
“Failure to use BCC correctly in emails is one of the top data breaches reported to us every year. Even showing which people receive an email could disclose sensitive or confidential information about them”.
In 2019, an NHS trust sent bulk emails about an art competition to their patients.
They had extracted the addresses from their patient record system and manually copied them into the ‘To’ field of the email, instead of the ‘BCC’ field. This disclosed the addresses of all recipients to each other.
The staff member attempted, unsuccessfully, to recall the messages.
The fact that the email was directed to patients of the clinic revealed sensitive information about the recipients (that the recipients were active patients of the trust), even though the contents of the email (promotion of an art competition) did not disclose any personal or sensitive information.
Charity Fine
In February 2020, a charity sent an email containing an agenda for an event they were running to 105 members of a HIV advisory board.
Despite the organisation procuring an email automation platform in order to secure emails, the migration to the new platform was incomplete. This resulted in a staff member manually adding email addresses to the CC field, instead of the BCC field.
65 of the105 email addresses clearly identified recipients, with two recipients contacting the charity to highlight the incident.
Whether or not special category information was disclosed, we found sensitivities around the nature of the charity’s work meaning that there was potential for the incident to cause recipients some distress. Therefore, the organisation should have treated the information in the same way as special category information. One recipient stated they were able to identify at least four people, one of whom was a previous sexual partner.
Amongst other findings, we considered the reliance on ‘BCC’ for communication to this group of people was not an appropriate security measure to manage these communications and they could have adopted other methods.
ICO Guidance
While BCC can be a useful function, it's not enough on its own to properly protect people's personal information. If you are sending any sensitive personal information, you should use alternatives to BCC.
Email Journals
Since an email journal is critical in meeting compliance needs, the following considerations are vital on migration:
- Preserving chain of custody
- Maintaining meta-data & context
- Consolidating your journals
Preserving Chain of Custody
Any time an electronic record is moved between storage devices or locations, there are great risks of point-of-failure, weak links, or possible disruptions that can result in deletions, alterations, or substitutions. Such risks can compromise the integrity and reliability of data - or what is considered as material evidence that is essential in legal procedures.
Our blog post covers the issue in more detail.
Maintaining Meta-Data and Context
When migrating a journal, it is crucial to preserve all relevant information, and correctly map it into the destination journal platform. An email journal migration that fails to preserve the envelope data, is fundamentally flawed. For example, missing out BCC recipients and the members of any distribution lists would mean that any future eDiscovery involving all the people who were ‘party’ to an email thread would be incomplete, leading to unnecessary risks of regulatory fines and litigation procedures.
Consolidating Email Journals
Journal archives are your organisation’s primary record of email communications and are often held in specialist platforms that are scalable and allow flexible eDiscovery searches across the journal’s contents.
A key benefit of migrating historic email journals to a new platform is the ability to manage and search all journal records in one place, essential for more effective eDiscovery. Legal teams can manage the retention and eDiscovery of email without complexity or need to involve the IT department and can do so alongside other collaboration records such as Teams chats, Slack and Zoom, to shorten the timelines for litigation readiness.
Managing the retention of migrated journal records can become a nightmare if they require separate access, sit in a difference structure, or require a different set of skills to implement the required records management policies.
Journal Consolidation and Migration
As technologies develop, a change in corporate strategy may lead to the introduction of a new journal archive solution. In these situations, it is common for consolidation of journal archives into the new platform where all information is in a single, centralised repository allowing for easy eDiscovery.
Equally, during Merger and Acquisition activities there is a need for consolidation of legacy archived data into a single platform.
Some Customer Scenarios
A global asset management company maintained a message journaling environment for compliance purposes. 13,500,000 messages needed to be migrated to maintain their historic journal content as part of a larger archive migration project. A robust extraction process had to be designed, tested and implemented to guarantee the journal integrity for regulatory mandates to be adhered with.
A FTSE listed investment management company had invested in email journaling technologies at an early stage with a market leading, on-premise solution. As technologies developed, a new, cloud-first corporate strategy led to a review of the archive estate and a decision was made to invest in a new, cloud-based platform. Over 60TB of historical email journal data needed to be securely and efficiently migrated from the ageing, legacy platform to the new solution, maintaining all message attributes and content.
A FTSE listed chemicals organisation with a significant volume of critical, legacy journal archived data made the business decision to switch from their long-standing on-premise archive solution to Office 365. In doing so, they would leverage their existing O365 licence costs and save considerable costs on running and maintaining an ageing, on-premise archive solution. Over 300TB of journal email data was successfully migrated, allowing the legacy platform to be decommissioned, introducing significant cost savings.
Additional Considerations
Where organisations are moving entirely to the cloud, decommissioning the on-premises journal environment becomes a key factor. The pressing need to save the costs and overheads of using a third-party journal service provider, such as Mimecast is often a big issue.