Confidential files by email: who is liable, and for what

Confidential files by email: who is liable, and for what

Written By Alexander Burba
August 18, 2026

The attachment is the standard method for sending confidential documents, and it is the only step in the process for which no one is responsible. Client correspondence, medical reports, credit files, personnel records: everything leaves the firm as a file attached to an email. Responsibility for it cannot be delegated, and it does not depend solely on whether something has already gone wrong.

Four industries, four legal frameworks, one common point: in an audit, what is usually in focus is not the damage that occurred but which safeguards were documented.

What makes exchanging confidential client documents legally risky?

For law firms, tax advisors and auditors, confidentiality is not a duty of care, it is backed by criminal lawSection 203 of the German Criminal Code (§ 203 StGB) makes the unauthorised disclosure of another person's secret a criminal offence, and the professional obligation sits alongside it in § 43a(2) BRAO and § 57(1) StBerG. One distinction matters here: § 203 StGB requires intentional disclosure, so a misdirected email is not automatically a criminal offence. The professional duty of confidentiality and the obligations under Art. 32 GDPR, by contrast, do not depend on intent but on the protective measures in place.

Then there is retention: § 147 AO requires tax-relevant records to be kept, six to ten years depending on the type, and to remain available and readily legible at all times. The GoBD add the requirements of unchangeability and traceability. A sent-items folder is not evidence of who read a file, or when.

The practical core: a sent email cannot be recalled, it leaves no access log, and the attachment then sits permanently in a mailbox the firm does not control.

How dangerous is insecure data exchange for hospitals in Germany?

Health data is a special category of personal data under Article 9 GDPR, subject in principle to a prohibition with a narrow set of exceptions. Hospitals, medical centres and practices are also covered by § 203 StGB, and Article 32 GDPR requires safeguards appropriate to the risk. For findings, care documentation and admission data the risk is high, so the standard is high.

The fine tiers are worth separating: infringements of the processing principles, which include Art. 9 for health data, fall under Art. 83(5) GDPR in the upper tier of up to 20 million euros or 4 percent of total worldwide annual turnover, whichever is higher. Infringements of the security obligations under Art. 32 GDPR fall under Art. 83(4), up to 10 million euros or 2 percent. Supervisory reviews in practice focus above all on which measures are documented.

DigiG and KHZG add pressure from the other direction: more is transmitted electronically, and for the route outside KIM and the ePA usually nothing is defined. That is precisely where the email with the attachment lands.

Why is insecure file exchange a compliance risk for banks?

In financial services, file exchange is not an IT topic, it is a supervisory one. § 25a KWG requires proper business organisation; MaRisk sets out the risk-management detail (currently BaFin Circular 06/2026 (BA)). For ICT risk management including third-party risk, DORA has applied directly as EU law since 17 January 2025. The BAIT have correspondingly fallen away for DORA subject institutions and remain in force only for a transitional group.

Three requirements follow that email structurally cannot meet: traceability at document level, control over the recipient group after sending, and the ability to demonstrate to a supervisor who had access and when. Missing encryption is only the most visible part. In practice, a review tends to start from missing traceability rather than from encryption alone.

What are the risks when public authorities exchange confidential documents by email?

For public authorities and municipal administrations, three layers meet: Article 32 GDPR for safeguards, the BSI IT-Grundschutz as the benchmark for what counts as appropriate, 

and the German NIS2 implementation act with a significantly broader duty of risk management plus evidence and reporting obligations. Those duties are in force: the statutory registration deadline with the BSI has already passed, and the BSI is

calling on affected organisations to register without delay.

On top of that comes a requirement the private sector does not have: records management. A case file has to remain traceable. If part of it leaves the building as an attachment and exists only in one caseworker's sent items, it is neither part of the file nor auditable.

What email cannot do, technically

These four points are sector-independent, and they are why the problem cannot be solved by being careful:

  1. Transport encryption is not content encryption. TLS protects the path between two servers. After that the attachment sits unencrypted in the mailbox, in every backup and in every forwarded thread.
  2. No recall. The wrong recipient stays a recipient.
  3. No access log. There is no record of who opened, saved or forwarded the file, and that record is exactly what supervisors and professional law require.
  4. No version. As soon as two people edit the same file there are two truths and no traceable authoritative copy.

What matters instead

The requirement is not "send it encrypted", it is keep access controllable and provable. Six criteria you can check with any provider:

  • A share, not an attachment. The document stays in one place; the recipient gets access, not a copy.
  • Permanent access, not just links. For ongoing collaboration, external parties get their own user accounts with defined permissions, instead of a chain of individual share links that nobody can keep track of.
  • Password protection and an expiry date on every share link, and the ability to revoke it.
  • Logs at file level, not at mailbox level.
  • Granular rights per area, so an external participant sees exactly one document and not a folder.
  • Version history, so the authoritative copy stays identifiable.

With SecureCloud, data is stored AES-256 encrypted in German data centres; an additional encryption layer can be enabled per library, and its key never leaves the device. Share links carry password protection and an expiry date, logs are kept at file level, and Office and PDF documents can be edited simultaneously in the browser, including with external participants who have no account of their own. Alongside share links, external parties can also be added as their own users with granular permissions, in practice the more common route whenever collaboration runs longer than a single file transfer. The platform is GDPR-compliant, ISO 27001 and Trusted Cloud certified, and BSI C5 attested. It is operated by SecureCloud GmbH, headquartered with its data centres in Germany, with no US parent company.

The first step is smaller than the topic: pick one process where confidential attachments leave the building every week, and convert that one.

This article provides a general overview of typical regulatory requirements and does not constitute legal advice for an individual case. What applies is the version of each provision in force at the time and the circumstances of the specific case. As at: August 2026.

FAQ

1. How can law firms exchange client correspondence without violating the duty of confidentiality under Section 203 of the German Criminal Code (StGB)?

By ensuring the document never leaves the law firm as a copy. Instead of an attachment, the client receives a password-protected access link with an expiration date that can be revoked at any time, and every access is logged at the file level. This makes it possible to prove, in the event of a dispute, who had access and when, something an outbox cannot do. The retention requirements under Section 147 of the German Fiscal Code (AO) and the GoBD are covered by the version history. Data is stored with AES-256 encryption in German data centers; the platform is ISO 27001-certified and BSI C5 attested.

2. How can hospitals transmit medical reports to collaborating practices if KIM is not available for this purpose?

By sharing the document with limited validity rather than via an email attachment. The receiving practice does not need its own account; it sees only the shared document itself and not the surrounding folder, and access is logged. For health data under Article 9 of the GDPR, this is the difference between a documented security measure and one that cannot be verified. An additional layer of encryption can be enabled per library, and the encryption key never leaves the device.

3. 

 

Does SecureCloud meet the logging and audit trail requirements that MaRisk and DORA impose on the exchange of credit files?

SecureCloud logs access at the file level, assigns granular permissions per library, and maintains a version history, making it possible to demonstrate to the supervisory authority who had access to which document and when. Sharing permissions can be revoked after sending, ensuring that the recipient group remains controllable. Whether the specific implementation in an individual case meets the requirements of MaRisk and DORA is determined by the institution’s outsourcing and risk assessment; the platform provides the technical evidence to support this. The Advanced and Enterprise editions run as dedicated, isolated instances.

4. How can local governments send confidential documents to external parties without losing the traceability of their records management?

By keeping the document in one place and granting external parties access to it, rather than sending a copy as an attachment. Access is logged at the file level and thus remains part of the traceable document workflow, whereas an attachment in a case worker’s outbox lies outside the file. Permissions can be assigned on a per-library basis; sharing links include expiration dates and password protection. The BSI IT-Grundschutz serves as the benchmark for adequacy.

5. Can SecureCloud revoke a sharing permission that has already been granted if a confidential document was sent to the wrong recipient?

Yes. A sharing link can be revoked at any time, and access ends when the expiration date is reached even without intervention. This is the structural difference from an email attachment: a sent copy remains with the recipient, whereas a revoked sharing link does not. The access log also shows whether the document was opened before revocation, which is the decisive factor in assessing whether reporting is required.

Interessiert Sie die souveräne Cloud?

Unsere Experten erklären Ihnen gerne mehr.

Picture of Alexander Burba

Alexander Burba

Alexander Burba is Marketing Manager at SecureCloud and is responsible for brand awareness and positioning online. He follows the German market for secure cloud infrastructure and the regulatory shifts reshaping it, from NIS2 and DORA to the sovereignty requirements now placed on the public sector. In his articles he translates those shifts into the requirements that actually apply in regulated industries, and into the decision that comes next.