For most businesses, the mailbox has long ceased to be merely a communication tool. It has become an archive of business knowledge. This is precisely where client arrangements, project histories, management board decisions, and case documentation are kept. From a business perspective, it is hardly surprising that organisations are reluctant to delete such information.
The larger the archive, the greater the risk
The problem is that almost every such message also contains personal data. The larger the archive, the wider the scope of data that could be exposed in the event of mailbox takeover, employee error, or a cyberattack. Therefore, data retention is not merely an obligation arising from the GDPR; it is also one of the fundamental mechanisms for limiting the impact of a potential security incident.
This is, of course, nothing new. The principle of limiting the storage period for personal data has been in force for years. What is new, however, is that the President of the Personal Data Protection Office (UODO), in his latest bulletin, practically demonstrates how to secure mailboxes in situations where an organisation, for various reasons, stores messages longer than would be optimal.
Specific technical and organisational solutions
The authority does not limit itself to reminding organisations of their obligations under the GDPR. It points to specific technical and organisational solutions which – in its view – reduce the risk of breaches. These include multi-factor authentication (MFA), attachment encryption, and the so-called “3-second rule”, which involves a brief verification of the recipient and attachments before sending a message.
Why does this matter? Because UODO explicitly shows which security measures it currently considers appropriate. This means it is precisely through the prism of such safeguards that the authority may subsequently assess an organisation during an audit or following a personal data breach.
Undoubtedly, this is a valuable tip for entrepreneurs. GDPR regulations do not provide an exhaustive list of specific safeguards, limiting themselves to the obligation to implement “appropriate technical and organisational organisational measures”. In practice, assessing what is “appropriate” remains one of the greatest difficulties for data controllers. The latest bulletin partially fills this gap. It does not create new obligations, but it shows which solutions – from the supervisory authority’s perspective – correspond to the proper level of electronic mail security today.
Significance from the accountability perspective
This is also significant from the perspective of accountability. In the event of a personal data breach, the mere occurrence of an incident does not yet predetermine the controller’s liability. What is also crucial is whether the organisation was able to demonstrate that it had previously implemented measures adequate to the identified risk. If the President of UODO points out specific solutions today, such as MFA, attachment encryption, or the “3-second rule”, it is difficult to assume that they will remain without consequence during an audit or explanatory proceeding.
Practical checklist of actions to verify
From the perspective of entrepreneurs, this material should therefore be treated not as yet another reminder of obligations arising from the GDPR, but as a practical checklist of actions that are worth verifying within one’s own organisation right away. All the more so because all UODO recommendations relate to risks that have for years been among the most common causes of personal data breaches – mailbox takeovers, misaddressed messages, or unauthorised disclosure of data. In practice, these are solutions that not only reduce the likelihood of an incident, but can also constitute a significant argument confirming the exercise of due diligence if a breach occurs despite the implemented safeguards.
You can read more on this topic in the article published in Gazeta Prawna. If you wish to discuss how to build a compliance trail that can withstand a UODO audit or check whether your organisation’s data retention policy covers electronic mail, please feel free to contact us.
