Research
24% of UK adults have accidentally sent personal data to the wrong recipient
The channel people prefer is the one where the mistakes happen most
Email is where sensitive information actually moves, and a quarter of UK adults have sent some of it to the wrong person. Our 2023 survey looked at what people send, how often it goes astray, and who it happens to.
The problem
Email that reaches the wrong person
Emailing the wrong recipient is the single most commonly reported data-security incident to the ICO, at around 1 in 5 reported incidents between 2022 and 2024. A wrong address, a stale contact record, or an autocomplete slip is enough.
The numbers
Key findings
We surveyed 2,000 UK adults with 3Gem Media Group between 17 and 20 February 2023, with quotas on age, gender, and region so the sample represented all UK adults aged 18 and over.
24% misdirected data
More than half have emailed data
73% know email is not secure
47% sent a home address
3 in 10 sent bank details
39% prefer email
21% asked by an adviser
Gen Z 7x more likely
Survey summary
What the findings mean for a sender
Two findings sit awkwardly together. People would rather receive sensitive documents by email than through a portal, and people send email to the wrong person often enough that a quarter of them have done it.
So moving off the channel is not the answer. The answer is to stop treating the address as a guarantee of who will read the message.
The way forward
Four layers that reduce the risk
Our framework, offered as a starting point rather than a standard. Each layer does a different job, and they work best together.
- Contact data: keep addresses and mobile numbers accurate and governed
- Send-time checks: confirmation prompts and warnings before a message goes
- Protected access: a proportionate check before the content opens
- Response: evidence and a rehearsed process when something goes wrong
From The Founder
It’s not just up to consumers to keep their data safe
“It’s not just up to consumers to keep their data safe, but also businesses to provide secure communication methods. Only by working together can we keep data secure from risk.”
Questions
Questions about this research
If most people know email is not secure, why is it still where sensitive information moves?
Because it is what people prefer. 39% chose email for business communication, ahead of a mobile app at 30% and an online portal at 16%, and more than half of UK adults have sent personal data by email. Only 27% believe email is protected and secure, so people are largely making that choice with their eyes open. That is why the useful response is to make the channel safer rather than to move people off it.
What are people actually sending by email?
Of those who have shared personal data by email, 47% sent a full home address and three in ten sent bank details, and at least a quarter have sent a passport, driving licence, or National Insurance number. Regulated professionals are part of the pattern: 21% of UK adults have been asked to email personal details by a financial adviser, and 25% by a health professional.
Who is most likely to misdirect an email?
Gen Z respondents were seven times more likely than baby boomers to report having done it. These are self-reported answers, so some of that gap is who notices and admits a mistake. The more useful reading is that misdirection is not confined to the careless or the untrained, so a control that depends on the sender being careful is the wrong place to put the weight.
Where should a firm start?
With contact data. Most misdirection starts with a wrong or stale address, and protecting a message that is going to the wrong person does not help. Accurate, governed addresses and mobile numbers reduce how often the question arises at all; send-time prompts catch some of the rest; and a proportionate check before the content opens covers the messages where being wrong matters most.
Does 24% mean a quarter of emails go to the wrong recipient?
No. It means around a quarter of UK adults told us they have accidentally sent personal data to the wrong recipient at some point. It measures how many people it has happened to, not how often it happens per message.
Sources and method
Method: Desk research on public ICO material, alongside our own 2023 UK consumer survey. The ICO dataset covers incidents discovered and reported to the regulator, uses best-fit categories, and includes incomplete records, so it shows a recurring control problem rather than the full UK frequency.
Sources accessed July 2026. |
Recipient authentication
Learn more about recipient authentication
See how Mailock could help your business to choose the right check for each message.