When we think about data breaches, we often picture sophisticated cyberattacks, ransomware or stolen databases.
But some data protection incidents can begin with something much simpler: an email sent incorrectly.
Recent incidents in Singapore have highlighted how easily personal data can be exposed through ordinary business activities. In one recent case, an email invitation intended for a specific group of individuals was sent using the CC function instead of BCC, allowing recipients to see the names, email addresses and, in some cases, workplaces of other recipients. The affected group was associated with a genetic health condition, making the disclosure particularly sensitive. The incident was reported to the Personal Data Protection Commission (PDPC), which was investigating the matter.
Around the same period, another Singapore incident showed a different dimension of the same problem. An employee used an AI tool to generate code for distributing marketing emails. An error in the resulting code caused recipients' email addresses to be visible to other recipients, affecting more than 95,000 individuals. The PDPC described this as human error in developing the email distribution code with an AI tool, rather than a malfunction of the AI tool itself.
A small human error can have a much larger data protection consequence when there are insufficient checks and controls.
Email-related mistakes are not new.
The PDPC has previously highlighted accidental disclosure arising from issues such as selecting the wrong recipient, incorrect use of email functions and inadequate procedures when sending personal data.
Its guidance has recommended practical measures such as checking recipient addresses, disabling autocomplete where appropriate, introducing a short email-sending delay and protecting sensitive information sent by email.
This is an important reminder for organizations:
Data protection is not only about protecting systems from external attackers. It is also about preventing information from being disclosed accidentally during normal business operations.
Consider how often employees handle personal or confidential information through routine work:
* Sending customer or employee lists by email
* Using CC instead of BCC for group communications
* Using "Reply All" unnecessarily
* Using AI-generated code or automation without adequate testing
* Giving employees access to more personal data than they need
None of these activities necessarily appears high-risk.
The risk comes when there is no effective control to catch the mistake before information leaves the organization.
The better question is not "Can employees make mistakes?"
They can.
A more useful question is:
"What controls do we have to prevent one simple mistake from becoming a data protection incident?"
1. Build verification into higher-risk activities
Bulk emails or communications containing personal data may warrant a second-person check before they are sent.
The level of checking should be appropriate to the sensitivity and volume of information involved.
2. Share only what is necessary
If a recipient does not need a complete customer or employee list, there may be no reason to include it.
Minimizing unnecessary access and disclosure reduces the impact of an error.
3. Review how AI is being used
AI can help employees write, analyse and automate tasks. But AI-generated output should not automatically be treated as correct.
Where AI is used to generate code, automate processes or handle business information, appropriate testing, review and approval should be considered.
The PDPC has specifically highlighted the importance of data protection impact assessments, policies, processes, testing and review when organizations adopt AI tools.
4. Make the safe process the easy process
Technology can support employees.
Depending on the organization's needs, this could include email delays, recipient warnings, controls on bulk emails, data-loss prevention measures or automated detection of sensitive information.
The PDPC's 2026 advisory on common data protection lapses also emphasizes process checks, testing, monitoring and automation combined with human verification.
5. Learn from near misses
A wrong email does not always become a reportable data breach.
But a near miss can still be valuable.
Organisations can ask:
Why did the mistake happen?
Could the system have prevented it?
Was the employee adequately trained?
Was there a second check?
The recent incidents are not simply an argument against email or AI.
They demonstrate something broader.
Technology can make work faster. It can also make an error happen faster.
Good data protection therefore cannot rely solely on employees remembering every rule. Policies, processes, training and technical controls need to work together.
For organizations reviewing their data protection practices, it may be useful to look beyond formal policies and examine everyday activities such as email communications, document sharing, access rights, AI usage, employee awareness and data breach response.
The PDPC has also reminded organizations that reasonable security arrangements are required to protect personal data in their possession or under their control, and that organizations should routinely review their data protection policies and practices to identify gaps and appropriate remedies.
For organizations that want to take a closer look at their data protection practices, the starting point does not always have to be a major compliance exercise.
QuESH Consultants can support organizations with practical data protection reviews, including reviewing existing policies and procedures, conducting gap assessments, identifying areas for improvement, and supporting organizations in developing and implementing processes aligned with the Personal Data Protection Act (PDPA).
For more information, see our previous articles on [DPTM and Singapore's data protection requirements], or speak with QuESH if your organization would like to understand where its current practices may have gaps or require enhancement.
Sources to read: PDPC Singapore
At QuESH, our articles aim to create value for organizations and individuals by sharing insights and practical tips on achieving business excellence. Drawing from our experience as ISO auditors and consultants, we cover key topics such as quality management, workplace safety, environmental compliance, and health systems. Our content provides actionable solutions to help businesses of all sizes overcome challenges, drive growth, and unlock their full potential.
Subscribe With Us!ISO 45001:2018 emphasizes the critical role of "worker participation" in occupa…
Since the publication of ISO 45001: 2018 Standard in March 2018, there have bee…
What will the revised DPTM offer?