What must companies consider when documents are lost in the mail?

Cindy Stefanet
by Cindy Stefanet · 27.09.2026

Data breach due to the loss of documents by post

Postal delivery of documents is part of the everyday business of many companies. Often, these documents contain personal data. If such shipments are lost, this can have data protection consequences.

What matters is whether the loss leads to Risk to the rights and freedoms of the persons concerned is created. If this is the case, a data protection incident that must be reported may exist within the meaning of the GDPR.

When is there a duty to report to the data protection supervisory authority?

If a postal shipment containing personal data does not reach the intended recipient and there is a risk of loss, a Data privacy violation in accordance with Art. 33 GDPR.

If a shipment is lost or an unauthorized third party learns of its contents, the following consequences may result: Risks to the rights and freedoms of the persons concerned Whether a reporting obligation exists depends, in particular, on the nature, scope, number, and sensitivity of the data in question.

A risk is particularly likely when sensitive data such as health data, financial information, or proof of identity are affected.

Pursuant to Article 33 of the GDPR, the controller is required to notify the competent supervisory authority if a personal data protection breach has occurred. likely to be a risk for the rights and freedoms of natural persons.

There even exists a High risk, In accordance with Article 34 of the GDPR, the data subjects must also be informed.

Who is responsible for the reporting?

After Art. 33 GDPR the reporting of data protection violations is the responsibility of the Responsible persons. Against this background, the question of data protection responsibilities regularly arises in the event of the loss or non-delivery of postal shipments.

Role of the postal service provider

Postal service providers usually provide an independent transport service and do not act as order processors, but as independent controllers within the meaning of the GDPR.

Responsibility in the event of loss of a shipment

Although it could initially be assumed that the transfer of the shipment also entails the data protection responsibility of the Postal service providers However, in practice, several reasons exist for believing that the data protection obligations will continue to apply. Shipper lie:

  1. Lack of knowledge about the incident: Postal service providers do not regularly identify the loss of individual shipments on their own, especially if no special tracking or delivery confirmation is provided. Without knowledge of the incident, neither a risk assessment nor a timely notification can be carried out. The sender, however, will notice the failure to deliver.
  2. Lack of knowledge of the content of the broadcast: Only the sender knows the specific contents of the shipment, the type of personal data contained therein, its sensitivity, and the potential impact on the individuals concerned. The postal service provider does not have regular knowledge of the contents and therefore cannot carry out a risk assessment pursuant to Art. 33, 34 GDPR.
  3. Lack of contact with the affected individuals: Notifying the affected individuals requires that the individuals in question can be identified and contacted. The postal service provider typically has no data protection-related relationship with the affected individuals and does not possess the necessary background information. The sender, however, can inform the affected individuals without further ado.
  4. Time of loss is regularly unknown: Most often, it is not possible to determine clearly at which point the loss or incorrect delivery occurred. Therefore, a clear attribution to the sphere of the postal service provider is often not possible.

Even if the loss actually falls within the responsibility of the postal service provider, the obligation to conduct a risk assessment and to report any findings in accordance with Article 33 of the GDPR remains the responsibility of the sender.

The sender must therefore check, whether there is a data protection incident that requires reporting and immediately – usually within 72 hours – report to the competent data protection supervisory authority.

The calculation of the deadline depends on when the responsible person has sufficient Gained knowledge of the possible loss.

Importance for companies

Special care must be taken when sending personal data. If documents are lost in the mail, this can, depending on the nature and sensitivity of the data, constitute a risk to the individuals concerned and trigger a reporting obligation under Article 33 of the GDPR.

The sender remains responsible for data protection even after handing it over to the postal service provider. In the event of suspicion, he must carry out a risk assessment and decide whether to report the incident.

Conclusion & recommendations for action

Not every lost postal item is automatically subject to reporting. What matters is whether the loss creates a risk to the rights and freedoms of the persons concerned.

When sending personal data, companies should take preventive organizational measures to be able to act legally in the event of suspicion.

Practical tips:

  • Introduction of mandatory requirements for the transmission of personal data: Determine the conditions and the way in which documents containing personal data may be sent.
  • Selection of suitable shipping methodsTrackable shipping methods (e.g., registered mail, proof of delivery) should in particular be chosen if the personal data sent could constitute a risk to the rights and freedoms of the data subjects in the event of loss, thereby triggering a reporting obligation.
  • Early inspection in case of non-deliveryIn data protection law, the prolonged absence of a delivery, about five days after shipment, considered as a possible indication of a loss. Within this timeframe, it should be verified whether the shipment has arrived at the recipient. If no plausible explanation is provided, the incident should be evaluated as a possible data protection incident.
  • Training and awareness raising of employees: Employees who send documents containing personal data must know when there is an increased risk, which shipping method to choose, when a missed delivery may be reportable, and which internal steps to take in the event of suspicion.

Clear regulations, documented processes, and trained employees are crucial to reducing liability risks and acting in a timely and legally sound manner in the event of an emergency.

Check the mandatory fields –
Step-by-step in the webinar

FAQ

When can the loss of a postal item constitute a data protection incident?


When is there a reporting obligation to the data protection supervisory authority?


Who is responsible for reporting a loss by mail?

Why is the sender responsible despite handing over to the postal service provider?


What is the deadline for a possible notification under Article 33 of the GDPR?


How can companies structurally hedge against losses in the postal sector?