

Human error data breaches through email are extremely common. The convenience, familiarity, and relative informality of email mean that your team aren’t always as careful managing personal information through email.
Customer inquiries, complaints and support requests often involve the disclosure of personal information (you can’t usually ask a chatbot for help without entering a swathe of personal information). Then, there’s internal matter management and business operations ‘as usual’ and the high volumes of personal information sharing that can come with that.
But a haphazard approach to personal information management through email comes with risks and costs. Given that security of personal information is currently an OAIC regulatory priority, it also currently comes with an increased risk of enforcement . We’ve outlined technical measures, training, and policies that can help your organisation manage these risks.
In its July-December 2023 Data Breach Report, the Office of the Australian Information Commissioner (OAIC) noted the following scenario highlighting the dangers of lax privacy hygiene in email management:
A health service provider experienced a phishing attack that resulted in unauthorised access to the contents of multiple email accounts.
The health service provider collected a large volume of personal and sensitive information via its email accounts, meaning there was a significant number of records that required review after the breach. The health service provider did not have a data retention policy governing the storage and destruction of information collected via its email accounts. The email accounts contained historical personal information that the entity no longer required and personal information that was already captured in another record management system.
This led to a costly exercise of engaging a third-party service provider to analyse the unstructured data held within the compromised email accounts. It caused lengthy delays in conducting a data review to identify what personal information was compromised.
Had the health service provider established and operationalised a data retention policy, it would more likely have turned its mind to whether it needed or was required to retain the historical personal information in the compromised email accounts. Had the health service provider taken the further step of destroying any personal information it no longer needed or was required to retain, it would have reduced the scale and cost of the data breach.
This approach to email management is extremely common. And, at the same time, email is a common target for cyber criminals. So, better privacy hygiene for business email should be towards the top of the list of priorities for boards and managers in Australia.
Given the extremely broad practice of sharing personal information in organisational emails, it requires a multi-pronged approach to management – through policies, training, and technical measures.
The data you collect and store should be kept for as long as it serves the business purposes for which it was collected, or to meet your legal and compliance obligations and no longer (usually). Beyond this, you should have data retention policies in place to ensure it’s deleted, destroyed, or de-identified.
While every organisation’s needs are different, these are some general rules of thumb for emails that are usually safe to delete by default:
Avoiding personal information sharing in email wherever possible is a good practice. Here are some measures you should include in your email use policies:
You should also create policies relating to how and when employees can share personal information when needed. Ideally, personal information would be shared only via links with a login required to access it.
Since human error is such a significant risk when it comes to data breaches, training is a worthwhile investment. Here’s what your team should learn and receive regular updates on:
They should also receive refresher training on your email management policies, including appropriate email use and data retention.
Finally, it’s helpful to make it clear how your team can ask questions and receive support. This can help to create a culture of privacy awareness and hygiene, as well as allowing your organisation to identify any blind spots, common questions, and areas for improvement.
There are a host of available technical security measures that can be deployed to make your email management more secure and to reduce your risk of a data breach. We think that every email account within your organisation should be protected by multifactor authentication, since it’s affordable and offers significant protections.
From there, you may also consider a combination of the following measures (amongst others):
If your organisation could benefit from improved privacy hygiene, reach out. Our team would love to work with you.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.