Copied on Mail - Data Protection
Discussion
Not sure if the correct forum.....
Received 3 mails this afternoon (copied) from a car dealer, none of the mails are for me. These mails include finance details, mobility refusal, scanned documents for reg transfer with names addresses etc.
Now I will delete and nothing to do with me, but should I inform the person who sent them incorrectly, the company or the persons whose details they have disclosed or just do nothing.
I’m swayed to inform the individual so they can act on it rather than the company who will most likely not inform them.
I am copied on all and the other recipients are all internal to the dealer, can’t see how I would be copied unless there is a glitch in their system. I would not be happy with any of my details being sent out incorrectly to someone’s e mail address.
As I said the mails are of no interest to me but want to make sure they act on the mistake to ensure this can’t happen again and wondering what else has been sent by mistake previously.
All are from the salesman I was dealing with, just can’t see how he would have picked up my name incorrectly on the mail.
Dealer is a large national company and are known to be quite ruthless........
Received 3 mails this afternoon (copied) from a car dealer, none of the mails are for me. These mails include finance details, mobility refusal, scanned documents for reg transfer with names addresses etc.
Now I will delete and nothing to do with me, but should I inform the person who sent them incorrectly, the company or the persons whose details they have disclosed or just do nothing.
I’m swayed to inform the individual so they can act on it rather than the company who will most likely not inform them.
I am copied on all and the other recipients are all internal to the dealer, can’t see how I would be copied unless there is a glitch in their system. I would not be happy with any of my details being sent out incorrectly to someone’s e mail address.
As I said the mails are of no interest to me but want to make sure they act on the mistake to ensure this can’t happen again and wondering what else has been sent by mistake previously.
All are from the salesman I was dealing with, just can’t see how he would have picked up my name incorrectly on the mail.
Dealer is a large national company and are known to be quite ruthless........
Nice way might just be to reply-all.
Not so nice way would be ask who the chain's Data Protection Officer is.
Are they all from the same sender and are they "template" emails or have they obviously been individually composed and does your name look anything like the people they're meant to go to?
Wondering if it's as simple as Outlook Auto-Complete (catches a lot of people out).
Not so nice way would be ask who the chain's Data Protection Officer is.
Are they all from the same sender and are they "template" emails or have they obviously been individually composed and does your name look anything like the people they're meant to go to?
Wondering if it's as simple as Outlook Auto-Complete (catches a lot of people out).
I was once copied in an email chain where I knew none of the recipients. It was a drama about a cracked wall that rumbled on for years. Every now and again I'd pipe up with a pithy comment, or who the hell are you people? It took years for them to remove me. Now I'm left wondering who eventually paid for the repair 

It’s happened to me, where I’ve sent an email to the wrong person and company from my work account. It’s a bit embarrassing and fortunately I’ve never disclosed anything confidential.
It’s a bit like when you make a phone call and you’ve hit the wrong contact, can be quite funny if you know the person well enough.
OP, I reckon if you’ve never done any of those things in your life then make a massive song and dance about it. Maybe they could even take him down the disciplinary route. Or you could discreetly let him know that he’s dropped a clanger and not too worry you’ve securely disposed of the emails. Your choice.
It’s a bit like when you make a phone call and you’ve hit the wrong contact, can be quite funny if you know the person well enough.
OP, I reckon if you’ve never done any of those things in your life then make a massive song and dance about it. Maybe they could even take him down the disciplinary route. Or you could discreetly let him know that he’s dropped a clanger and not too worry you’ve securely disposed of the emails. Your choice.
I believe that technically it's a breach of GDPR and depending on the severity the ICO should be notified - however that is the 'nasty' approach.
At the very least, the data protection officer of the company concerned should be notified, and hopefully the sender of the email will be educated to ensure that the same mistake is not made again.
You also need to look at it as a way of protecting yourself - you wouldn't want any accusations of sharing data from the parties concerned, should they find out you received their email.
At the very least, the data protection officer of the company concerned should be notified, and hopefully the sender of the email will be educated to ensure that the same mistake is not made again.
You also need to look at it as a way of protecting yourself - you wouldn't want any accusations of sharing data from the parties concerned, should they find out you received their email.
I once received an email from my financial adviser's office that had been sent to all their clients, each of whose email address was visible, including local business men, politicians, some celebrities etc. etc.
I wrote back, pointing out the magnitude of their error and received a profound apology and thanks for bringing it to their attention. Any repercussions were theirs to deal with.
I wrote back, pointing out the magnitude of their error and received a profound apology and thanks for bringing it to their attention. Any repercussions were theirs to deal with.
TonyRPH said:
I believe that technically it's a breach of GDPR and depending on the severity the ICO should be notified - however that is the 'nasty' approach.
At the very least, the data protection officer of the company concerned should be notified, and hopefully the sender of the email will be educated to ensure that the same mistake is not made again.
You also need to look at it as a way of protecting yourself - you wouldn't want any accusations of sharing data from the parties concerned, should they find out you received their email.
Just back from bike run this morning so not contacted anyone yet, received another 3 mails this morning with scanned driving licenses and finance details.At the very least, the data protection officer of the company concerned should be notified, and hopefully the sender of the email will be educated to ensure that the same mistake is not made again.
You also need to look at it as a way of protecting yourself - you wouldn't want any accusations of sharing data from the parties concerned, should they find out you received their email.
Was just going to mail the person but think I will contact the data protection contact at the company themselves, quite uncomfortable with the information being received.
tighnamara said:
Just back from bike run this morning so not contacted anyone yet, received another 3 mails this morning with scanned driving licenses and finance details.
Was just going to mail the person but think I will contact the data protection contact at the company themselves, quite uncomfortable with the information being received.
Contact the company data protection officer so cause can be properly investigated and corrective measures put in place. Thats their job. Just replying to sender might brush it under the carpet.Was just going to mail the person but think I will contact the data protection contact at the company themselves, quite uncomfortable with the information being received.
It is a breach of GDPC and the ICO should be informed - However if the dealer themselves informs them it's usually just for notification purposes and little will come of it as a first offense. Unless you have a reason to believe this is a habitual mistake and they're likely to do it with your own details etc, I would leave it to them.
I would reply to the email and let them know it wasn't intended for you but you have deleted it. I'm on the fence as to whether to reply all or just to the sender.
Reply all might embarrass the sender unnecessarily, but it would also stop anyone else copied in from replying again with further details. It's highly unlikely anyone is going to get more than a "just be more careful in future" email from their data officer.
I would reply to the email and let them know it wasn't intended for you but you have deleted it. I'm on the fence as to whether to reply all or just to the sender.
Reply all might embarrass the sender unnecessarily, but it would also stop anyone else copied in from replying again with further details. It's highly unlikely anyone is going to get more than a "just be more careful in future" email from their data officer.
I was on the other end of this once...but I blame my boss.
We'd finally finished a drawn-out contract re-negotiation, and had spotted something in the old contract that meant we didn't have to pay any compensation for terminating (if we chose to).
The boss came out of the session, asked me to type up the notes, and send them to all the attendees...which I did!
A day later the boss comes back to me fuming, and asking why I'd told the other party that we'd spotted that clause about no compensation for early termination...I replied that's that what he asked, and he pointed out that he only meant it to be sent out to "all our side of the team".
Luckily, it came to naught, as the other party replied to the email, directly to my boss, telling him that they should find the signed copy of the contract, as that error was spotted years ago and there was a £10-£100m early-termination clause (depending on the term) in the final version.
We'd finally finished a drawn-out contract re-negotiation, and had spotted something in the old contract that meant we didn't have to pay any compensation for terminating (if we chose to).
The boss came out of the session, asked me to type up the notes, and send them to all the attendees...which I did!
A day later the boss comes back to me fuming, and asking why I'd told the other party that we'd spotted that clause about no compensation for early termination...I replied that's that what he asked, and he pointed out that he only meant it to be sent out to "all our side of the team".
Luckily, it came to naught, as the other party replied to the email, directly to my boss, telling him that they should find the signed copy of the contract, as that error was spotted years ago and there was a £10-£100m early-termination clause (depending on the term) in the final version.
I received an e-mail at work where the sender had put all 150 recipients e-mail addresses into the "to" field, instead of using "bcc". One recipient took umbrage at their e-mail address being sent out to 149 other people and e-mailed the sender to express their concern at this breach of their privacy.
Unfortunately, they compounded the error by using "reply all"
Unfortunately, they compounded the error by using "reply all"

I've been guilty in the past, not with confidential data though.
I got a reply back saying "I think you need the other Tony" or something like that. The addresses were something like Tony@ and Tony.L@, as the company hadn't accounted for there being more than one Tony until the second one turned up.
If it seems like a mistake I'd inform the sender and confirm the data is not at risk and will be deleted.
I got a reply back saying "I think you need the other Tony" or something like that. The addresses were something like Tony@ and Tony.L@, as the company hadn't accounted for there being more than one Tony until the second one turned up.
If it seems like a mistake I'd inform the sender and confirm the data is not at risk and will be deleted.
I had the same recently, an estate agent i had used in the past copied me instead of another colleague with a similar name into a conversation with a customer with attachments including proper details contact details etc of tenants. Obviously in breach of GDPR, i emailed them back pointing out their mistake and the consequences, they apologised profusely, i deleted the emails and got on with my life. Honest mistake, no harm done
romeogolf said:
It is a breach of GDPC and the ICO should be informed
It is a breach and the business Data Protection Officer should be informed. The business DPO then has to create an entry into their incident log, and the business policy will define the procedure from there. The ICO does not have to be informed, the DPO is allowed to make a judgement on whether the scale of the breach requires notification. They are however required to record their decision and their justification for it.
The OP can notify the sender of the error, and his destruction of the data, and rely on that persons ability to follow their internal policies, or the OP can notify the company DPO directly if they can be identified.
The nature and scope of this breach is very minor, and apart from record the incident, notify the intended recipient, and do some follow up information security training with the staff, I wouldn’t expect it to go any further.
In the scale of things this is an incredibly minor incident and not worth getting over excited about.
Now, whether the business even has a nominated DPO or a documented policy is another issue. Most businesses are blithely using IT any don’t even think about security. There is a very simple baseline government standard - CyberEssentials - which has a very low bar but most businesses i hazard have never even heard of it let alone follow it.
Have left it for the company to deal with internally, agree it may seem minor but that is because I’m not going to do anything with the information.
I am sure the persons who’s details (driving licences, address, finance details) may not see it as minor.
I would have thought that in this day and age a company that size would have a more robust system internally to pass sensitive information.
Didn’t affect me but I’m sure Mrs X and Mr Y wouldn’t be best pleased that their data was being sent out to an incorrect e mail address.
Thanks for the replies.
I am sure the persons who’s details (driving licences, address, finance details) may not see it as minor.
I would have thought that in this day and age a company that size would have a more robust system internally to pass sensitive information.
Didn’t affect me but I’m sure Mrs X and Mr Y wouldn’t be best pleased that their data was being sent out to an incorrect e mail address.
Thanks for the replies.
tighnamara said:
I am sure the persons who’s details (driving licences, address, finance details) may not see it as minor.
No I’m sure they wouldn’t, but in the scheme of infosec a single incident caused by human error, where the impact of the breach is contained and easily preventable in the future is actually about as minor as it gets.Systematic or corporate failures, or the loss of large amounts of sensitive data, are the type of thing that are classed as major and need to be notified to the ICO.
Forums | Speed, Plod & the Law | Top of Page | What's New | My Stuff


