Clivanta
← Blog

GDPR and client documents: where email falls short

12 May 2026 · The Clivanta team

A client sends you a scan of a director’s passport for a KYC file. Simple enough. Except that passport now sits in the client’s sent items, in your shared inbox, in the personal inbox of whoever it was forwarded to for a second opinion, and in a downloads folder on a laptop that goes home each evening. One document, several copies, and you could not honestly say where all of them are.

Client documents are full of exactly this kind of thing. And most of the personal data your firm handles arrives not through a form on a website, but as an attachment.

The personal data is hiding in ordinary requests

It is easy to think of GDPR as a matter of cookie banners and marketing lists. For a professional-services firm, the real exposure is the document pile. IDs and proof of address for KYC. Payroll files with salaries and national identifiers. Financial statements, bank mandates, registers of directors and shareholders, beneficial-ownership charts. Almost every routine request you send a client asks, in passing, for personal data about a real person.

That does not make the work improper. Firms have every reason to collect these documents. It simply means the ordinary business of gathering evidence is also the handling of personal data, and the place most of it lands, email, was never designed to keep track of it.

It is worth being honest about the scale of it too. A mid-sized firm might handle personal documents for hundreds of individuals across its client base in a single year, most of them arriving as attachments and coming to rest in mailboxes no one is really watching. The exposure is not one dramatic file. It is the slow accumulation of ordinary ones.

Email scatters copies you cannot account for

Email’s core behaviour is to make copies and move them around. That is what it is for. It is also the opposite of what careful data handling asks of you.

Forward an attachment and a new copy exists on another server, in another mailbox, beyond your sight. A shared inbox means everyone with access can open everything in it, whether or not they need that particular file. People download attachments to work on them locally, and those downloads linger in folders no one revisits. There is no record of who opened what, no way to narrow access to the people actually working the engagement, and no reliable way to find every copy later. The convenience that makes email feel effortless is exactly what makes it hard to control.

The questions email cannot answer

Set aside the legal detail for a moment and think in practical terms. Good handling of personal data tends to turn on a handful of plain questions, and email answers each of them badly.

  • Who has accessed this document? In a shared inbox, effectively anyone who can reach the mailbox. There is no log.
  • Can you limit it to the people who need it? Not really. An attachment, once sent, goes where the recipient sends it next.
  • If a client asks you to delete their data, can you find every copy? Across sent items, forwards and local downloads, honestly, no.
  • How long will you keep it, and can you enforce that? Retention on an unstructured pile of emails is a good intention, not a control.

None of this means email is forbidden. It means email quietly makes every one of these questions harder to answer than it needs to be.

What structured collection gives you

The alternative is not more policy. It is a place where the handling is easier by design. When client documents come in through a structured collection process rather than as loose attachments, the picture changes.

  • One audited place per Client and Engagement. The documents live where they belong, not sprayed across a dozen inboxes. There is a single copy to reason about, not an unknown number.
  • Access that matches need. People see the engagements they work on. The passport for one client’s KYC file is not sitting in a mailbox the whole team can browse.
  • An activity log of what happened. Every meaningful action, a request sent, a Document uploaded, a review decision, an acceptance to Evidence, is recorded with a name and a timestamp. If you need to show who did what, the record already exists. We wrote about that record in more depth in what a defensible audit trail actually looks like.
  • Retention you can reason about. When documents sit in one structured system rather than scattered across inboxes and laptops, a retention rule is something you can actually apply, and an erasure request is something you can actually action.

Clivanta is built this way on purpose, and you can read how it treats access and records on the security page.

A note, and a caveat

This is a piece about handling practice, not legal advice. Your specific obligations under GDPR depend on your role, your data and your circumstances, and the sensible move is to confirm the details with your data protection officer or adviser rather than take a blog post as settled interpretation.

But as a matter of practice, the principle is not complicated. Every uncontrolled copy of a personal document is a small liability you did not have to create. The fewer copies scattered across inboxes, the easier every question about that data becomes to answer.

Personal data is easiest to protect when there is only one place it lives.


Clivanta runs the audited request-and-response loop for professional-services firms. See how it works →