Outcomes - Selected Case Summaries

Categories

 

Performance Assessment Sent to Wrong Person

Informal Resolution | 18 February 2020

A wealth management firm notified us of a personal data breach that involved a senior manager who inadvertently sent a performance appraisal to the wrong employee. The incident was due to a network scanner that retained the wrong recipient’s email address from a previous scan job.

As soon as the error was discovered, the senior manager contacted the recipient to request the deletion of the email and the attachment. The IT team confirmed that the email had not been forwarded to another destination. The company’s compliance manager and the senior manager informed the data subject of the breach, and explained the measures that the company planned to take to avoid the issue from reoccurring. A number of technical and organizational measures were also taken. We were satisfied with the response and the case was closed.