Blog article

Can you request personal data by email under GDPR?

Email is not prohibited under GDPR. But organisations asking clients for identity documents, financial records, or medical information must be able to show that their delivery channel is appropriately secured.

“Could you send us a copy of your passport and a bank statement by email?” Accountants, employers, public authorities, and professional advisers ask questions like this every day. For the client, however, it means sending sensitive documents through their own email provider — a service they may use for free and probably did not choose specifically for sharing confidential information.

Passports, payslips, and medical documents may consequently enter the systems, mailboxes, and backups of external providers. Those providers operate under their own privacy terms, retention practices, and technical infrastructure. The organisation requesting the documents has no control over that environment. The sender may also be unable to determine where copies remain or when they are permanently deleted.

Is an organisation allowed to ask clients to do this under GDPR? The short answer is that email is not prohibited. But when sensitive documents are involved, ordinary email can become increasingly difficult to justify.


GDPR does not prohibit email

The General Data Protection Regulation does not say that personal data may never be requested or sent by email. Sending a name, telephone number, or appointment confirmation by email can be entirely reasonable in many situations.

GDPR is technology-neutral and does not prescribe one specific technical solution. Organisations must assess which security measures are appropriate for their particular processing. Relevant considerations include:

  • the nature and sensitivity of the data;
  • the amount of data involved;
  • the purpose for which it is collected;
  • the possible consequences of loss or unauthorised access;
  • the security measures that are available;
  • the likelihood and severity of the risk.

There is therefore an important difference between asking someone for their preferred appointment date and asking them to send a passport, tax return, or medical record.

What does GDPR require?

Article 5 GDPR requires personal data to be processed with appropriate security. This includes protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage. This is known as the principle of integrity and confidentiality.

Article 24 makes the controller responsible for implementing appropriate technical and organisational measures and for being able to demonstrate compliance.

Article 25 requires organisations to consider data protection when designing their processes. This is known as data protection by design and by default.

Article 32 requires security appropriate to the risk. Encryption is expressly mentioned as one of the measures that may be appropriate. The European Data Protection Board similarly emphasises that security measures must be adapted to the context, the state of the art, and the risks to individuals.

Special category data, such as health information, biometric data, religious beliefs, or political opinions, receives additional protection. Identity documents, national identification numbers, and detailed financial records can also cause significant harm if they fall into the wrong hands.

The relevant legal question is therefore not simply:

“Is email allowed?”

A better question is:

“Can we demonstrate that ordinary email provides appropriate security for these documents?”

The more sensitive the information and the more practical the available alternatives, the harder it becomes to answer that question with “yes”.

The organisation cannot simply shift responsibility to the client

When an organisation asks someone to return sensitive documents as email attachments, the organisation effectively determines the delivery process. The client may be able to choose their email provider, but they have usually not been offered a reasonable alternative to email.

This places part of the security and privacy risk on the client. They must use a personal email account for documents that the account may never have been selected or configured to handle.

The requesting organisation has no visibility into or control over that email environment. It does not know where copies remain, who can access the account, or when the documents will be permanently deleted.

The fact that the client clicks “send” does not remove the organisation’s responsibilities. GDPR requires the organisation to incorporate appropriate safeguards when designing the process and to be able to justify its choice of delivery channel.

An organisation that asks for sensitive documents should also provide an appropriately secured way to deliver them.

Why ordinary email presents risks

Email is a general communication tool. It was not designed as a controlled environment for collecting and managing confidential documents.

This creates several structural risks.

The wrong address is easily selected

A typing error or an incorrect autocomplete suggestion can send personal data to the wrong person. Once a message has been delivered, recovering every copy is usually impossible.

Transport encryption is not end-to-end encryption

Modern mail servers often use TLS to protect connections while messages are being transported. That is valuable, but it does not automatically mean that only the sender and intended recipient can read the contents.

Messages may remain readable on mail servers and in mailboxes. Genuine end-to-end encryption requires additional technology and appropriate key management.

Attachments spread easily

An attachment can be downloaded, copied, forwarded, or saved in a separate client file. Multiple versions may therefore be created without a clear overview of where they are stored.

Access is difficult to revoke

After sending an ordinary email, the sender usually cannot retrieve it. The receiving organisation may also be unable to guarantee that every copy will be deleted when it is no longer required.

Retention periods are difficult to enforce

GDPR requires personal data to be kept no longer than necessary. Applying and demonstrating a retention policy becomes harder when documents are distributed across mailboxes, downloads, internal folders, and backups.

An email address does not prove identity

An email address alone does not establish who is using the account. Depending on the risk, additional verification may be needed to determine who submitted a document or who is allowed to access it.

Is secure email sufficient?

Secure email can be an appropriate solution in some circumstances. The answer depends on how it is implemented and on the sensitivity and risks of the processing.

Relevant measures can include end-to-end encryption, strong authentication, protected downloads, limited message validity, and control over retention. Organisational safeguards, such as clear procedures and verification of recipients, are important as well.

There is therefore no simple rule that a portal is always mandatory or that every use of email is insecure.

A dedicated upload environment can nevertheless provide controls that are difficult to achieve with ordinary email:

  • documents are not copied through several mailboxes as attachments;
  • the request can specify exactly which documents are needed;
  • access can be restricted or revoked;
  • files can be deleted automatically;
  • important actions can be logged;
  • encryption can be applied by default;
  • the organisation can manage the process centrally;
  • the person submitting documents does not need to select a storage or file-sharing solution.

A practical checklist for organisations

Before asking someone to provide personal data or documents, consider the following questions:

  1. Which data do we genuinely need?
  2. Can unnecessary information be omitted or redacted?
  3. Does the document contain special category or fraud-sensitive data?
  4. What would the consequences be if it reached the wrong person?
  5. Can we obtain sufficient assurance about the submitter’s identity?
  6. Is the content appropriately encrypted during transfer and storage?
  7. Can access to the document be restricted and revoked?
  8. Do we know where copies are stored?
  9. Can we set and enforce a retention period?
  10. Can we demonstrate who has accessed the document?
  11. Do we offer the client a practical and secure alternative?
  12. Can we explain why the selected channel is appropriate?

If these questions are difficult to answer in an ordinary email workflow, the process should be reconsidered.

Request sensitive documents without email attachments

Doqubox gives organisations a controlled environment for requesting and receiving confidential documents.

The organisation specifies which documents are required and sends an invitation. The client can then upload the requested files without creating an account or installing additional software. Documents are end-to-end encrypted and stored within the European Union. Retention periods and automatic deletion give the organisation greater control over the document lifecycle.

Doqubox does not automatically make an organisation GDPR-compliant. It does, however, provide important building blocks for securing sensitive documents and receiving, retaining, and deleting them in a controlled manner. Targeted document requests, end-to-end encryption, and automatic deletion help organisations limit the spread of personal data and support their security and retention obligations.

The organisation asks for the data. It should therefore take responsibility for how that data is delivered.

Does your organisation still ask clients to send passports, bank statements, payslips, or medical documents through ordinary email? Discover how Doqubox can make the process safer and simpler.

Sources

This article provides general information and does not constitute legal advice.