Principles of Secure Transmission of Documents via Traditional Mail

23 November 2023

Almost every organization sends correspondence to its contractors, financial institutions, or authorities, such as courts or offices, during the work week. A significant portion of this correspondence is usually sent in traditional (postal) form. Have you considered in your organization how you should do this to ensure compliance with the GDPR? Are the current practices related to addressing letters or verifying the correspondence database in your organization indeed correct?

In order to ensure that outgoing correspondence does not fall into unwanted hands and that the information on the envelope is limited to what is necessary, it is important to be aware of several key principles related to data processing.

First, let us remember the principle of data minimization.

What does it mean? We process, and thus use, only the data that is necessary to accomplish a given task. In this case, it will involve using the data of the recipient and sender of the correspondence. On the envelope, we will write only such data that will guarantee us that the letter reaches the correct recipient. In practice, when sending a letter, for example, to an office, this will include: the first and last name of the person, their position, and the address of the office. Attention should be drawn to a common mistake made when sending registered letters with return receipt. Many people incorrectly indicate a large amount of data in the space for additional information on the back of the return receipt, which may reveal personal data or violate the confidentiality of correspondence. Therefore, in this case, it will be sufficient to indicate, for example, the abbreviation of the department's name (so that the return receipt reaches the person assigned to handle the matter) or to indicate, for instance, the case number or contract number, so that it is easy to identify which matter the correspondence pertains to.

Second, let us apply appropriate security measures.

It is not always possible to avoid the error of sending correspondence to the wrong recipient. However, by implementing appropriate security measures, this risk can be minimized in the following ways:

  • Continuously verify the accuracy of addresses in our recipient database. Each time our contractor's headquarters changes or they change their delivery address, we must remember to update such information.
  • Apply the principle of double verification for correspondence intended for dispatch.
    In large organizations, the best method is one in which one person checks the list of recipients to determine which contractor or institution the correspondence should be sent to today, while another person, who is responsible for preparing the letters for dispatch, checks whether a letter has been prepared and addressed to that recipient today. When, for organizational reasons, one employee is responsible for the correspondence, they should maintain, for example, two separate lists. The first pertains to correspondence intended for dispatch, while the second pertains to already addressed outgoing letters.
  • Let us not forget about training employees. The most common reason for errors is a lack of awareness of the threat. Therefore, we should educate employees about the principles related to the protection of personal data processed by the organization and inform them about the consequences of unauthorized data disclosure. In addition to traditional training, short quizzes sent once a month to employees work exceptionally well, in which they must, for example, identify a threat related to data protection or indicate which action will help protect the organization from violating GDPR regulations.

Thirdly, let us remember what to do in the event of a data breach.

A data breach due to unauthorized disclosure in correspondence is one of the most common breaches reported to the Polish DPA. We must ensure that all employees in our organization know how to behave when a breach occurs. How to do this step by step? At this link you will find the most important information and tips regarding the reporting of personal data breaches from the employee's perspective.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.