Fax and the GDPR

What the regulation requires, and what it never says.

The GDPR neither bans the fax nor authorises it: it does not talk about channels, it talks about risk. Sending a document containing personal data is processing, whatever the means, and the obligations attached are the same as for an email — minimise what is transmitted, secure the transmission in proportion to the risk, and know how to react when something goes to the wrong place. The particularity of fax is simply that encryption is not available, which shifts the effort onto organisational measures.

Four points that settle most of it

None of them is specific to fax, and that is precisely what to understand first.

  • Sending a fax is processing

    Transmitting personal data is a processing operation under the regulation, just like collecting or storing it. The choice of channel does not take the operation out of scope: it only changes which measures make it acceptable.

  • The regulation does not grade channels

    Nowhere will you find a list of permitted or forbidden means. The text requires measures "appropriate to the risk", which means the assessment depends on the sensitivity of the data, the volume and the consequences of disclosure — not on a label attached to the technology.

  • Minimisation applies to the page itself

    The minimisation principle covers the data you transmit, not only the data you keep. A page carrying a full social security number where an initial and a file reference would have done is excessive, even if the transmission goes perfectly.

  • A recipient outside the European Economic Area is a transfer

    Faxing to a third country falls under the rules on international transfers, exactly as an electronic send would. That the data travels down a phone line changes nothing.

The absence of encryption, and what it implies

The regulation requires appropriate technical and organisational measures, and it cites encryption among the examples — as an example, not as a general obligation. On a fax the question is settled in advance: the protocol provides none, and the last leg to the machine travels in the clear over the telephone network. No provider can remedy that.

This does not make fax non-compliant; it shifts the effort. What remains available are the organisational measures: checking the number against a written procedure rather than from memory, warning the recipient so the page does not sit on an accessible device, reducing what appears on the page, and keeping the transmission report as evidence of what went out and where. Those measures are what documents your assessment of the risk.

The reverse reasoning holds just as well: if the data is sensitive enough that only an encrypted, authenticated channel would do, and the recipient accepts one, then fax is not the right choice — even though nobody forbids it.

The fax sent to the wrong number

This is the most common GDPR scenario involving fax, and the one where reflexes matter. Disclosure to an unauthorised third party is a personal data breach, even without intent and even if the recipient acts in good faith.

  1. Document it, in every case

    The regulation requires every breach to be recorded internally — the facts, the effects and the remedial action — regardless of whether it has to be notified. That record is the first thing a supervisory authority asks for.

  2. Assess the risk to individuals

    The test is not how bad the mistake was but the risk to the people concerned: which data, how many individuals, what consequences are possible, and who actually received the page.

  3. Notify the authority within 72 hours if there is a risk

    Notification to the supervisory authority is made without undue delay and, where feasible, within 72 hours of becoming aware of the breach — unless it is unlikely to result in a risk to the rights and freedoms of individuals.

  4. Inform the individuals if the risk is high

    Where the breach is likely to result in a high risk, the individuals concerned must be told as well, in clear terms and with the steps they can take.

What an organisation can put in place

A number-checking procedure
Written down, and applied by someone other than the person dialling when the send is sensitive. It is the measure that addresses the most frequent cause of fax-related breaches.
A standard cover sheet
Naming the recipient and stating what to do if it arrives by mistake. It binds nobody, but it does get read and it limits accidental reading of what follows.
A supervised receiving point
A fax machine in a restricted-access area rather than a corridor. On the receiving side, that is the measure that changes the most.
Wiping the devices
Multifunction machines keep pages in memory and print a log. Plan for erasure before any resale, repair or disposal.
The processing entered in the record
If sending faxes is part of your routine processes, it belongs in the record of processing activities like any other flow, with its purpose, its recipients and its retention period.

Frequently asked questions

Does the GDPR forbid faxing health data?
No, no provision forbids it. Health data does fall into the special categories, whose processing is subject to stricter conditions and whose disclosure carries a higher risk: the bar for accompanying measures rises accordingly, and the recipient is often the very institution imposing this channel. What your organisation is allowed to do is settled with your data protection officer.
Is a fax sent to the wrong number a data breach?
Yes, as soon as it contains personal data: it is an unauthorised disclosure. It must be recorded internally in every case, notified to the supervisory authority if there is a risk to individuals, and communicated to those individuals if that risk is high.
Do I need a contract with the online fax service I use?
Where a provider processes personal data on your behalf, the relationship falls under the rules applying to processors and calls for a contractual framework. That is a point to check with whichever service you use before making it a regular professional tool.
What does MondialFax keep of my sends?
The document is deleted from our servers once the transmission is complete: it is neither archived, indexed nor analysed. The service asks for no registration, so there is no personal area gathering your past sends. What remains after sending sits with the recipient, out of our reach.

The most useful pages to carry on with your fax.