
When organisations discuss data breaches, human error is often treated as the softer category.
It sounds less dramatic than ransomware. Less technical than exploitation. More forgivable than a public-facing server left exposed.
But from a DPO's perspective, that framing can be dangerous. Wrong-recipient emails, unsecured attachments, manual exports, unreviewed templates and rushed sending processes can still lead to unauthorised disclosure, complaints, investigations and long-lasting trust damage.
That is why the recent PDPC undertakings matter. In April 2026, PDPC highlighted an erroneous email disclosure in a new batch of undertakings. One of the published undertakings, involving Stepup (Sup) Pte Ltd, noted that the incident affected the personal data of about 607 individuals, including combinations of names, email addresses and educational information. The broader point is familiar: small workflow mistakes can create very real exposure.
For DPOs in Singapore, the real risk is not only the mistaken send. It is the fact that many organisations still rely on manual workarounds and goodwill to protect personal data in daily operations.
Why manual workflows keep causing problems
Manual processes often grow in the gaps between systems.
A team exports a file because two systems do not integrate cleanly. A follow-up email is sent because the workflow is partly automated and partly manual. An attachment is reused because it is faster than rebuilding the report. A recipient list is copied from an old chain. Sensitive records are sent over email because "that is how we have always done it."
These shortcuts usually survive because they save time in the moment. Over time, they become normal operating practice, even when they involve personal data.
For a DPO, this is exactly the kind of risk that deserves scrutiny. The more often a process depends on people remembering the right recipient, the right file, the right encryption step or the right review sequence, the more likely it is to fail under pressure.
What DPOs should look for first
Start with the workflows that combine personal data, repetition and manual handling.
Bulk communications. Payroll and HR exchanges. Student or patient reporting. Customer service escalations. Vendor transmissions. Mail merges. Reports prepared outside the main system. Temporary spreadsheets created for "one-off" tasks that become recurring.
These processes may never show up in the system architecture diagram, but they often carry real disclosure risk.
Controls that actually help
The most effective fix is not another reminder email telling staff to "be careful."
What works better is reducing the number of judgement calls a person must get right.
Use pre-approved templates and controlled send flows. Restrict who can export full datasets. Separate test and live recipient lists. Apply approval steps for high-risk transmissions. Default to secure links or controlled portals instead of raw attachments where possible. Use file naming conventions and clear version control. Mask or minimise data fields when full detail is not necessary.
Training still matters, but training should support better process design, not compensate for weak process design.
Why this matters for DPOs
Human error cases are often dismissed because they feel smaller than cyber attacks. But they create a different kind of problem: they reveal whether the organisation has built privacy into ordinary operations.
A mature DPO function is not only concerned with major incidents. It also reduces repeatable, everyday exposure in the workflows staff touch constantly.
That means asking whether the process is safe by design, whether it depends too much on memory, whether controls are layered, and whether the organisation has learned from near misses.
The DPO's practical checklist for email and disclosure risk
- Identify high-frequency workflows that involve exporting, attaching, emailing or manually transmitting personal data.
- Reduce attachment-based processes where secure portals, limited-access links or workflow tools are more appropriate.
- Set approval rules for bulk sends and high-risk data categories.
- Review recipient validation, auto-complete controls, and the use of shared mailboxes.
- Update training to include realistic sending mistakes, escalation steps and near-miss reporting.
The urgency for Singapore organisations
Recent enforcement activity is a reminder that accidental disclosure is still very much on the regulator's radar. DPOs should not assume that because a breach was accidental, it will be treated lightly. What matters is whether the organisation had reasonable measures to prevent it and to reduce the chance of recurrence.
In practice, that means the DPO should be close to the operational reality of the business. Not just the policy binder. Not just the annual training deck. The real workflows.
Because that is where many avoidable breaches still begin.
Key takeaways
- Human error remains a recurring data protection risk, especially in email and export-heavy workflows.
- The most effective controls reduce manual judgement, not just remind staff to be careful.
- High-frequency operational tasks deserve the same privacy attention as major systems.
- Wrong-recipient and attachment incidents are often symptoms of weak process design.
- DPOs should review real workflows, not only formal policies.
