The GDPR Do's and Don'ts
The Busy Friday Mistake
A Simple Slip-up
It’s 4:30 PM on a Friday. You’re rushing to send a newsletter to 200 customers. You attach the file, type the names into the To: field, and hit send.
Five minutes later, you realize: every customer can now see everyone else’s private email addresses. This is a data breach.
Imagine it's Friday afternoon and you're in a rush. You send out a group email, but instead of using BCC, you put everyone in the 'To' field. Instantly, you've shared 200 private email addresses with strangers. This simple human error is how most data breaches actually happen.
- Human error is the leading cause of data breaches.
- Accidentally exposing email addresses via CC instead of BCC is a common mistake.
- Vigilance in daily habits is the best defense.
The Human Factor
The Strongest Link
Research shows that up to 95% of data breaches are caused by simple human mistakes, not master hackers.
By building secure habits, you become the strongest link in our company’s security. You don't need to be a lawyer; you just need to be vigilant.
It's a common myth that hackers are the biggest threat. In reality, nearly 95 percent of breaches stem from everyday slips. This means that your daily habits—like how you handle your desk or your inbox—are the most powerful tools we have to stay compliant.
- 95% of breaches are caused by human error.
- Secure habits are more effective than complex technical barriers.
- Every employee plays a role in data protection.
Spot the Privacy Risks
The Desk Inspection
Imagine you are walking past a colleague's desk while they are at lunch. Can you spot the 4 GDPR red flags in this scene?
Click on the items that represent a security risk.
Take a look at this workspace. It looks normal at first glance, but there are four major privacy risks hiding in plain sight. Click on the items you think are 'red flags'. Well spotted. An unsecured USB stick labeled 'Customer Export' could easily be lost or stolen, leading to a massive breach. Correct. An unlocked screen is an open door to customer data. Always lock your computer before walking away. That's a big one. Writing down passwords on sticky notes is a major security failure. Use a password manager instead. Exactly. A list of home addresses is highly sensitive personal data. It should be in a locked drawer, not on a desk.
- Unlocked screens expose sensitive data to unauthorized viewers.
- Passwords should never be written down on sticky notes.
- Physical documents containing personal data must be secured.
- Unsecured external storage (USB) is a high-risk item.
Daily Do's and Don'ts
Mastering Your Workflow
Use these simple rules to keep your digital and physical workspace safe.
- BCC is your friend for group emails.
- Lock before you walk (Win+L or Cmd+Ctrl+Q).
- Check the share before starting a screen-share.
Let's break down the most important daily habits. First, always use BCC for external groups. Second, make it a reflex to lock your screen every single time you stand up. Finally, before you share your screen in a meeting, take five seconds to close any unrelated tabs or private chats.
- BCC prevents external contacts from seeing each other's details.
- Screen locking is mandatory every time you leave your desk.
- Clear your desktop and close private tabs before screen-sharing.
Three Mental Checks
The 'Think Before You Act' Framework
When you're unsure about handling data, ask yourself these three questions:
- The Need to Know Test: Does this person need this data right now?
- The Public Square Test: Would I be okay if this was shouted in public?
- The Right Place Test: Is this stored in our secure system?
When you're in doubt, use these three mental checks. Does the recipient actually need this info? Would you be comfortable if this data were public? And is the data where it belongs, in our secure system, or is it sitting on your personal desktop?
- Only share data with those who have a legitimate business need.
- Treat all personal data as sensitive and private.
- Avoid 'shadow folders' or local exports on your hard drive.
The Email Safety Check
Practice: Spot the Error
You are about to send this email. Look closely at the recipients, the content, and the attachments. Can you find the privacy risk?
Here is a draft email ready to go. Before you hit send, check it for risks. Click on the area that you think violates GDPR best practices. That part looks okay. Look closer at the attachments or the recipient list—is there data there that shouldn't be shared? Excellent catch! You noticed that the attachment contains the full home addresses of every client, which isn't necessary for this specific request. This is a violation of the 'Need to Know' principle.
- Double-check recipients to avoid 'Reply All' errors.
- Verify that attachments don't contain unnecessary personal data.
- Remove sensitive history from long email threads before forwarding.
Handling a Potential Breach
What would you do?
You just realized you sent a sensitive report to the wrong 'John Smith' outside the company. Type your plan of action below.
Mistakes happen. If you realize you've sent sensitive data to the wrong person, what are your next steps? Type a brief plan and submit it for review.
- Immediate reporting to the DPO is critical.
- Speed is vital for containing a data breach.
- Do not try to hide the mistake.
Your GDPR Checklist
Stay Compliant Every Day
Keep these points in mind as you go back to your work:
- BCC for groups.
- Lock your screen.
- Check your shares.
- Escalate to the DPO if you spot a risk.
You've completed the lesson. Remember, you don't need to be a lawyer to protect our data. Just stay vigilant, follow these simple do's and don'ts, and always reach out to the DPO if something doesn't feel right. Great job!
- Vigilance is a daily commitment.
- The DPO is your partner in safety, not a police officer.
- Small habits prevent big breaches.