The GDPR Do's and Don'ts

The Busy Friday Mistake

A Simple Slip-up

It’s 4:30 PM on a Friday. You’re rushing to send a newsletter to 200 customers. You attach the file, type the names into the To: field, and hit send.

Five minutes later, you realize: every customer can now see everyone else’s private email addresses. This is a data breach.

Imagine it's Friday afternoon and you're in a rush. You send out a group email, but instead of using BCC, you put everyone in the 'To' field. Instantly, you've shared 200 private email addresses with strangers. This simple human error is how most data breaches actually happen.

The Human Factor

The Strongest Link

Research shows that up to 95% of data breaches are caused by simple human mistakes, not master hackers.

By building secure habits, you become the strongest link in our company’s security. You don't need to be a lawyer; you just need to be vigilant.

It's a common myth that hackers are the biggest threat. In reality, nearly 95 percent of breaches stem from everyday slips. This means that your daily habits—like how you handle your desk or your inbox—are the most powerful tools we have to stay compliant.

Spot the Privacy Risks

The Desk Inspection

Imagine you are walking past a colleague's desk while they are at lunch. Can you spot the 4 GDPR red flags in this scene?

Click on the items that represent a security risk.

Take a look at this workspace. It looks normal at first glance, but there are four major privacy risks hiding in plain sight. Click on the items you think are 'red flags'. Well spotted. An unsecured USB stick labeled 'Customer Export' could easily be lost or stolen, leading to a massive breach. Correct. An unlocked screen is an open door to customer data. Always lock your computer before walking away. That's a big one. Writing down passwords on sticky notes is a major security failure. Use a password manager instead. Exactly. A list of home addresses is highly sensitive personal data. It should be in a locked drawer, not on a desk.

Daily Do's and Don'ts

Mastering Your Workflow

Use these simple rules to keep your digital and physical workspace safe.

Let's break down the most important daily habits. First, always use BCC for external groups. Second, make it a reflex to lock your screen every single time you stand up. Finally, before you share your screen in a meeting, take five seconds to close any unrelated tabs or private chats.

Three Mental Checks

The 'Think Before You Act' Framework

When you're unsure about handling data, ask yourself these three questions:

  1. The Need to Know Test: Does this person need this data right now?
  2. The Public Square Test: Would I be okay if this was shouted in public?
  3. The Right Place Test: Is this stored in our secure system?

When you're in doubt, use these three mental checks. Does the recipient actually need this info? Would you be comfortable if this data were public? And is the data where it belongs, in our secure system, or is it sitting on your personal desktop?

The Email Safety Check

Practice: Spot the Error

You are about to send this email. Look closely at the recipients, the content, and the attachments. Can you find the privacy risk?

Here is a draft email ready to go. Before you hit send, check it for risks. Click on the area that you think violates GDPR best practices. That part looks okay. Look closer at the attachments or the recipient list—is there data there that shouldn't be shared? Excellent catch! You noticed that the attachment contains the full home addresses of every client, which isn't necessary for this specific request. This is a violation of the 'Need to Know' principle.

Handling a Potential Breach

What would you do?

You just realized you sent a sensitive report to the wrong 'John Smith' outside the company. Type your plan of action below.

Mistakes happen. If you realize you've sent sensitive data to the wrong person, what are your next steps? Type a brief plan and submit it for review.

Your GDPR Checklist

Stay Compliant Every Day

Keep these points in mind as you go back to your work:

You've completed the lesson. Remember, you don't need to be a lawyer to protect our data. Just stay vigilant, follow these simple do's and don'ts, and always reach out to the DPO if something doesn't feel right. Great job!