification. They are however required to record their decision and their justification for it.

The OP can notify the sender of the error, and his destruction of the data, and rely on that persons ability to follow their internal policies, or the OP can notify the company DPO directly if they can be identified.

The nature and scope of this breach is very minor, and apart from record the incident, notify the intended recipient, and do some follow up information security training with the staff, I wouldn’t expect it to go any further.

In the scale of things this is an incredibly minor incident and not worth getting over excited about.

Now, whether the business even has a nominated DPO or a documented policy is another issue. Most businesses are blithely using IT any don’t even think about security. There is a very simple baseline government standard - CyberEssentials - which has a very low bar but most businesses i hazard have never even heard of it let alone follow it.

darreni

4,522 posts

299 months

Saturday 28th August 2021
quotequote all
In the past when I've received stuff like this, i reply to the sender saying "i don't think this was intended for me", & delete the original. Job done.

tighnamara

Original Poster:

2,822 posts

182 months

Saturday 28th August 2021
quotequote all
Have left it for the company to deal with internally, agree it may seem minor but that is because I’m not going to do anything with the information.

I am sure the persons who’s details (driving licences, address, finance details) may not see it as minor.

I would have thought that in this day and age a company that size would have a more robust system internally to pass sensitive information.

Didn’t affect me but I’m sure Mrs X and Mr Y wouldn’t be best pleased that their data was being sent out to an incorrect e mail address.

Thanks for the replies.

PhilboSE

6,117 posts

255 months

Saturday 28th August 2021
quotequote all
tighnamara said:
I am sure the persons who’s details (driving licences, address, finance details) may not see it as minor.
No I’m sure they wouldn’t, but in the scheme of infosec a single incident caused by human error, where the impact of the breach is contained and easily preventable in the future is actually about as minor as it gets.

Systematic or corporate failures, or the loss of large amounts of sensitive data, are the type of thing that are classed as major and need to be notified to the ICO.