DaveA Posted September 17, 2025 Posted September 17, 2025 Hi All, A quick data question... We had an internal job advertised and 5 members of staff applied. A member of the admin team sent an email with all 5 people copied in asking them to fill in an online form. One of the applicants is now saying we have caused a data breach and have to report ourselves to the ICO as he did not want anyone to know he had applied for this job and it is now causing him emotional stress that other people know. So my question is have we caused a breach and do we have to report ourselves as no personal data was leaked apart from the fact they had applied for a job. What are peoples thought? Thanks in advance. Dave.
Scan099 Posted September 17, 2025 Posted September 17, 2025 Reading this article i think it depends on the email address structure. https://hnksolicitors.com/news/is-revealing-my-email-address-a-breach-of-gdpr/
David44 Posted September 17, 2025 Posted September 17, 2025 I don't think it's the sharing of the email address that is the potential data breach. It's an internal job so it was probably their school email address anyway. The data that was shared is the fact that they had applied for the job. Nothing was breached, the data was shared willingly by the member of the admin team by the sounds of it. Should it be reported to the ICO, I don't know.
HC_Netman Posted September 17, 2025 Posted September 17, 2025 I would say yes it is a data breach but I would question whether or not it was reportable. I would be logging it. Speaking to the people involved. Outlining better ways of doing it next time and apologising to the affected people. Make sure everything is recorded including whether or not you decide to report yourselves. Self assess here: https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach-assessment/ 1
NegativeKillDeath Posted September 17, 2025 Posted September 17, 2025 No all breaches need to be reported to the ICO, they have a self assessment check. Self-assessment for data breaches | ICO Assuming that the fact that a job was applied for is a personal data breach Im not sure there would be any physical, materiel or non-material damages to the person so it wouldn't need reporting. Just recorded.
psydii Posted September 17, 2025 Posted September 17, 2025 It's a breach, but not one that requires reporting to the ICO. Personal data breaches: a guide | ICO
APMerry Posted September 17, 2025 Posted September 17, 2025 (edited) That is a weird one. I think it is a data breach and one that could cause harm, which if I'm not mistaken is the criteria for reporting breaches to the ICO. I think I would report it as if you don't, they are likely to. That would look very bad from the ICO perspective. Reporting to the ICO is easy and they will likely come back with some advice on how to avoid it in the future and close the case. It's pretty unprofessional though and I would too be a bit annoyed about it. Edited September 17, 2025 by APMerry 1
paulkerton Posted September 17, 2025 Posted September 17, 2025 (edited) Yes. It's a breach. The fact they've applied for the job is personal data under ol GDPR and this would be an unauthorised disclosure. I doubt it's reportable though as it's not likely to result in a risk to the person's rights and freedoms. Personally? Record it as a near-miss/breach, let the DPO know and let them decide if its reportable. I wouldn't say it was though as the emotional distress really is low. There was every chance the 5 applicants would become aware of each other during interview processes, and if it was only disclosed to the other colleagues also applying, they're not going to suffer discrimination and financial loss from that. It's not like every colleague has been told about a medical concern, for example. Also send each of them an individual email apologising (dear god, do not send to all again!) and getting them to delete said email (though obviously you can do that centrally, it's better if you ask people to do so as it looks proactively like you're attempting to correct rather than cover up) then speak to the complainant directly to apologise. Edited September 17, 2025 by paulkerton 1
Ditto Posted September 17, 2025 Posted September 17, 2025 I'm slow to reply, but @paulkerton has 100% the view I have and I agree with his proposed actions. The only thing I would add is, unless you are the DPO, the DPO should be answering these questions, and if anything working with HR and not the IT department - if indeed that is the OPs role.
synaesthesia Posted September 18, 2025 Posted September 18, 2025 Yes it's a breach, and I will also echo @paulkerton's comments and recommendations. From an IT perspective all you should probably be involved with, if at all, is to provide advise on correct use of email, bcc etc but even that's a bit of a reach. DPO's job entirely As former DPO, I'd have taken the exact actions Paul mentioned.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now