Join our Newsletter — 33% off our NHI Course

Why do unencrypted emails create compliance and legal risk for organisations handling regulated data?

Unencrypted email can expose personal or protected information to interception, which creates both security and compliance exposure. Regulations such as HIPAA and GDPR require organisations to protect sensitive data in transit and limit unnecessary disclosure. If email traffic carries regulated information without safeguards, the organisation may face fines, audit findings, and avoidable privacy incidents.

Why unencrypted email creates compliance exposure

Email is not just a convenience channel, it is a transport path for regulated information. When messages move in clear text or without effective encryption, interception, mailbox compromise, forwarding, and misdelivery can expose protected data outside the intended trust boundary. That matters because many compliance regimes expect organisations to use appropriate safeguards when personal, health, financial, or otherwise regulated data is transmitted.

For regulated data, the key issue is not only that a message can be read by the recipient, but that the organisation can no longer show it applied reasonable protection in transit. In practice, that weakens data-handling controls, audit evidence, and the ability to demonstrate that disclosures were limited to authorised parties.

Compliance findings often arise when unencrypted email is used for routine business workflows, such as sending attachments, support updates, or notifications containing sensitive fields. Even where a regulation does not explicitly mandate one specific technology, the control expectation is usually that the organisation protect confidentiality proportionate to the sensitivity of the data and the transmission path.

Legal exposure comes from the fact that unencrypted email can create an avoidable disclosure of regulated information. If the message contains personal data, health data, customer records, or similar protected material, the organisation may trigger breach notification duties, contract disputes, regulator scrutiny, or privacy claims depending on the facts and jurisdiction.

That risk is amplified when email is used across organisational boundaries. Once a message leaves the sender’s control, the sender may still retain responsibility for the decision to transmit it insecurely. The organisation then has to explain why a safer channel, secure portal, or encryption method was not used for data that warranted protection.

For teams handling EU personal data, GDPR is especially relevant because security of processing, data minimisation, and protection by design all push organisations toward safer transmission choices. For health-related workflows, HIPAA risk is similar in practice: the issue is whether reasonable safeguards were in place for data in transit and whether the sender limited unnecessary disclosure.

What organisations should control before sending regulated information by email

The practical question is not whether email can ever be used, but whether the message content and audience justify the risk. If the email includes regulated information, organisations should decide whether encryption, secure links, message expiry, redaction, or an alternate delivery channel is required before the message is sent.

Controls should also match the lifecycle of the data. A message that was acceptable for low-risk correspondence may become unacceptable once it includes identifiers, attachments, case notes, or account data. Clear rules for classification, approved sending paths, and retention help prevent staff from relying on judgment at the moment of send.

For broader control mapping, NIST SP 800-53 Rev. 5 Security and Privacy Controls supports the underlying need to protect information in transit, while NIST Cybersecurity Framework 2.0 reinforces governance over data protection decisions. In cloud-heavy environments, the CSA Cloud Controls Matrix is useful where email handling is part of a wider data-security and IAM control set.

Risk and Threat Considerations

Unencrypted email creates a double exposure: the message can be intercepted in transit, and it can also be mishandled after delivery through forwarding, mailbox compromise, or accidental external sharing. The risk becomes materially higher when the email carries regulated data that is sensitive enough to trigger reporting, remediation, or legal review if exposed.

Failure mechanism: The sender assumes the mail path and recipient handling are sufficiently trusted, but the message may traverse multiple providers, devices, and mailboxes without strong confidentiality protection.

Impact: The result can be unauthorised disclosure, breach notification obligations, audit findings, contractual breach, regulator attention, and reputational harm, even if no attacker explicitly targeted the message.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
GDPR Art. 5 — Principles Relating to Processing of Personal Data Encrypted transport supports lawful, minimised handling of EU personal data.
Art. 32 — Security of Processing Email encryption is a core safeguard for protecting regulated data in transit.
Recommendation — Apply Art. 5 to minimise exposure and justify secure transmission for personal data. Implement Art. 32 safeguards for confidentiality when sending regulated data by email.
NIST SP 800-53 Rev 5 SC-8 — Transmission Confidentiality and Integrity Directly addresses protecting data while it is transmitted over email and other channels.
AU-2 — Event Logging Logging supports evidence of who sent what and when for regulated-message review.
Recommendation — Use SC-8 controls to protect regulated information transmitted by email. Retain email activity logs to support investigations and compliance evidence.
ISO/IEC 27001:2022 A.8.24 — Use of cryptography Cryptography is the primary control family for protecting email content in transit.
Recommendation — Require cryptographic protection for regulated email content where risk warrants it.
CIS Controls v8 CIS-3 — Data Protection Data protection safeguards help limit exposure of sensitive information sent by email.
Recommendation — Classify sensitive email data and enforce approved protection before transmission.

Practitioner Guidance

What to verify: Verify the data classification before email leaves the organisation, and treat any regulated content as needing an approved secure delivery path unless a documented exception exists. If staff cannot quickly tell whether a message is regulated, the control design is already too weak.

Decision rule: If the message contains personal, health, financial, or similarly protected information, use encryption or an alternative secure channel by default, and reserve plain email for content that would not create harm if exposed beyond the recipient.

Practitioner takeaway: The core judgment is whether the organisation can defend the transmission choice, not whether the message was intended for the right recipient. If that choice cannot be explained to an auditor or regulator, the risk has already become material.