logo

To BCC or not to BCC – that is the question data watchdog wants answered

ID: 1ec6ef5b-78cf-5dc5-a4d0-c331e82a0c1c

STIX ID: report--1ec6ef5b-78cf-5dc5-a4d0-c331e82a0c1c

Feed Name: The Register (Security)

Threat Score
25/100

Date Published: 2023-12-15

Date Updated: 2026-04-26

Author: Richard Speed

...
...

The ICO has warned organisations about numerous personal-data breaches resulting from incorrect use of email recipient fields (To/CC instead of BCC), highlighting case studies — including an NHS trust, a charity and a £350K MOD fine — and advising staff training, email system safeguards (warnings, send delays, disable autocomplete) and consideration of alternatives to email for sharing sensitive information.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.