A misdirected email, a file with the wrong person's data, a sheet left on a shared printer. You become, unwillingly, the temporary holder of data you have no right to use. Here is what to do, calmly and correctly.
It happens more often than we would like. Someone fills in the "To" field wrong and an email with a list of employees lands in your inbox. A supplier sends you, attached, another client's file. You pick up a sheet full of personal data from the shared printer that isn't yours. Or you open an envelope that bore someone else's name. In all these cases you are a decent person who, suddenly, is holding information about someone you don't know and who should never have seen it.
The good news is that, if you react well, it all resolves quickly and without consequences. The part many people overlook is that the wrong reaction — even a well-meaning one — can turn someone else's slip into a problem of your own. This guide explains, in plain terms, what it means to receive data you should never have received, and how to behave decently and lawfully.
The GDPR is built around the idea of a legal basis: to process personal data, you need a ground from Art. 6 (consent, contract, legal obligation, legitimate interest, and so on). When data reaches you by mistake, you have none of those grounds. There is simply no legitimate reason for you to work with that information.
In practice, you are a temporary and involuntary holder. The fact that the information landed on your screen or your desk gives you no right over it. And "processing" in the GDPR sense covers almost anything you do with it: reading, copying, saving, printing, forwarding, looking the person up online. That is why the first and most important rule is to stop: what you haven't yet seen, don't rush to see.
If special categories of data are involved — health, trade-union membership, sexual orientation, beliefs (Art. 9 GDPR) — the sensitivity is even higher and caution all the more necessary. We wrote about how easily such data leaks through ordinary channels in our piece on a GDPR incident with medical data in an Excel file.
The list below seems obvious, but each point matches a common mistake, made out of curiosity or a wish to "help":
The golden rule: the only processing allowed is the minimum strictly needed to notify the sender and fix the mistake. Anything beyond that minimum takes you out of the comfortable position of "a third party who received it by mistake".
The right path is short and has only a few steps:
Tone matters. There is no need for drama or reproach: a polite, prompt notification is exactly what a responsible controller expects. Your correct reaction protects everyone — you, the person whose data it is, and the organisation that made the mistake.
From the perspective of the organisation that sent it to the wrong place, the situation is a personal data breach: an unauthorised disclosure of data to a person who should not have received it. That is the definition of a confidentiality breach, and its handling is governed by Art. 33 and 34 GDPR.
In short, the controller who made the mistake must assess the risk of the incident. If the breach is likely to result in a risk to the rights and freedoms of individuals, it notifies the ANSPDCP within 72 hours of becoming aware of it (Art. 33). If the risk is high, it must also inform the data subjects (Art. 34). The fact that you, as the accidental recipient, confirmed deletion matters: it can lower the assessed risk and sometimes justify a milder conclusion. We set out what such a notification looks like in our guide on notifying a breach to the ANSPDCP — when, how and what to expect.
An important point: it is not "your breach". You are not the controller who lost control of the data; you are the third party who received it without wanting to. The notification duty rests with the one who made the mistake. Your role is not to make the situation worse and to help limit it — exactly what you do when you notify and delete.
The same logic applies to the other side of the coin: if you are the organisation that never wants to send someone's data to the wrong person, the problem is not solved with calls for vigilance, but with processes. A few simple measures cut the risk dramatically: disabling email autocomplete or adding a confirmation step for external recipients, separating attachments per client, a short send-delay that allows recall, clear rules for the shared printer (pull-printing with a code, no forgotten stacks), and envelopes double-checked by a second person for sensitive mail.
Just as important is preparing your people: an employee who knows in advance what to do when they receive data by mistake reacts calmly and correctly, instead of improvising. A mature GDPR programme includes both these controls and a clear channel through which any accidental recipient can quickly flag the slip to you. If you want someone to handle such processes and incident management on an ongoing basis, an outsourced DPO gives you the expertise you need without the cost of a dedicated employee.
Receiving someone else's data by mistake does not make you guilty of anything — but it gives you a small responsibility, easily honoured. Stop, don't use or spread the information, notify the sender, and delete or return what you received. That's all. For the organisation that made the mistake, the incident is a breach it manages under Art. 33–34; for you, it is an opportunity to behave decently. A calm, correct reaction turns a potentially serious slip into a situation resolved in a few minutes.
Stop and don't use the information. Don't read more than you have already seen, don't save it, don't print it, don't forward it and don't send it to anyone. Notify the sender (the controller) that you received something not meant for you, and ask for instructions. Then delete the message, or return or destroy the document securely, as agreed with the sender. You have no legal basis to process that data — the only processing allowed is the minimum needed to fix the mistake.
Do not use it for any purpose of your own — you have no Art. 6 GDPR basis for that, and if it is special-category data (Art. 9) the restriction is even stricter. Deleting or destroying it is usually the right answer, but ideally you do so after notifying the sender and agreeing how to resolve it: sometimes the controller needs you to confirm what you received for their own incident record. Permanently delete the email (including from the trash) or destroy the document by shredding; don't archive it and don't keep it as "evidence" without the sender's agreement.
Yes — notify the sender, i.e. the organisation that sent the data to the wrong place (the controller). Use the email address, the letterhead, or the contact details of the data protection officer (DPO). Do not contact the person whose data it is (the data subject): that is not your role, and tracking them down is additional processing. The decision to notify the supervisory authority (ANSPDCP) and the data subjects belongs to the controller that made the mistake, not to you.
For the organisation that sent it to the wrong place, yes — it is a personal data breach (an unauthorised disclosure) falling under Art. 33 and, where relevant, Art. 34 GDPR. The controller has to assess it and, where there is a risk, notify the ANSPDCP within 72 hours and, at high risk, inform the data subjects. For you, the accidental recipient, it is not "your breach": your role is not to make the situation worse and to help limit it by deleting or returning the data.
We help you assess a data breach correctly, notify the ANSPDCP on time, and build processes that prevent such slips. We also provide an outsourced DPO — independent, with up-to-date expertise and without the cost of an extra employee.