ARTICLE
18 September 2023

ICO Publishes Guidance On Bulk Emails

NR
Norton Rose Fulbright Hong Kong

Contributor

Norton Rose Fulbright provides a full scope of legal services to the world’s preeminent corporations and financial institutions. The global law firm has more than 3,000 lawyers advising clients across more than 50 locations worldwide, including London, Houston, New York, Toronto, Mexico City, Hong Kong, Sydney and Johannesburg, covering Europe, the United States, Canada, Latin America, Asia, Australia, Africa and the Middle East. With its global business principles of quality, unity and integrity, Norton Rose Fulbright is recognized for its client service in key industries, including financial institutions; energy, infrastructure and resources; technology; transport; life sciences and healthcare; and consumer markets.

The Information Commissioner's Office has published new guidance on email security, with emphasis on safety when sending to multiple recipients...
United Kingdom Employment and HR

The Information Commissioner's Office has published new guidance on email security, with emphasis on safety when sending to multiple recipients which is relevant for pension schemes when emailing their membership.

The principal points include:

  • Awareness that showing which people receive an email could disclose sensitive or confidential information about them.
  • How to assess what technical and organisational security measures are appropriate to protect personal information when sending bulk emails.
  • Giving pointers for training staff about security measures when sending bulk communications by email.
  • Considering whether using secure methods, such as bulk email services or mail merge services, is more appropriate, rather than just relying on a process that uses the BCC function. This helps ensure that personal information is not shared with other people by mistake.
  • If an email is to be sent to a small number of recipients, consideration should be given to sending each message separately, rather than one bulk email.

As regards pension schemes, administrators should remember that whether information is sensitive can depend on the context and consideration should be given to the impact a breach could have on members. For example, financial information or information that might be used to commit ID fraud would be sensitive information for these purposes.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More