Sending a file that contains other people's data

Most data incidents are not attacks. They are an ordinary file sent to an ordinary recipient with more in it than anyone intended — and the extra is usually invisible in the window you were looking at.

Updated:

What counts

Personal data is anything that identifies a living person, directly or in combination: name, email, phone, address, national ID, customer number, IP address, a photograph, a voice recording. It does not have to be secret to count — a public phone number in a list of your customers is still personal data, because the list itself is the disclosure.

A narrower category carries stricter rules under both the GDPR and Türkiye's KVKK: health data, biometrics, religious or political affiliation, union membership, criminal records, and sexual life. If a file touches these, the bar for how it moves and how long it persists is meaningfully higher.

Send less: the control that actually works

Everything else on this page is mitigation. Minimisation is prevention, and it is the one step that makes the rest smaller.

Advertisement

The copies you cannot see

Spreadsheets in particular carry data that is not on screen, and deleting the visible copy does not remove it.

How it travels, and for how long

Both frameworks expect measures appropriate to the risk, rather than one prescribed technology. In practice that means three questions you should be able to answer about any transfer:

  1. Is it encrypted in transit? Effectively table stakes. Anything on HTTPS clears this.
  2. Who else can read it where it rests? A file sitting decrypted on a third-party server is readable by that third party. Encrypting before upload materially reduces the exposure — see what end-to-end encryption actually protects.
  3. When does it stop existing? Storage limitation is an explicit principle, not a nicety. A share link with no expiry is an indefinite disclosure waiting for someone to forward it. This is the strongest argument for a transfer over a permanent drive link — see how long a file should stay downloadable.

One organisational point: if you use a third-party service to move personal data on behalf of your employer, that service is a processor, and your employer is supposed to know it is being used. A personal account chosen ad hoc is a gap in that record — which is the real reason IT blocks transfer sites, and why working around the block is the wrong move.

If it goes wrong

A personal-data breach is notifiable to the supervisory authority within 72 hours under the GDPR, and Türkiye's KVKK applies an equivalent 72-hour expectation, with notification to the affected people as well where the risk to them is high.

Two things people get wrong under pressure. The clock starts when the organisation becomes aware, not when someone finishes deciding how bad it is — so an hour spent hoping it is nothing is an hour off the deadline. And a breach is not only an attacker: sending a file to the wrong recipient is a disclosure and counts. Escalate it rather than fixing it quietly; the recall attempt is not the report. See what can be undone and what cannot.

More guides

Try SendMyFile

Encrypt a file in your browser and hand it over with a 9-digit code. No account, and it deletes itself.

Try SendMyFile