Data breach question
Discussion
A public sector organisation has recently committed a data breach by sending an email in which all recipients' (who are members of the public and staff) email addresses are visible. They've apologised, reported themselves and the breach is under investigation.
One of the members of the public has replied to all drawing attention to the breach "before he takes further action". In 'replying to all', which has again revealed all email addresses, has he also committed a breach?
Before you ask - no, it wasn't me!
One of the members of the public has replied to all drawing attention to the breach "before he takes further action". In 'replying to all', which has again revealed all email addresses, has he also committed a breach?
Before you ask - no, it wasn't me!
No, he hasn't committed a breach as he didn't have all of their email addresses in the first place. What he has done is exploited the breach caused by the original sender.
I assume the ICO has been engaged and they will be investigating accordingly. Exposing email addresses isn't huge in itself and depending upon the content of the mail I doubt much will happen.
I assume the ICO has been engaged and they will be investigating accordingly. Exposing email addresses isn't huge in itself and depending upon the content of the mail I doubt much will happen.
Freakuk said:
Exposing email addresses isn't huge in itself and depending upon the content of the mail I doubt much will happen.
If it's a fairly innocuous list (eg. a council sending a circular to a list of licensed premises) then I agree nothing will happen. The problem comes if membership of the list is likely to reveal something about the recipient, eg. a while back an HIV clinic CCd all patients onto an email rather than BCC.matchmaker said:
I received an e-mail at work from an organisation which included hundreds of addresses in the "To" field. One recipient furiously replied stating that this was a disgraceful data breach.
Unfortunately, they used "Reply all".
Rather like the example I mentioned in my original post you mean?Unfortunately, they used "Reply all".

Riley Blue said:
One of the members of the public has replied to all drawing attention to the breach "before he takes further action". In 'replying to all', which has again revealed all email addresses, has he also committed a breach?
No - he might be bang to rights on the crime of being a bit thick but everyone's probably done things of similar levels of stupidity (including me!). But from that description he's not the Data Controller or a Processor just a regular old private citizen so what he did was no different to hitting reply-to-all on the amusing photo of a cat trying to walk in socks that his friend Darren sent all his mates last Friday.Riley Blue said:
matchmaker said:
I received an e-mail at work from an organisation which included hundreds of addresses in the "To" field. One recipient furiously replied stating that this was a disgraceful data breach.
Unfortunately, they used "Reply all".
Rather like the example I mentioned in my original post you mean?Unfortunately, they used "Reply all".

An nhs trust did simmilar and were fined over £78k recently
https://ico.org.uk/action-weve-taken/enforcement/t...
https://ico.org.uk/action-weve-taken/enforcement/t...
Gassing Station | Speed, Plod & the Law | Top of Page | What's New | My Stuff


