GDPR Compliant Process for sorting through unidentified mail

Discussion in 'General Data Protection Regulation (GDPR) Forum' started by Michaelwilson76, Jan 23, 2018.

  1. Michaelwilson76

    Michaelwilson76 UKBF Newcomer Free Member

    3 0
    Has anyone had any thoughts on a GDPR compliant process for sorting through unidentified letters and documents in a mailroom environment?
     
    Posted: Jan 23, 2018 By: Michaelwilson76 Member since: Jan 22, 2018
    #1
  2. Simon Plummer

    Simon Plummer UKBF Contributor Free Member

    80 20
    Are you recording and processing the information from this? I would have thought you will be ok if you are not using the data for anything other than passing to the relevant recipient. Belt and braces you could document that process to make it clear.
     
    Posted: Jan 23, 2018 By: Simon Plummer Member since: Dec 6, 2017
    #2
  3. Michaelwilson76

    Michaelwilson76 UKBF Newcomer Free Member

    3 0
    No recording or processing by the mailroom however the problem is identifying the correct recipient when there is no reference or addressee. We can't send out emails company wide that feature personal data in an attempt at identifying a letter/documents owner.
     
    Posted: Jan 23, 2018 By: Michaelwilson76 Member since: Jan 22, 2018
    #3
  4. Simon Plummer

    Simon Plummer UKBF Contributor Free Member

    80 20
    So it would be your current process (whatever that may be). The trick with any process like this is to document it and demonstrate you have considered the risks, your above statement would be an ideal candidate to go on there,
    i.e.
    risk = emailing personal information to broad audience and losing control of data
    Control = mitigate
    Action = design process that ensures mail receives correct recipient in a secure manner*

    *obviously 'secure manner' would be relative to the data concerned.

    Hope this helps!
     
    Posted: Jan 23, 2018 By: Simon Plummer Member since: Dec 6, 2017
    #4
  5. Michaelwilson76

    Michaelwilson76 UKBF Newcomer Free Member

    3 0
    Thanks, yes it's the mitigation I'm focused on as I have documented the risks. Hopefully this will trigger my thoughts on a process. I was just very keen to find out if anyone had put together a process.
     
    Posted: Jan 23, 2018 By: Michaelwilson76 Member since: Jan 22, 2018
    #5