Sent to the Wrong Person: Everyday Data Mistakes and How to Prevent Them
Not every data breach involves a hacker. Many start with an email sent to the wrong person, a shared link left open or a spreadsheet with a hidden tab. Here are the most common mistakes and simple habits that prevent them.

When people imagine a data breach, they picture a hacker. In reality, a large share of incidents start with an ordinary person doing an ordinary task a little too quickly. The email went to the wrong Kwame. The spreadsheet had a hidden tab. The shared folder was open to anyone with the link.
These mistakes are easy to make and, with a few habits, easy to prevent.
The most common everyday mistakes
1. Autocomplete sends it to the wrong person
You type the first few letters, the email client suggests a name, and you press send. It is one of the most frequent causes of personal data going where it should not.
2. Everyone can see everyone
An email to a group of customers or candidates with every address in the To or CC field exposes all of them to each other. Use BCC or a proper mailing tool.
3. The hidden data in the attachment
A spreadsheet with hidden columns or tabs, a document with tracked changes and comments, or a file that still contains data from a previous version.
4. Links that are open to anyone
Cloud sharing links set to "anyone with the link" can be forwarded, indexed or found long after the project is over.
5. Paper and screens
Printouts left on the printer, files taken home, documents thrown in the bin rather than shredded, and screens visible to visitors or passers-by.
6. Personal accounts and devices
Forwarding work files to a personal email "to finish at home", or saving them on an unencrypted USB stick.
Why it matters: in Ghana, the Data Protection Act, 2012 (Act 843) places duties on organizations that process personal data, and similar laws apply across Africa and beyond. Beyond the law, customers remember who lost their data.
Simple habits that prevent most of it
- Pause before sending anything containing personal data and check every recipient.
- Turn on a send delay of a few seconds in your email client, so you can recall a mistake.
- Use BCC for group emails to people outside the organization.
- Share links to specific people, not "anyone with the link", and remove access when it is no longer needed.
- Check attachments for hidden tabs, columns and comments before sending.
- Send only what is needed. The safest data is the data you do not send.
- Lock screens and clear desks, and shred paper that contains personal information.
- Keep work data on work systems.
When a mistake happens
Report it straight away to whoever handles data protection in your organization, even if it seems small. Try to recall the email, ask the recipient to delete it, and write down what was sent to whom and when. Organizations may have legal duties to assess and report certain breaches, and they can only do that if they know.
No blame, fast reporting. A culture where people report their own mistakes within minutes protects customers far better than one where mistakes are hidden.
Making good habits normal
Data protection is mostly about everyday care, and care comes from awareness. CyberWatch AI includes short training lessons on handling data safely alongside phishing and account security, so good habits become part of how the whole team works.


