Context
The Information Commissioner’s Office (ICO) has issued a warning to organisations to use alternatives to the blind carbon copy (BCC) email function when sending emails containing sensitive personal information, following a number of business errors. The warning comes as the ICO publishes new guidance to help organisations understand the law and good practice around protecting personal information when sending bulk emails.
Key points to note
- Failure to use BCC correctly in emails is one of the top data breaches reported to the ICO every year.
- Organisations that use and share large amounts of data, including sensitive personal information, should consider using other secure means to send communications, such as bulk email services, so information is not shared with people by mistake.
- To help firms understand the published guidance, in particular the law and good practice, the guidance says what organisations must, should, and could do to comply.
- The guidance contains a short checklist, and covers nine key questions, giving case studies to assist firms in understanding the context of the guidance.
Next actions
None – for information and awareness.