Alex Franch

Do You Have Access To A Mailbox Of An Ex-employee? It Could Cost You £13,000

Do You Have Access To A Mailbox Of An Ex-employee? It Could Cost You £13,000

Share this content

As your company grows, people come and go. Though one thing that might not go as much as it comes is data. We often forget the vast amounts of personal data we collect and retain from employees. From our conversations with SMEs here in the UK and we've seen that companies try their best to remove personal data from past employees but they fail in one thing: removing old employee mailboxes. We get it, it's not too clear what has to be done and it's handy to have that data in case it is needed in the future. This is why we've set out this blog post so that you know what has to be done. The answer is:

You have to delete it

Just this September we have seen a 13 employee company fined €15,000 for not managing old employee mailboxes correctly.

How to manage an old employee mailbox

Before the dismissal or departure of the employee

  1. Have an IT policy that specifies what has to be done when an employee leaves the company (i.e. what we are going to talk about).
  2. Just how they can collect or throw away their personal belongings they can choose to collect or delete their data. So you must sort personal from professional emails so the person can choose to collect or delete their private communications before their departure. If some content has to be recovered so "business can carry on" this must occur before the dismissal or departure of the employee and must happen in their presence. This means you shouldn't be able to access and recover emails and other files after the person has left.
  3. Tell the employee in advance that the mailbox will be blocked.
  4. Set an automated response before blocking the mailbox in which you:
    • indicate that the person no longer exercises his/her role in the organisation; and
    • give contact details of the relevant person to contact instead.
  5. Block the mailbox, before or on the day the employee leaves the organisation.

After the dismissal or departure of the employee

  1. Maintain the automatic response for a "reasonable period", e.g. 1 month. The time frame can be extended provided that:
    • the duration is no longer than 3 months (ideally);
    • a justification is given; and
    • the person is informed of this extension.
  2. Beyond the (maximum) timeframe for the automatic response, the mailbox must be deleted.

And that's it. As always, be transparent and fair. Make sure that whenever you access the employee's data he's always there and give him/her the chance to delete or take it with him. Once he/she is gone, their data should be too. If you want to prevent data breaches, avoid fines and risk like these, book a free consultation with us here:


November 10, 2020

Frequently asked questions

Do I need to connect all my tools and third parties?

We never have access to any of your data, our platform is able to scan each tool and provide recommendations without needing to access any of the data within those tools.  There's no need for your dev' team to do anything, there are no security risks, just tell us the tools you use and we will do the rest.

What is the scope of my privacy policy?

Our policies are not just about my website or service. Once set up, our platform will help you map-out internal and external processes, such as HR, finance, and more!

Do I need to replace my current policy for the privacy portal?

We recommend replacing your current policy with our policy, this way you’ll remain compliant as your business changes and as the laws update.

Do I need help filling out my details?

Setting up is easy, just follow the on-screen commands and go through a few short steps to add your tools. You don't need any technical ability, anything you don't know the answer to you can ask us via our live chat or add later.

Why can’t I just use a template and add it to my website myself?

A template will not be applicable to your particular business as there are many things to consider for each tool you use. Also the template will not automatically update when changes happen in your business and when changes to GDPR laws are released. This can leave you vulnerable to breaking GDPR laws.

What if you don’t have the tools and third parties that I have?

We have a huge selection of tools pre-loaded and anything you don't see you can add directly from the platform as well as mapping data for any custom software you may use.

Which plan should I choose?

Our Essential Plan is perfect for people just getting started, small businesses, self-employed people and early stage companies. It allows you to get set up and start making your site GDPR compliant. You can move to our pro plan when you grow and your needs become more complex.

Our Pro Plan is aimed at SMEs and is our most popular plan as it includes everything you'll need such as a cookie banner, multiple languages as well as dedicated support.

Our Agency Plan is aimed at businesses that operate with clients needing GDPR solutions. The plan allows you to onboard clients as well as benefit from the Pro Plan for your own site.

Our Enterprise Plan is our most customisable and inclusive plan aimed at large, corporate businesses. We will essentially build you a bespoke plan with full maintenance support, onboarding classes and full company-wide access.

Feel free to get in touch to discuss our GDPR Compliance Software solution.

How easy is it to set up?

Signing up is super easy. The platform will ask you a few basic questions and then you can add your tools - don't worry if you don't know them all, you can come back and add tools at any point. The platform will then generate you the correct privacy policy based on your information, you can there share it directly on your site. That's it!

What size companies is Privasee aimed at?

Privasee has a plan for smaller companies as well as larger enterprise companies. For companies small to medium you can signup directly. For bigger enterprise companies get in touch with your requirements and our team will build you a bespoke plan.

I already have a privacy policy, do I need Privasee?

You have a legal responsibility to keep your policy up to date with every change in legal requirements for every tool you have. With Privasee you are always covered.

Still have questions?

We are here to help