Join the Mozilla’s Test Days event from 9–15 Jan to test the new Firefox address bar on Firefox Beta 135 and get a chance to win Mozilla swag vouchers! 🎁

为提升您的使用体验,本站正在维护,部分功能暂时无法使用。如果本站文章无法解决您的问题,您想要向社区提问的话,请到 Twitter 上的 @FirefoxSupport 或 Reddit 上的 /r/firefox 提问,我们的支持社区将会很快回复您的疑问。

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

详细了解

We use Thunderbird to send work emails and given the introduction of GDPR on May 25, we need to know if your security levels support GDPR compliance

  • 2 个回答
  • 1 人有此问题
  • 20 次查看
  • 最后回复者为 JaneSabherwal

more options

Hello! Just wondering with GDPR how we can continue to use Thunderbird to send work emails with client data and know they will be GDPR compliant. Any advice appreciated. Thank you Jane

Hello! Just wondering with GDPR how we can continue to use Thunderbird to send work emails with client data and know they will be GDPR compliant. Any advice appreciated. Thank you Jane

被采纳的解决方案

It may be harder to configure and use email to send and receive information securly in GDPR compliance as you can't control your recipient's or senders compliance. Emails sent to GMail recipients come to mind.

UK's Information commissioner's office has a lot of information on compliance, this link is one of those simpler documents to check:

Thunderbird can be configured to:

  • Encrypt, decrypt and digitally sign your email communications, to avoid data breaches and leaks
  • Avoid collecting email addresses in your address books to comply with email communications opt-in / opt-out rules and regulations
  • Setup email signatures and / or headers to include disclaimers, links to privacy policies, etc.
  • Avoid sending large attachments directly - for example using the Filelink extension to store them in self-hosted storage using NextCloud (a solution recently chosen by the German government)

In my opinion your IT department should seek some legal guidance and assess what your risk is to be non-compliant, then address those concerns by looking at technical + human implications of implementing compliance. In many cases I suspect this will mean completely avoiding email and implementing new policies like "always digitally sign any emails".

As an example, if your company sends any documents including personal information, perhaps such process will need to be replaced with a secured website or offline process to completely avoid unencrypted email.

定位到答案原位置 👍 0

所有回复 (2)

more options

选择的解决方案

It may be harder to configure and use email to send and receive information securly in GDPR compliance as you can't control your recipient's or senders compliance. Emails sent to GMail recipients come to mind.

UK's Information commissioner's office has a lot of information on compliance, this link is one of those simpler documents to check:

Thunderbird can be configured to:

  • Encrypt, decrypt and digitally sign your email communications, to avoid data breaches and leaks
  • Avoid collecting email addresses in your address books to comply with email communications opt-in / opt-out rules and regulations
  • Setup email signatures and / or headers to include disclaimers, links to privacy policies, etc.
  • Avoid sending large attachments directly - for example using the Filelink extension to store them in self-hosted storage using NextCloud (a solution recently chosen by the German government)

In my opinion your IT department should seek some legal guidance and assess what your risk is to be non-compliant, then address those concerns by looking at technical + human implications of implementing compliance. In many cases I suspect this will mean completely avoiding email and implementing new policies like "always digitally sign any emails".

As an example, if your company sends any documents including personal information, perhaps such process will need to be replaced with a secured website or offline process to completely avoid unencrypted email.

more options

Thank you for taking the time to answer this so fully Fabian - your answer has flagged up some important issues - I think we will need to find a new communications solution after May 25 if we are to be GDPR compliant. Best wishes Jane