GDPR and Sending Documents by Email
Email is not automatically prohibited for personal information, but organisations should understand the risks and choose controls that fit the document.
Specialist view
The question is not whether email is always allowed or always unsafe. It is whether the document, recipient and context justify using email as the delivery method.
Can personal information be sent by email?
UK GDPR does not simply ban email. The better question is whether email is appropriate for the information being sent, the recipient, the purpose and the likely impact if something goes wrong.
A routine appointment letter and a payroll spreadsheet carry different levels of risk. Email may be acceptable for some low-risk communication, while sensitive attachments may need stronger controls.
Where email creates risk
Email risk often comes from ordinary mistakes: selecting the wrong recipient, forwarding a thread, attaching the wrong file, sending more information than needed or leaving a document in an inbox long after the purpose has passed.
Attachments are particularly hard to control because they create separate copies outside the sender's workflow.
Controls to consider
For lower-risk documents, organisational controls such as address checking, staff training and clear procedures may be enough. For more sensitive documents, consider encryption, recipient verification, secure links, expiry and activity visibility.
Duckuments can help by keeping the document behind a protected link while email is used only to notify the recipient.
