Business Tech & Tools
What business information should I avoid sending through ordinary email?
The short answer
Do not use ordinary email to send passwords, recovery codes, full Social Security or national identification numbers, complete payment-card details, bank-login information, or an unprotected file full of sensitive client records. Use the secure portal or protected transfer method intended for that information.
Email is wonderful for conversation. It is a poor vault. Messages can be forwarded to the wrong person, remain in several inboxes, appear in backups, or be read after an account is compromised. The safest sensitive information is often the information you never collect or send.
Sort the information before you send it
Use three simple levels:
| Level | Examples | Better handling |
|---|---|---|
| Routine | Appointment time, public brochure, ordinary project update | Normal business email is usually reasonable |
| Private | Draft contract, invoice, internal pricing, client work product | Confirm the recipient, limit access, and use a protected link when the consequences of a mistake are meaningful |
| Highly sensitive | Passwords, tax IDs, identity documents, account credentials, medical or detailed financial records | Do not put it in ordinary email; use an approved secure system and collect only what is necessary |
Context changes the category. A customer name may be routine by itself but sensitive when attached to a diagnosis, account number, or confidential dispute. A harmless document can also expose information through comments, revision history, hidden sheets, or file properties.
The FTC advises businesses to understand what personal information they hold, keep only what they need, limit access, and protect sensitive information in transit. Its guide to protecting personal information specifically cautions against emailing Social Security numbers, passwords, and account information through unencrypted email.
Replace email with the right doorway
Choose the transfer method based on the work:
- Ask a client to upload documents through your established client portal.
- Share a cloud file with a named recipient instead of attaching a copy.
- Set the narrowest permission, add an expiration date if available, and remove access when the job ends.
- Use the bank, payroll provider, accountant, insurer, or government agency's official secure message center.
- Collect payments through a reputable payment processor rather than asking for card numbers by email.
- If you must exchange a protected file, agree on the method before sending it and deliver any password through a separate channel.
“Password-protected” does not automatically mean safe. The strength of the encryption, the password, the transfer method, and the recipient's handling all matter. For recurring sensitive work, use a professional system designed for the data instead of inventing a homemade process.
Send the minimum necessary
Before requesting a document, ask what fact you actually need. If you need proof of an account balance, you may not need every transaction on the statement. If you need the last four digits, do not request the full account number. If you only need to confirm identity, ask whether a trusted provider can do that without giving you a permanent copy of the identity document.
When redacting, make a new copy and confirm the hidden content cannot be recovered. Placing a black rectangle over text in an editable file may only cover it visually. Export appropriately, reopen the finished file, try to select or search for the hidden text, and keep the unredacted original in its protected location.
Prevent ordinary mistakes
Slow down for attachments. Open the file you are about to send, check every page or sheet, and confirm the recipient's full address. Remove outdated recipients from autocomplete when they create a risk. Do not put private details in a subject line because subject lines may appear in notifications even when the message body is protected.
For a protected cloud link, test the permission in a private browser window. “Anyone with the link” is convenient, but a link can be forwarded. Named-person access is usually better for client material. Record where the file lives and set a reminder to remove access later.
If sensitive information has already gone out
Ask the unintended recipient to delete it without forwarding it, but do not assume deletion solves the problem. Remove or restrict any shared link, notify the data owner and the service or client required by your agreement, and preserve a factual record of what was sent, to whom, and when.
Privacy, breach-notification, professional, and recordkeeping rules vary by location and industry. The FTC's data-breach response guide describes a general response process, but it cannot tell you every rule that applies locally. If the information could create a real risk of fraud, identity theft, confidentiality harm, or contractual breach, promptly check your agreements and the rules in your jurisdiction, and consult qualified local counsel or a security professional.
Sources and further reading
- Federal Trade Commission: Protecting Personal Information, A Guide for Business
- Federal Trade Commission: Data Breach Response, A Guide for Business
A free next step
You don't have to build this alone
Bring your questions, share what you're working on, and meet other women building businesses from home. It is free to join.
Related Questions
- How do I use home and public Wi-Fi safely for business?
- When does a business computer need antivirus or endpoint-protection software?
- Which cybersecurity basics should a one-person business put in place first?
- Do I need a password manager, and how should I create and manage strong business passwords?
