Om de ûnderfining foar jo te ferbetterjen is tydlik de funksjonaliteit dan dizze website troch ûnderhâldswurk beheind. Wannear in artikel jo probleem net oplost en jo in fraach stelle wolle, kin ús stipemienskip jo helpe yn @FirefoxSupport op Twitter en /r/firefox op Reddit.

Sykje yn Support

Mij stipescams. Wy sille jo nea freegje in telefoannûmer te beljen, der in sms nei ta te stjoeren of persoanlike gegevens te dielen. Meld fertochte aktiviteit mei de opsje ‘Misbrûk melde’.

Mear ynfo

Dizze konversaasje is argivearre. Stel in nije fraach as jo help nedich hawwe.

We use Thunderbird to send work emails and given the introduction of GDPR on May 25, we need to know if your security levels support GDPR compliance

  • 2 antwurd
  • 1 hat dit probleem
  • 20 werjeftes
  • Lêste antwurd fan JaneSabherwal

more options

Hello! Just wondering with GDPR how we can continue to use Thunderbird to send work emails with client data and know they will be GDPR compliant. Any advice appreciated. Thank you Jane

Hello! Just wondering with GDPR how we can continue to use Thunderbird to send work emails with client data and know they will be GDPR compliant. Any advice appreciated. Thank you Jane

Keazen oplossing

It may be harder to configure and use email to send and receive information securly in GDPR compliance as you can't control your recipient's or senders compliance. Emails sent to GMail recipients come to mind.

UK's Information commissioner's office has a lot of information on compliance, this link is one of those simpler documents to check:

Thunderbird can be configured to:

  • Encrypt, decrypt and digitally sign your email communications, to avoid data breaches and leaks
  • Avoid collecting email addresses in your address books to comply with email communications opt-in / opt-out rules and regulations
  • Setup email signatures and / or headers to include disclaimers, links to privacy policies, etc.
  • Avoid sending large attachments directly - for example using the Filelink extension to store them in self-hosted storage using NextCloud (a solution recently chosen by the German government)

In my opinion your IT department should seek some legal guidance and assess what your risk is to be non-compliant, then address those concerns by looking at technical + human implications of implementing compliance. In many cases I suspect this will mean completely avoiding email and implementing new policies like "always digitally sign any emails".

As an example, if your company sends any documents including personal information, perhaps such process will need to be replaced with a secured website or offline process to completely avoid unencrypted email.

Dit antwurd yn kontekst lêze 👍 0

Alle antwurden (2)

more options

Keazen oplossing

It may be harder to configure and use email to send and receive information securly in GDPR compliance as you can't control your recipient's or senders compliance. Emails sent to GMail recipients come to mind.

UK's Information commissioner's office has a lot of information on compliance, this link is one of those simpler documents to check:

Thunderbird can be configured to:

  • Encrypt, decrypt and digitally sign your email communications, to avoid data breaches and leaks
  • Avoid collecting email addresses in your address books to comply with email communications opt-in / opt-out rules and regulations
  • Setup email signatures and / or headers to include disclaimers, links to privacy policies, etc.
  • Avoid sending large attachments directly - for example using the Filelink extension to store them in self-hosted storage using NextCloud (a solution recently chosen by the German government)

In my opinion your IT department should seek some legal guidance and assess what your risk is to be non-compliant, then address those concerns by looking at technical + human implications of implementing compliance. In many cases I suspect this will mean completely avoiding email and implementing new policies like "always digitally sign any emails".

As an example, if your company sends any documents including personal information, perhaps such process will need to be replaced with a secured website or offline process to completely avoid unencrypted email.

more options

Thank you for taking the time to answer this so fully Fabian - your answer has flagged up some important issues - I think we will need to find a new communications solution after May 25 if we are to be GDPR compliant. Best wishes Jane