A file sent to the wrong person: the first hours after a data incident
Echipa HR 365 · reviewed 2026-09-15 · 5 min read
In order: stop it spreading, write down exactly what left and to whom, and notify the person you designated in advance. What does not help at all is the hour spent working out whose fault it was — that comes later, and if it comes first, nobody reports the next incident.
What an HR incident actually looks like
The mental image is a cyberattack. In practice, the incidents that reach HR take much more mundane forms, and that is exactly why they are frequent: a file attached to the wrong message, a list sent with every address visible, a laptop left behind, an account still active for someone who left.
| What happened | What the actual problem is |
|---|---|
| Payroll file attached to the wrong email | The data cannot be recalled; the recipient has already seen it |
| List sent with everyone in the “to” field | You disclosed a list of people, not just addresses |
| Employee export left on a personal laptop | You do not know who else can use that device |
| Account still active for someone gone three months | The access continues and nobody is watching it |
| Folder shared with an “anyone with the link” link | The link travels onward and leaves no trace |
The first three share one thing: they happened because someone was in a hurry and the system allowed it. They are not discipline problems, they are workflow design problems — and that matters for what you do next.
The first hour
In this order
- Minute 1 — stop it spreading: revoke the link, recall the message if the system allows it, disable the account
- Minutes 5-15 — write down what left: which fields, how many people, to whom, at what time — written, not from memory
- Minutes 15-30 — notify the person designated in advance, with the notes above
- Within the hour — assess together whether the affected people need to be told and what else is required
What to write down, specifically
The note from the first few minutes is the single most valuable piece of information in the whole incident, because in three days nobody will remember precisely. Write it once, with five things in it.
- Which data, at field level: names and salaries, or names and departments? The difference changes everything.
- How many people are in the file — the number, not “a few”.
- Who it went to, and whether they are inside or outside the organisation.
- The exact time and the channel.
- What you did to stop it spreading, and at what time.
The first point determines severity and is often the hardest to pin down. An export of 400 rows “about employees” might be a list of names and departments, or it might carry salaries and identity data — two completely different incidents, with two different correct responses.
The conversation with the recipient
If the file went to an identifiable person, a direct phone call in the first few minutes achieves more than anything else. A short message, no drama: what was sent by mistake, a request to delete it without forwarding, and a written confirmation that they did.
What does not work is a formal retraction email sent the next day. By then the file has been opened, and the legal tone turns a person who would have cooperated into a cautious one. Ask for the deletion confirmation, keep it — but do not mistake it for a guarantee.
Afterwards, once the urgency fades
This is where an organisation that learns diverges from one that merely got away with it. The question is not who made the mistake, but what made the mistake possible — because anyone in a hurry will make the same mistake under the same conditions.
- Why did that file exist as a local export instead of being read from the system?
- Why did it contain every field, when the recipient needed three?
- Why could it be sent with no check on the way out?
- Why was the account of someone gone three months still active?
Most HR incidents are stopped at source by a single change: fewer exports. A report consulted inside the system, with role-based access, cannot be attached to the wrong email, because it does not exist as a file on anybody’s laptop.
Is it still an incident if it went to a colleague?
You record it and assess it the same way. A colleague who sees the whole team’s salaries is a real incident even though nothing left the organisation — and treating it as “does not count” is exactly the habit that produces the serious case.
Who should the designated internal contact be?
Decided in advance and known to everyone, with a deputy for holidays. If you are working out who to notify at the moment of the incident, you lose precisely the hour that matters.
How do I get people to report quickly?
Your reaction to the first incident sets the rule for every one after it. If the person who reported it is reprimanded, you will hear about the second incident three months later, from somebody else.
Where to start
Write on a single page who gets notified and what gets recorded, and send it to the HR team. Five lines available before the incident are worth more than a ten-page procedure written after one.
Reports consulted inside the system, with role-based access, instead of exports
A file that exists on no laptop cannot be attached to the wrong email — and who opened what stays in the log.
You can create an account in a few minutes and use every module for 7 days, no card required.