What to do if…
you sent confidential information or a file to the wrong person at work
Short answer
Act immediately to contain access, then report it through your organisation’s data protection or security process so it can be assessed and recorded without delay.
Do not do these things
- Don’t try to fix it quietly by deleting your sent email or keeping it off the record.
- Don’t repeat the confidential content in a follow-up message.
- Don’t forward the original message or attachment around for awareness unless your incident process tells you to.
- Don’t blame, threaten, or pressure the recipient; keep any contact brief and practical.
- Don’t assume it is not a breach just because it was accidental or sent to only one person.
- Don’t contact the ICO yourself unless you are the person responsible under your organisation’s process.
What to do now
-
Pause for one minute and write down the essentials. Record what was sent, when, to whom, and how it was sent: email body, attachment, shared link, shared drive, portal, HR system, ticket, or another route.
-
Use any safe containment option you already have.
- If your email system supports it, try to recall or withdraw the message.
- If you used a shared link, disable the link, restrict permissions, or remove the recipient’s access.
- If it was sent through a work system, ask the system owner, IT team, or administrator to restrict access urgently.
-
Contact the recipient briefly if it is safe and appropriate. Ask them not to open the content if they have not already done so, to delete it including from deleted items, and to confirm in writing that they have deleted it and not shared it.
-
Report it internally right away as a possible data protection or security incident. Follow your organisation’s process. If you are unsure where to report it, contact IT or security and your manager, and use the words: “possible personal data breach – confidential information sent to the wrong recipient”.
-
Keep the evidence your incident team will need without spreading the content. Keep the recipient address, time sent, subject line, attachment name, shared-link details, permission settings, and any reply from the recipient. Do not send the confidential material again unless the incident team asks for it.
-
Make a simple incident note while it is fresh. Include the type of information involved, whether it included personal data, roughly how many people may be affected, whether the file was password-protected or encrypted, and what you have already done to contain it.
-
Give your DPO, privacy team, IT, or security team the facts quickly, not perfectly. They may need to know whether the recipient is internal or external, named or generic, known or unknown, and whether the information could cause harm if misused, such as financial loss, identity fraud, discrimination, distress, or loss of confidentiality.
-
Let the responsible team decide on recording and notifications. If a personal data breach is notifiable, the organisation must usually notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Even if it is not notifiable, the organisation should still record what happened, what was decided, and why.
What can wait
- Writing a perfect explanation or apology can wait until containment and internal reporting have started.
- Deciding whether the incident is reportable to the ICO can wait for your DPO, privacy team, or responsible manager.
- Debating fault, blame, or disciplinary worries can wait.
- Longer-term fixes, such as training, process changes, approval steps, or technical controls, can wait.
Important reassurance
Wrong-recipient incidents are common workplace mistakes. The most helpful thing now is that you noticed, limited further spread, and reported it promptly so the right people can reduce any harm.
Scope note
These are first steps only. Later decisions about ICO reporting, affected-person communications, contractual duties, disciplinary process, or remediation may need your DPO, privacy team, IT or security team, management, legal support, or other specialist help.
Important note
This guide is general information, not legal, employment, data protection, information security, financial, therapeutic, or other professional advice. Follow your employer’s incident reporting policy and any instructions from your DPO, privacy team, IT team, security team, or manager.
Additional Resources
- Information Commissioner's Office — Common data protection mistakes (and how to fix them)
- Information Commissioner's Office — Personal data breaches: a guide
- Information Commissioner's Office — UK GDPR data breach reporting (DPA 2018)
- Information Commissioner's Office — Breach response and monitoring
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.