In order to ensure that outgoing correspondence does not fall into unwanted hands and that the information on the envelope is limited to what is necessary, it is important to be aware of several key principles related to data processing.
First, let us remember the principle of data minimization.
What does it mean? We process, and thus use, only the data that is necessary to accomplish a given task. In this case, it will involve using the data of the recipient and sender of the correspondence. On the envelope, we will write only such data that will guarantee us that the letter reaches the correct recipient. In practice, when sending a letter, for example, to an office, this will include: the first and last name of the person, their position, and the address of the office. Attention should be drawn to a common mistake made when sending registered letters with return receipt. Many people incorrectly indicate a large amount of data in the space for additional information on the back of the return receipt, which may reveal personal data or violate the confidentiality of correspondence. Therefore, in this case, it will be sufficient to indicate, for example, the abbreviation of the department's name (so that the return receipt reaches the person assigned to handle the matter) or to indicate, for instance, the case number or contract number, so that it is easy to identify which matter the correspondence pertains to.
Second, let us apply appropriate security measures.
It is not always possible to avoid the error of sending correspondence to the wrong recipient. However, by implementing appropriate security measures, this risk can be minimized in the following ways:
- Continuously verify the accuracy of addresses in our recipient database. Each time our contractor's headquarters changes or they change their delivery address, we must remember to update such information.
- Apply the principle of double verification for correspondence intended for dispatch.
In large organizations, the best method is one in which one person checks the list of recipients to determine which contractor or institution the correspondence should be sent to today, while another person, who is responsible for preparing the letters for dispatch, checks whether a letter has been prepared and addressed to that recipient today. When, for organizational reasons, one employee is responsible for the correspondence, they should maintain, for example, two separate lists. The first pertains to correspondence intended for dispatch, while the second pertains to already addressed outgoing letters. - Let us not forget about training employees. The most common reason for errors is a lack of awareness of the threat. Therefore, we should educate employees about the principles related to the protection of personal data processed by the organization and inform them about the consequences of unauthorized data disclosure. In addition to traditional training, short quizzes sent once a month to employees work exceptionally well, in which they must, for example, identify a threat related to data protection or indicate which action will help protect the organization from violating GDPR regulations.
Thirdly, let us remember what to do in the event of a data breach.
A data breach due to unauthorized disclosure in correspondence is one of the most common breaches reported to the Polish DPA. We must ensure that all employees in our organization know how to behave when a breach occurs. How to do this step by step? At this link you will find the most important information and tips regarding the reporting of personal data breaches from the employee's perspective.

