Troubleshooting
I sent it to the wrong person
Cut the access first, then tell people. In that order, and without waiting to find out whether they opened it.
**First cut off access to the link, then tell people, and only at the end weigh up the scope.** That order matters: every minute the link stays live is a minute in which the wrong person can open it.
The first ten minutes
- 1
Cancel the send or the link
Before writing to anyone. It is the only thing that shrinks the problem while it is happening.
- 2
Tell whoever received it by mistake
One sentence asking them to ignore and delete it. Most people cooperate.
- 3
Send it to the right recipient
So the work continues and does not get forgotten in the scare.
- 4
And write down what happened, with times
Ten lines today beat next month's reconstruction.
Important
**Do not wait to find out whether they opened it before acting.** It is the natural temptation —«maybe they haven't seen it and we needn't make a fuss»— and it is exactly backwards: if they have not seen it, cutting and telling costs nothing; if they have, every minute counts. Doubt is not a reason to wait, it is a reason to cut now.
How much it matters depends on what was inside
| What was sent | What else to do |
|---|---|
| A document with nothing sensitive | Cut, tell them, move on |
| Personal data | Also tell whoever handles data protection |
| Another client's documents | Also tell that client. They find out anyway, and worse |
| Terms, prices or anything confidential | Also flag it internally before it comes back from outside |
Watch out
The underlying cause is rarely carelessness: **it is two similar contacts in the address book**. Two people with the same name at different companies, the same company entered twice, or a generic office address sitting next to the individual's. Once the fire is out, half an hour cleaning up those duplicates is worth more than any resolution to be more careful.
›Do I tell them even if they never reply?
Yes. The notice puts you in a different position even with no answer.
›Do I have to report it internally?
If it held personal data or a third party's, yes, and quickly.
›Can I find out whether they opened it?
Not with certainty, and it does not change what to do now.
A real case
The situation
A file is sent to another client's contact with a similar name.
What you do
- Cancels the link first, tells them after, and resends to the right person
What you get
The window in which someone could open it shrinks to minutes.
The situation
After the scare, the address book still holds the two near-identical contacts.
What you do
- Spends half an hour merging duplicates and disambiguating the names
What you get
The cause disappears, not just the episode.
The situation
A file is sent to the wrong contact.
What you do
- Revokes access before writing to anyone
What you get
Exposure is cut even if the other side never looked.
The situation
The wrong recipient belongs to another company.
What you do
- Cuts access and alerts the right people internally
What you get
Whoever should decide what to communicate does.
The situation
It is discovered hours later.
What you do
- Cuts access anyway and records what was sent and to whom
What you get
The scope is documented for whatever follows.
The situation
The recipient is simply asked to delete it.
What you do
- Revokes access as well as asking
What you get
You do not depend on a third party complying.
This article answers
- i sent a document to the wrong person
- sent data to another client
- how do i retract a misdirected send
- sent to wrong recipient what do i do