UNILINK Helpunilink.help

Which sensitive details should you keep out of an initial support message?

An initial support message sent through ordinary email should leave out sensitive personal information, especially details that are not genuinely necessary for the request. If a necessary detail is still needed, the sender should confirm an appropriate secure route before including it. The cited guidance does not identify which types of personal information count as sensitive in this context, so this article does not invent a list of examples.

What the cited guidance establishes

Australia's privacy regulator warns that “Email is not a secure form of communication” and advises avoiding “certain types of personal information via unsecured email.” Applied to an initial support message, this supports keeping sensitive information out of ordinary email rather than treating the first message as a secure place to disclose it.

The same guidance asks whether personal information is genuinely necessary before it is collected. For an initial message, that means checking whether each detail is actually needed to understand or answer the request. A detail that is not needed should be left out.

How to check the message

  1. Check the channel. If the initial message will be sent through ordinary email, treat the channel as unsecured for this purpose.
  2. Check necessity. Identify the information required to answer the immediate question and remove any detail that is not required.
  3. Handle necessary information separately. If a sensitive detail cannot be omitted, confirm an appropriate secure method before sending it. The cited guidance does not name a particular secure channel.

What the reader must still confirm

The cited material does not provide a complete category list, a case-specific list of required fields, or a named secure channel. The reader must still confirm:

  • Which proposed details are necessary for the actual request.
  • Whether the chosen channel is secure and suitable for the information.
  • Which secure method the relevant organisation accepts.

Until those points are confirmed, the cautious choice is to keep sensitive personal information out of the initial ordinary-email message.

Sources