The Information Commissioner’s Office (ICO) is suggesting organisations steer clear of using the blind carbon copy (BCC) email function amidst recent blunders in the UK.
According to the ICO, BCC on its own is not enough to properly protect people’s personal information, and advises that if organisations send personal information, that they use alternatives such as bulk email services, mail merge, or secure data transfer services.
BCC allows the sender to reach multiple recipients without disclosing the email addresses of other recipients. This is in contrast to the carbon copy (CC) feature or sending to recipients directly, which allows them to see who else the email was sent to.
According to data from the ICO, failure to use BCC correctly was one of the top 10 leading non-cyber breaches with nearly 1,000 reported since 2019. The research also points out that local government is the third biggest offender of these breaches, following education first then health.
“These breaches can cause real harm, especially where sensitive personal information is involved,” said Mihaela Jembei, the ICO’s director of regulatory cyber.
Just earlier this month, the ICO reprimanded two Northern Irish organisations for inappropriately disclosing information over email. In March, it issued a reprimand to NHS Highland for a breach of trust involving those accessing HIV services.
Recommended
- Managing Cloud Spend is Key to Avoiding ‘Bill Shock’
- NHS Scotland Releases ‘Protect Scotland’ Contact Tracing App
- Fail Fast, Fail Small to Avoid Failing Big and Failing Slowly
The watchdog recommends that organisations have appropriate policies and training in place for staff in relation to email communications to avoid further issues.
“This new guidance is part of our commitment to help organisations get email security right. However, where we see negligent behaviour that puts people at risk of harm, we will not hesitate to use the full suite of enforcement tools available to us,” said Jembei.





