Sending a file that contains other people's data
Most data incidents are not attacks. They are an ordinary file sent to an ordinary recipient with more in it than anyone intended — and the extra is usually invisible in the window you were looking at.
What counts
Personal data is anything that identifies a living person, directly or in combination: name, email, phone, address, national ID, customer number, IP address, a photograph, a voice recording. It does not have to be secret to count — a public phone number in a list of your customers is still personal data, because the list itself is the disclosure.
A narrower category carries stricter rules under both the GDPR and Türkiye's KVKK: health data, biometrics, religious or political affiliation, union membership, criminal records, and sexual life. If a file touches these, the bar for how it moves and how long it persists is meaningfully higher.
Send less: the control that actually works
Everything else on this page is mitigation. Minimisation is prevention, and it is the one step that makes the rest smaller.
- Send the rows they asked for, not the export. "Here is the whole customer table, the one you want is row 4,812" is the most common form this failure takes, and it is entirely voluntary.
- Delete the columns nobody needs. A support ticket rarely requires a date of birth. An invoice query rarely requires the full address history.
- Pseudonymise when the identity is not the point. If the recipient is analysing patterns, a customer ID serves as well as a name and turns a personal-data transfer into a much smaller problem.
- Aggregate when you can. "37 users in this cohort" answers most questions that people request a user list for.
The copies you cannot see
Spreadsheets in particular carry data that is not on screen, and deleting the visible copy does not remove it.
- Pivot table caches. A pivot table stores its own copy of the source data. Delete the source sheet and the pivot still works — because the data is still in the file. Anyone can expand it back out by double-clicking a total.
- Hidden rows, columns and sheets. Hidden is a display state, not a deletion. Right-click → Unhide is all it takes.
- Filtered views. A filter showing 12 rows out of 40,000 is showing you 12 rows. The file has 40,000.
- Comments, tracked changes and earlier revisions in documents that were edited rather than written fresh.
- Black rectangles in PDFs. A shape over text is not redaction; the text is still selectable underneath. See what your files say about you.
How it travels, and for how long
Both frameworks expect measures appropriate to the risk, rather than one prescribed technology. In practice that means three questions you should be able to answer about any transfer:
- Is it encrypted in transit? Effectively table stakes. Anything on HTTPS clears this.
- Who else can read it where it rests? A file sitting decrypted on a third-party server is readable by that third party. Encrypting before upload materially reduces the exposure — see what end-to-end encryption actually protects.
- When does it stop existing? Storage limitation is an explicit principle, not a nicety. A share link with no expiry is an indefinite disclosure waiting for someone to forward it. This is the strongest argument for a transfer over a permanent drive link — see how long a file should stay downloadable.
One organisational point: if you use a third-party service to move personal data on behalf of your employer, that service is a processor, and your employer is supposed to know it is being used. A personal account chosen ad hoc is a gap in that record — which is the real reason IT blocks transfer sites, and why working around the block is the wrong move.
If it goes wrong
A personal-data breach is notifiable to the supervisory authority within 72 hours under the GDPR, and Türkiye's KVKK applies an equivalent 72-hour expectation, with notification to the affected people as well where the risk to them is high.
Two things people get wrong under pressure. The clock starts when the organisation becomes aware, not when someone finishes deciding how bad it is — so an hour spent hoping it is nothing is an hour off the deadline. And a breach is not only an attacker: sending a file to the wrong recipient is a disclosure and counts. Escalate it rather than fixing it quietly; the recall attempt is not the report. See what can be undone and what cannot.
More guides
Six ways to get a file from your phone to a computer — and where each one breaks
Cable, cloud drive, email, messaging apps, local network and transfer services compared: size ceilings, what each one costs you in privacy, and the specific situation where each method falls apart.
Email attachment size limits — and why your file is bigger than you think
The attachment ceiling for Gmail, Outlook, Yahoo, iCloud, Proton and Zoho, why encoding makes your file about 33% larger in transit, and the four ways past the limit.
What end-to-end encryption actually protects — and what it does not
The difference between HTTPS, encryption at rest and true end-to-end encryption, why the key matters more than the cipher, and the four things E2EE will never save you from.
Try SendMyFile
Encrypt a file in your browser and hand it over with a 9-digit code. No account, and it deletes itself.
Try SendMyFile