DPDP Insights › Questions › Staff share personal data on WhatsApp and personal email. Wh
Question
Staff share personal data on WhatsApp and personal email. What do we do?
Short answer: Yes, this is a common breach; give staff a safer option
Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.
What the law says
Section 8(5) asks for reasonable safeguards. A wrong send is a breach under Section 2(u), and Section 8(6) applies.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Section 8(6) · Rule 7: On becoming aware of a personal data breach, tell each affected person and the Data Protection Board without delay. Send the Board a detailed report within 72 hours, or a longer period if the Board allows on request.
Steps
Ask teams how they actually share files and photos today.
Provide an approved tool for that job.
Set three simple rules: approved tool, no personal accounts, report wrong sends.
Teach the rules with real examples from your own work.
Treat a quick report as good behaviour, not a disciplinary case.
Healthcare and hospitals: Reports and images on WhatsApp groups are the most common hospital breach.
From each seat
CISO / Security head: Your tooling can help: data-loss rules on email, an approved file-share, mobile device controls. Pair it with a reporting route that people trust.
HR head: Teams share CVs, salary sheets and ID copies on chat. Give recruiters and payroll an approved way to share.
Operations head: Shift groups and vendor chats are where data leaks. Give supervisors an approved way to share lists and photos.
Branch / business head: Your teams share data in the middle of real work. Make the approved way faster than the risky way.
Customer service department: Never send customer data from personal phones or accounts.
What a good answer from management sounds like
“Staff have an approved way to share, they know the three rules, and wrong sends are reported within the hour.” Effort and time: Light to medium · 4 to 8 weeks.