The Adviser Online - October 2026 | Page 44

Protection
Medical underwriting material, GP reports, and health questionnaires contain health data. UK GDPR treats this as special category personal data, so it needs particular care.
Identity documents, across all of it
Passports, driving licences, and National Insurance numbers appear across advice, mortgage, and protection work. Among UK adults who have shared personal data by email, at least a quarter have sent one of those three. The information can be misused for identity fraud and may remain useful long after the case has closed.
Dual-authority firms may handle several of these document types for the same client. One clear standard for outbound client email helps staff apply the right protection across the relationship.
How secure email supports regulatory compliance
UK GDPR requires appropriate technical and organisational measures to protect personal data, and ICO guidance recognises encryption as an appropriate safeguard when sharing data by email. The Consumer Duty ' s cross-cutting rules include acting to avoid causing foreseeable harm and supporting retail customers to pursue their financial objectives.
Record-keeping rules may also require firms to retain communications in a durable medium so they can be retrieved unchanged. Since 12 January 2026, the FCA ' s PS25 / 13 has made electronic communication the default for relevant MiFID-derived retail-client disclosures, where the delivery method meets the durable-medium criteria and clients are told about their right to request paper.
Secure email supports those expectations through practical controls. It encrypts the message itself, checks the recipient before opening, gives the sender a way to withdraw or expire a message, and records what was sent, when, and whether it was opened. A protected reply keeps sensitive information inside the same controlled exchange.
Before sending, ask:
• Does the body or attachment contain sensitive client information?
• What could happen if the wrong person opened it?
• Would the client need to return sensitive information in the same exchange?
• If someone asked in six months, could you show who opened it?
" The mistakes we need to design for are ordinary: the wrong name in the To field, or the right attachment on the wrong case. Secure email should fit the way advisers work and give the firm control when somebody makes that mistake." Carole Howard, Beyond Encryption( Mailock)
Where Mailock fits
Mailock is Beyond Encryption ' s secure email platform. It adds AES-256 encryption, recipient authentication, secure replies, message revocation, and message tracking to email-based communication. Advisers work from Outlook or a browser, while recipients can open and reply to a secure message without creating another account.
Start with the documents your firm sends most often. Decide which may travel by ordinary email, which need protected delivery and replies, and what evidence staff must keep. That gives advisers a rule they can apply when the client is waiting and the deadline is real.
Get in touch
Email our team to find out more about Mailock by Beyond Encryption:
EMAIL THE TEAM
September 2026 | 23