Can I send personal or health data by fax?

Short answer

The GDPR does not ban fax: it requires you to transmit only what is necessary, to secure the send in proportion to the risk and to react if something goes wrong. Since fax is not encrypted, most precautions concern the right number and where the recipient's fax machine is located.

What the GDPR says

The General Data Protection Regulation does not talk about channels: it talks about risk. Sending a document containing personal data is processing, whatever the means. The obligations are the same as for an email: transmit only what is necessary, secure the send in proportion to the risk, and know how to react if something goes to the wrong place.

What is specific to fax

A fax is not encrypted over the telephone network, and no service can encrypt it end to end. The effort therefore goes into organisation: the right number, a recipient who knows the fax is coming, a fax machine that is not in a busy passageway.

For health data, which counts as sensitive data, first ask yourself whether a secure health messaging service or an upload to the recipient's online space is available.

Practical precautions

Remove from the document anything that is not needed for the purpose. Check the number against a recent source and read it back before confirming. Add a cover sheet with the recipient's name and the word “confidential”. Let the recipient know, and ask them to confirm receipt.

If a fax goes to the wrong number, contact the unintended recipient to ask them to destroy the document, and record the incident: depending on the risk, notifying the supervisory authority may be necessary.

Key points

  • The GDPR does not ban fax: it requires minimisation and proportionate security.
  • Fax is not encrypted: the effort goes into organisation.
  • Right number, “confidential” cover sheet, recipient forewarned.
  • If a fax goes to the wrong number: ask for it to be destroyed and record the incident.

All questions