# Liability for Receiving Unsolicited Sensitive Data

**URL:** <https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695>\
**Category:** Factual Questions\
**Created:** [April 25, 2013, 8:03pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695 "2013-04-25T20:03:00Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![Johnny\_Bravo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_bravo/32/493_2.png) [@Johnny\_Bravo](https://boards.straightdope.com/u/Johnny_Bravo)\
**Post date:** [April 25, 2013, 8:03pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/1 "2013-04-25T20:03:00Z")

</div>

I got into the gmail beta nice and early, and so my email address is [johnnybravo@gmail.com](mailto:johnnybravo@gmail.com), except that instead of “Johnny Bravo” it’s my actual name. My name is not terribly unique, so I get lots of misdirected emails.

Nine times in 10, I scan and then delete them. Sometimes I’ll respond if the information seems particularly sensitive or important and let them know that they need to check their info, but I feel no particular obligation to do so.

So anyway, there’s lots of Johnny Bravos in America and I often receive their email. I read a lot of them because it’s interesting.

When I get a work-related email from someone in HR or otherwise Super Important, it appends a message including the following lines:

> [@](#):
>
> This communication including any attachments, may contain confidential information and is intended only for the individual or entity to whom it is addressed. Any review, dissemination, or copying of this communication by anyone other than the intended recipient is strictly prohibited. … . Because the information contained in this message may be privileged, confidential, proprietary or otherwise protected from disclosure, please notify us immediately by replying to this message and deleting it from your computer if you have received this communication in error.

So my question is this: if one day I get some super sensitive financial or personal information that was meant to go to the Johnny Bravo who works for Sensitive Information Database Consolidated, can I be held in any way responsible just for having it? Do disclaimers like the one above hold any weight?

---

<div class="post-metadata">

**Author:** ![Shodan](https://avatars.discourse-cdn.com/v4/letter/s/9f8e36/32.png) [@Shodan](https://boards.straightdope.com/u/Shodan)\
**Post date:** [April 25, 2013, 8:10pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/2 "2013-04-25T20:10:19Z")

</div>

AFAIK, once they send it to you, even in error, it is yours to do with as you please. If it is something like kiddie porn, you will want to remove it (and document your having done so in some way), but if Megabucks Inc. sends you their six month sales forecast, tough toenails for them.

This is assuming it is not otherwise protected, like being under copyright or something.

Regards,  
Shodan

---

<div class="post-metadata">

**Author:** ![Saintly\_Loser](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/saintly_loser/32/4045_2.png) [@Saintly\_Loser](https://boards.straightdope.com/u/Saintly_Loser)\
**Post date:** [April 25, 2013, 8:20pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/3 "2013-04-25T20:20:52Z")

</div>

That’s standard lawyer boilerplate. _Every_ outgoing email from my work email address has something like that on it.

I am not a lawyer. Nevertheless, I seriously doubt that there’s anything anyone can do to you for receiving an email sent to the wrong address.

Now, if that email contained information that could be defined as inside information (“this drug will kill everyone who takes it, but what the heck, let’s put it on the market anyway!”), and you traded on that information, that might be a different story.

But again, IANAL.

---

<div class="post-metadata">

**Author:** ![dstarfire](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dstarfire/32/5762_2.png) [@dstarfire](https://boards.straightdope.com/u/dstarfire)\
**Post date:** [April 25, 2013, 8:30pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/4 "2013-04-25T20:30:53Z")

</div>

The key part (or in this case, lack of a part) is the “strictly prohibited by” line. Unless they mention some law, or legally binding contract that applies to YOU, it’s little more than a forcefully worded version of ‘please don’t do this’.

---

<div class="post-metadata">

**Author:** ![redtail23](https://avatars.discourse-cdn.com/v4/letter/r/3e96dc/32.png) [@redtail23](https://boards.straightdope.com/u/redtail23)\
**Post date:** [April 25, 2013, 8:35pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/5 "2013-04-25T20:35:23Z")

</div>

We have to use the stupid things at work. I agree with everyone else - they’re pretty much bogus.

No one can do anything to you because someone else screwed up and sent email to the wrong address.

---

<div class="post-metadata">

**Author:** ![Mama\_Zappa](https://avatars.discourse-cdn.com/v4/letter/m/71e660/32.png) [@Mama\_Zappa](https://boards.straightdope.com/u/Mama_Zappa)\
**Post date:** [April 26, 2013, 1:26pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/6 "2013-04-26T13:26:29Z")

</div>

Heh - yeah, it’s not enforceable. The sender screwed up, not you. That said, of course it’d be a dick move for you to do anything with the information (unless it pertained to something illegal in which case, you should turn it over to the authorities.

I used to own a domain [something-or-other.org](http://something-or-other.org). As it happened, there was a [something-or-other.com](http://something-or-other.com) domain which was owned by a business. As I was listed as the admin contact, anything that went to an unknown address at the dot-org address got forwarded to my personal email. And a LOT of people tended to put the wrong high level domain, so I used to get misdirected email fairly often. I’d reply to them, saying “think you meant the dot-com address” and that was usually the end of that.

Except for one ditz, who kept sending to dot-org, and finally in frustration sent a really mad-sounding email saying “I don’t know why I keep getting this when I try to email you!!”.

To my dot-org address. Yeah, she was reading the email, but not noticing that she was sending it right back to the same bad address. Urgh.

I actually contacted the dot-com owner and let him know that I was getting this stuff and he might want to remind his contacts of the problem.

Another ongoing problem: my former office phone number was, say, 202-555-1212. Our phone system was set up so that faxes could be sent to the same as your voice number, and the system would intercept and email them to you. Every few months, I’d get faxes of private medical information. It turns out, there was some kind of hospital or something at 201-555-1212 and the number got messed up often enough that I got their information.

I phoned the senders when I could but mostly just deleted. Had the information been anything incriminating, would I have been liable under HIPAA if I had disclosed it?

---

<div class="post-metadata">

**Author:** ![Omar\_Little](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/omar_little/32/269_2.png) [@Omar\_Little](https://boards.straightdope.com/u/Omar_Little)\
**Post date:** [April 26, 2013, 2:41pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/7 "2013-04-26T14:41:01Z")

</div>

Those disclaimers aren’t there to come after you just because you “have” it. But if you decided to forward the super sensitive information to a journalist at the New York Times, and he published it. The original sender has established some level expectation of privacy of data, and could possibly go after the NYT.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [April 26, 2013, 2:52pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/8 "2013-04-26T14:52:03Z")

</div>

By reading this post, you are obligated to send me $100.

Obviously, that’s unenforceable. In order for it to be, the recipient has to positively agree to the terms; you cannot force anyone to abide by any terms without consent (Why do you think software has EULAs? To make sure the user has agreed to the terms). You didn’t agree to send me money, and a recipient of the email did not agree to the terms of the disclaimer.

**Mama Zappa** : HIPAA’s privacy rules apply to “covered entities”: health plans, hospitals, doctors, nursing homes, etc. I doubt you’re a covered entity. If you released the information, the person who sent it to you is the one in trouble.

---

<div class="post-metadata">

**Author:** ![Bill\_Door](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@Bill\_Door](https://boards.straightdope.com/u/Bill_Door)\
**Post date:** [April 26, 2013, 3:08pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/9 "2013-04-26T15:08:38Z")

</div>

A separate but related question: I have at times received scam “misdirected” emails that purport to contain information about future stock prices. I assume they are part of some “pump and dump” scheme whereby the sender intends to profit from me and others going “Woohoo! Inside information!” and running out to purchase said stock.

If I were to accidently get a real misdirected email, say from the head of corporate R&D at some Fortune 100 company to the CEO, would that trigger SEC insider trading rules?

---

<div class="post-metadata">

**Author:** ![Dewey\_Finn](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dewey_finn/32/4222_2.png) [@Dewey\_Finn](https://boards.straightdope.com/u/Dewey_Finn)\
**Post date:** [April 26, 2013, 3:22pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/10 "2013-04-26T15:22:19Z")

</div>

> [@RealityChuck](#):
>
> **Mama Zappa** : HIPAA’s privacy rules apply to “covered entities”: health plans, hospitals, doctors, nursing homes, etc. I doubt you’re a covered entity. If you released the information, the person who sent it to you is the one in trouble.

My understanding is that the fact that **Mama Zappa** received faxes of private medical information is a problem for the sender whether or not she releases the information.

---

<div class="post-metadata">

**Author:** ![ZenBeam](https://avatars.discourse-cdn.com/v4/letter/z/3ab097/32.png) [@ZenBeam](https://boards.straightdope.com/u/ZenBeam)\
**Post date:** [April 26, 2013, 3:31pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/11 "2013-04-26T15:31:01Z")

</div>

At work, I recently had ethics training. One of the bits was that if we received proprietary or competition sensitive information we shouldn’t have received, we were supposed to notify the sender. If we used the information, or if they found out we had it even if we didn’t use it, it could lead to us losing an awarded contract.

That may not apply to **Johnny Bravo** , but perhaps the notification has legal significance to some potential unintended recipients.

---

<div class="post-metadata">

**Author:** ![redtail23](https://avatars.discourse-cdn.com/v4/letter/r/3e96dc/32.png) [@redtail23](https://boards.straightdope.com/u/redtail23)\
**Post date:** [April 26, 2013, 3:31pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/12 "2013-04-26T15:31:01Z")

</div>

Correct. The originator of the faxes has violated HIPAA by sending any identifiable medical information to the wrong person.

**Mama Zappa** , not being (presumably) a medical person involved in that person’s care, would not fall under HIPAA rules.

**ZenBeam** , if I owned a company that had sensitive info and hired you, and you breached confidentiality of information you acquired by accident, I’d probably fire you. And I’d probably write that into contracts, which would make the breach of contract yours and not mine.

That’s still not the same as “legal consequences”, i.e., you’ve broken some law. And it still doesn’t make the disclaimers enforceable on whatever random person has received an email.

---

<div class="post-metadata">

**Author:** ![kayaker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kayaker/32/441_2.png) [@kayaker](https://boards.straightdope.com/u/kayaker)\
**Post date:** [April 26, 2013, 4:21pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/13 "2013-04-26T16:21:18Z")

</div>

> [@Dewey\_Finn](#):
>
> My understanding is that the fact that **Mama Zappa** received faxes of private medical information is a problem for the sender whether or not she releases the information.

For a while a local school district was mistakenly faxing stuff to my work fax. It was mostly medical stuff pertaining to students. Because it was using my toner, I called and said something several times, as well as faxing the stuff back. The faxes all contained the warning at the end.

When they still failed to stop faxing to my number, I called the home number of the student mentioned in a fax. I spoke to the Mom. I told her I knew her kid’s medical info and read stuff directly to her. She was livid. The school never sent me an errant fax again.

---

<div class="post-metadata">

**Author:** ![drewtwo99](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@drewtwo99](https://boards.straightdope.com/u/drewtwo99)\
**Post date:** [April 26, 2013, 4:27pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/14 "2013-04-26T16:27:29Z")

</div>

Unless it’s actually classified information by the government (which I doubt can exist in email form anyway), I would also say you are probably safe.

That being said, taking classified documents into account, not \*everything \*requires a positive agreement to be enforceable. Telling the judge, “Well I never AGREED to not look at restricted/classified US documents” isn’t going to get you very far, I don’t think, even if it’s true.

---

<div class="post-metadata">

**Author:** ![robert\_columbia](https://avatars.discourse-cdn.com/v4/letter/r/e79b87/32.png) [@robert\_columbia](https://boards.straightdope.com/u/robert_columbia)\
**Post date:** [April 26, 2013, 4:52pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/15 "2013-04-26T16:52:53Z")

</div>

> [@redtail23](#):
>
> Correct. The originator of the faxes has violated HIPAA by sending any identifiable medical information to the wrong person.
> 
> **Mama Zappa** , not being (presumably) a medical person involved in that person’s care, would not fall under HIPAA rules.
> 
> **ZenBeam** , if I owned a company that had sensitive info and hired you, and you breached confidentiality of information you acquired by accident, I’d probably fire you. And I’d probably write that into contracts, which would make the breach of contract yours and not mine.
> 
> That’s still not the same as “legal consequences”, i.e., you’ve broken some law. And it still doesn’t make the disclaimers enforceable on whatever random person has received an email.

> [@Shodan](#):
>
> …
> 
> This is assuming it is not otherwise protected, like being under copyright or something…

Good points. For there to be legal consequences for disclosing “sensitive” or “confidential” data, there would have to be a legal cause of action (civil or criminal), administrative procedure, etc., to handle people accused of mishandling the information. Afaik there isn’t a generic “misuse of confidential information” offense or tort. If you disclosed government classified information, you might be charged with offenses related to disclosure of classified information. If you signed an employment contract not to disclose details on MegaBigCorp’s project plan to cut costs in the Denver-Salt Lake City shipping route but you sold it to Conglom-O in violation of that contract, you might be subject to suit under breach of contract. Someone who wasn’t a party to the contract might get off, but if MegaBigCorp was publicly traded and they traded on that info, they might be guilty of Insider Trading. If you were subject to HIPAA and violated its confidentiality provisions, you might be proceeded against using that. But if you weren’t subject to HIPAA’s provisions, there would be no cause of action under it against you.

---

<div class="post-metadata">

**Author:** ![robert\_columbia](https://avatars.discourse-cdn.com/v4/letter/r/e79b87/32.png) [@robert\_columbia](https://boards.straightdope.com/u/robert_columbia)\
**Post date:** [April 26, 2013, 4:58pm UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/16 "2013-04-26T16:58:26Z")

</div>

> [@drewtwo99](#):
>
> Unless it’s actually classified information by the government (which I doubt can exist in email form anyway), I would also say you are probably safe…

Classified information doesn’t stop being classified just because someone transferred it to a different medium. Otherwise, classified documents could be legally breached by turning them into paintings, microfilm, audiotapes, mp3’s, etc. Letting people off just because they breached the info as a sound file is absurd.

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [April 27, 2013, 4:02am UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/17 "2013-04-27T04:02:10Z")

</div>

> [@robert\_columbia](#):
>
> Classified information doesn’t stop being classified just because someone transferred it to a different medium. Otherwise, classified documents could be legally breached by turning them into paintings, microfilm, audiotapes, mp3’s, etc. Letting people off just because they breached the info as a sound file is absurd.

And this leads to the [Illegal Number](http://en.wikipedia.org/wiki/Illegal_number) issue.

Every integer in the real numbers system is just an integer, right? But apparently some plain old integers are illegal for you to possess.

All information, of all sorts, can be coded as a number (e.g., for usage in computers or other electronic media). You could, perhaps, steal a classified document, convert the data to a number, and then concoct an image file or music or video or something that has that in it. It’s all just a big sequence of 0’s and 1’s, right? And you might even send this around by e-mail. But the simple fact that you have some integer that represents a classified document means it’s illegal for you to possess that number, regardless of what media it may be on.

ETA: Also, [Illegal Prime](http://en.wikipedia.org/wiki/Illegal_prime)

---

<div class="post-metadata">

**Author:** ![Acsenray](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/acsenray/32/4519_2.png) [@Acsenray](https://boards.straightdope.com/u/Acsenray)\
**Post date:** [April 27, 2013, 4:13am UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/18 "2013-04-27T04:13:45Z")

</div>

That’s a spurious line of reasoning. The illegality of possessing the data has nothing has nothing to do with its numerical representation. It has to do with its origin and the intent and knowledge of each person passing it on. It’s never the \* number\* that’s “illegal.” Otherwise you could reduce any offense involving communication or information to this meaningless level of abstraction.

---

<div class="post-metadata">

**Author:** ![drewtwo99](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@drewtwo99](https://boards.straightdope.com/u/drewtwo99)\
**Post date:** [April 27, 2013, 6:34am UTC](https://boards.straightdope.com/t/liability-for-receiving-unsolicited-sensitive-data/656695/19 "2013-04-27T06:34:18Z")

</div>

I don’t know how classified/restricted documents work, which is why I said “doubt” when talking about classified emails.

Seems like this might make a good question for Cecil honestly. “Can I be held legally responsible if I receive a sensitive email in error? Are there such things as classified/restricted by the government emails that would carry fines or prison sentences for unauthorized recipients?”
