Principles of Secure Transmission of Documents via Traditional Mail

27 November 2023

Almost every organization sends correspondence to its contractors, financial institutions, or authorities, such as courts or offices, during the work week. A large portion of this correspondence is usually sent in traditional (postal) form. Have you considered in your organization how you should do this to remain compliant with the GDPR? Are the current practices related to addressing letters or verifying the mailing database correct in your organization? To ensure that outgoing correspondence does not fall into the wrong hands and that the data on the envelope is limited to what is necessary, it is essential to be aware of several key principles related to data processing.

First, let us remember the principle of data minimization

What does it mean? We process, and therefore use, only the data that is necessary to accomplish a given task. In this case, it will involve the use of the data of the recipient and sender of the correspondence. On the envelope, we will write only such data that will ensure that the letter reaches the correct recipient. In practice, when sending a letter, for example, to an office, this will include: the first and last name of the person, their position, and the address of the office. It is important to note the frequently repeated mistake when sending registered letters with return receipt. Many people incorrectly indicate a lot of data in the space for additional information on the back of the return receipt, which may reveal personal data or violate the confidentiality of correspondence. Therefore, in this case, it will be sufficient to indicate, for example, the abbreviation of the department's name (so that the return receipt reaches the person assigned to handle the matter) or to indicate, for example, the case number or contract number, so that it is easy to identify which matter the correspondence pertains to.

Second, let us apply appropriate security measures

It is not always possible to avoid the error of sending correspondence to the wrong recipient. However, by applying appropriate security measures, this risk can be minimized in the following ways:

  • Continuously verify the accuracy of addresses in our recipient database. Each time our contractor's office changes or they change their delivery address, we must remember to update such information.
  • Do not forget about training employees. The most common reason for errors is a lack of awareness of the threat. Therefore, we should educate employees about the principles related to the protection of data processed by the organization and inform them about the consequences of unauthorized data disclosure. In addition to traditional training, short quizzes sent once a month to employees, in which they must, for example, identify a data protection threat or indicate which action will protect the organization from violating GDPR regulations, work very well.

Third, let us remember what to do in the event of a data breach

A data breach through unauthorized disclosure in correspondence is one of the most common violations reported to the Polish DPA. We must ensure that all employees in our organization know how to behave when a breach occurs. How to do this step by step? Under this link, you will find the most important information and tips regarding the reporting of personal data breaches from the employee's perspective.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.