Tìm kiếm hỗ trợ

Tránh các lừa đảo về hỗ trợ. Chúng tôi sẽ không bao giờ yêu cầu bạn gọi hoặc nhắn tin đến số điện thoại hoặc chia sẻ thông tin cá nhân. Vui lòng báo cáo hoạt động đáng ngờ bằng cách sử dụng tùy chọn "Báo cáo lạm dụng".

Learn More

We use Thunderbird to send work emails and given the introduction of GDPR on May 25, we need to know if your security levels support GDPR compliance

  • 2 trả lời
  • 1 gặp vấn đề này
  • 51 lượt xem
  • Trả lời mới nhất được viết bởi JaneSabherwal

more options

Hello! Just wondering with GDPR how we can continue to use Thunderbird to send work emails with client data and know they will be GDPR compliant. Any advice appreciated. Thank you Jane

Hello! Just wondering with GDPR how we can continue to use Thunderbird to send work emails with client data and know they will be GDPR compliant. Any advice appreciated. Thank you Jane

Giải pháp được chọn

It may be harder to configure and use email to send and receive information securly in GDPR compliance as you can't control your recipient's or senders compliance. Emails sent to GMail recipients come to mind.

UK's Information commissioner's office has a lot of information on compliance, this link is one of those simpler documents to check:

Thunderbird can be configured to:

  • Encrypt, decrypt and digitally sign your email communications, to avoid data breaches and leaks
  • Avoid collecting email addresses in your address books to comply with email communications opt-in / opt-out rules and regulations
  • Setup email signatures and / or headers to include disclaimers, links to privacy policies, etc.
  • Avoid sending large attachments directly - for example using the Filelink extension to store them in self-hosted storage using NextCloud (a solution recently chosen by the German government)

In my opinion your IT department should seek some legal guidance and assess what your risk is to be non-compliant, then address those concerns by looking at technical + human implications of implementing compliance. In many cases I suspect this will mean completely avoiding email and implementing new policies like "always digitally sign any emails".

As an example, if your company sends any documents including personal information, perhaps such process will need to be replaced with a secured website or offline process to completely avoid unencrypted email.

Đọc câu trả lời này trong ngữ cảnh 👍 0

Tất cả các câu trả lời (2)

more options

Giải pháp được chọn

It may be harder to configure and use email to send and receive information securly in GDPR compliance as you can't control your recipient's or senders compliance. Emails sent to GMail recipients come to mind.

UK's Information commissioner's office has a lot of information on compliance, this link is one of those simpler documents to check:

Thunderbird can be configured to:

  • Encrypt, decrypt and digitally sign your email communications, to avoid data breaches and leaks
  • Avoid collecting email addresses in your address books to comply with email communications opt-in / opt-out rules and regulations
  • Setup email signatures and / or headers to include disclaimers, links to privacy policies, etc.
  • Avoid sending large attachments directly - for example using the Filelink extension to store them in self-hosted storage using NextCloud (a solution recently chosen by the German government)

In my opinion your IT department should seek some legal guidance and assess what your risk is to be non-compliant, then address those concerns by looking at technical + human implications of implementing compliance. In many cases I suspect this will mean completely avoiding email and implementing new policies like "always digitally sign any emails".

As an example, if your company sends any documents including personal information, perhaps such process will need to be replaced with a secured website or offline process to completely avoid unencrypted email.

more options

Thank you for taking the time to answer this so fully Fabian - your answer has flagged up some important issues - I think we will need to find a new communications solution after May 25 if we are to be GDPR compliant. Best wishes Jane