May I send personal data by email? (GDPR)
Is it allowed? The short answer
The GDPR doesn't ban email. It does require you to take "appropriate technical and organisational measures" to protect personal data. In plain language: you may send mail, as long as you reasonably cover the risk.
What is "appropriate" depends on how sensitive the data is. An appointment confirmation with a name requires less than a medical file or a copy of an ID document. The more sensitive the data, the heavier the security you may expect.
Why it matters
A frequently heard remark from practice: "email is inherently insecure". That's true at its core. An ordinary email travels across servers you don't manage yourself, and without measures a message can in principle be intercepted along the way or end up somewhere it shouldn't.
But there's a nuance against that: with encrypted connections (such as forced TLS), email is perfectly usable for many purposes. The message is then protected in transit between the servers. For a GDPR-sensitive professional (a doctor, lawyer or bookkeeper) that difference is important: it determines whether you can comfortably mail a piece of customer data or whether you need an extra lock. You can read more about that technique in forced TLS and encrypted connections explained.
It helps not to make the discussion black and white. "Email may never be used for personal data" is too strict and unworkable in practice; "email is always secure enough" is too easy. The truth sits in between: it depends on the sensitivity of the data and on the measures you take. That's exactly why a secure, European foundation is so valuable, because it shifts your default to the safe side.
How to send personal data safely by email
A practical guide, from light to heavy:
- Only send what's necessary. The less personal data in a mail, the smaller the risk. Leave out what doesn't need to be in it.
- Ensure encrypted connections. Use a provider that supports encrypted connections (TLS), so messages are protected in transit.
- Secure the access. A strong password and two-factor authentication (2FA) prevent someone else from getting into your mailbox.
- Check the addressee. A wrong address is one of the most common causes of data breaches. Look twice before you send.
- Work with a provider that hosts in Europe. Then your data falls under the GDPR. See European email hosting on your own domain.
For the broader approach, with more practical tips, there's secure emailing: a practical guide.
What's usually fine, and what requires more care?
A feel for practice often helps more than knowing the rules by heart. Roughly:
Usually fine by email, provided it's secured:
- an appointment confirmation with a name and date
- a quote or invoice with name and address details
- ordinary customer correspondence without sensitive content
Requires extra care or a safer channel:
- health or medical data
- a copy of an ID document or national registration number
- large files or exports with many people in them
- data on religion, ethnicity or a criminal record
This is a guideline, not a law. The core is always the same weighing-up: how sensitive is the data, and have I reasonably covered the risk? If you're in doubt about a specific case, then a quick consultation with a specialist is wiser than guessing.
What to watch out for
- Special categories of personal data require more. Health data, data on race, religion or a criminal record fall under a heavier regime. An ordinary, unsecured mail is generally not suitable for that. If you work with medical or patient data, read may I send medical data by email (GDPR).
- Large amounts or whole files. A single piece of data is different from an export with hundreds of customers. For larger sensitive sends, an extra secure channel can be wiser.
- Recipient beyond your control. You secure your own side, but not the other person's. Bear that in mind with truly sensitive content.
- Don't keep it forever. Old mails with personal data are a risk too. Clear out what you no longer need.
These remain general points of attention. For your specific situation, certainly with sensitive data, consult a specialist or the Belgian Data Protection Authority (GBA) when in doubt.
And at Mailflux
Mailflux gives you a solid foundation to mail carefully. Your mailboxes are on your own domain, hosted in Europe and GDPR-compliant, and no one reads along without being asked. Every plan includes filtering against spam, phishing and malware, automatic backups and optional two-factor authentication, so you can secure access to your mailbox well.
That way you cover a large part of the "appropriate measures" the GDPR expects, without having to manage a server park yourself. Exactly what you must do in a specific, sensitive case remains a matter of tailoring; for that, consult a specialist when in doubt.
Important to remember: no service makes you "GDPR-proof" on its own. The technology and the data location are the foundation, but your own diligence (choosing the right address, not sending more than necessary, giving sensitive data extra security) remains decisive. A good provider only makes that diligence a lot easier.
FAQ
Frequently asked questions
May I just email a customer's name and address?
Usually yes, provided you do it securely and don't send more data than necessary. Use a provider with encrypted connections and secure your mailbox. Stricter requirements apply to sensitive data.
Is email safe enough for personal data?
Ordinary email isn't automatically safe, but with encrypted connections (forced TLS) and a well-secured mailbox it's perfectly usable for a lot of ordinary personal data. For special categories of data, extra security is often needed.
What if I accidentally mail the wrong address?
A misaddressed mail with personal data can be a data breach. Always check the addressee before you send, and look into what your obligations are with your privacy authority. When in doubt, consult a specialist.