First, let us remember the principle of data minimization
What does it mean? We process, and therefore use, only the data that is necessary to accomplish a given task. In this case, it will involve the use of the data of the recipient and sender of the correspondence. On the envelope, we will write only such data that will ensure that the letter reaches the correct recipient. In practice, when sending a letter, for example, to an office, this will include: the first and last name of the person, their position, and the address of the office. It is important to note the frequently repeated mistake when sending registered letters with return receipt. Many people incorrectly indicate a lot of data in the space for additional information on the back of the return receipt, which may reveal personal data or violate the confidentiality of correspondence. Therefore, in this case, it will be sufficient to indicate, for example, the abbreviation of the department's name (so that the return receipt reaches the person assigned to handle the matter) or to indicate, for example, the case number or contract number, so that it is easy to identify which matter the correspondence pertains to.
Second, let us apply appropriate security measures
It is not always possible to avoid the error of sending correspondence to the wrong recipient. However, by applying appropriate security measures, this risk can be minimized in the following ways:
- Continuously verify the accuracy of addresses in our recipient database. Each time our contractor's office changes or they change their delivery address, we must remember to update such information.
- Do not forget about training employees. The most common reason for errors is a lack of awareness of the threat. Therefore, we should educate employees about the principles related to the protection of data processed by the organization and inform them about the consequences of unauthorized data disclosure. In addition to traditional training, short quizzes sent once a month to employees, in which they must, for example, identify a data protection threat or indicate which action will protect the organization from violating GDPR regulations, work very well.
Third, let us remember what to do in the event of a data breach
A data breach through unauthorized disclosure in correspondence is one of the most common violations reported to the Polish DPA. We must ensure that all employees in our organization know how to behave when a breach occurs. How to do this step by step? Under this link, you will find the most important information and tips regarding the reporting of personal data breaches from the employee's perspective.

