Duckuments logo
Compliance-conscious sharing

GDPR and Sending Documents by Email

Email is not automatically prohibited for personal information, but organisations should understand the risks and choose controls that fit the document.

Specialist view

The question is not whether email is always allowed or always unsafe. It is whether the document, recipient and context justify using email as the delivery method.

3 min readUpdated 23 September 2026

Can personal information be sent by email?

UK GDPR does not simply ban email. The better question is whether email is appropriate for the information being sent, the recipient, the purpose and the likely impact if something goes wrong.

A routine appointment letter and a payroll spreadsheet carry different levels of risk. Email may be acceptable for some low-risk communication, while sensitive attachments may need stronger controls.

Where email creates risk

Email risk often comes from ordinary mistakes: selecting the wrong recipient, forwarding a thread, attaching the wrong file, sending more information than needed or leaving a document in an inbox long after the purpose has passed.

Attachments are particularly hard to control because they create separate copies outside the sender's workflow.

Controls to consider

For lower-risk documents, organisational controls such as address checking, staff training and clear procedures may be enough. For more sensitive documents, consider encryption, recipient verification, secure links, expiry and activity visibility.

Duckuments can help by keeping the document behind a protected link while email is used only to notify the recipient.

Related resources

Keep building safer document habits

All resources