← All posts
How-to Guides

How to stop confidential information leaving in an email

September 14, 2026 · 7 min read

Search for how to stop confidential information leaving in an email and almost everything you find is about what to do afterwards. How to bring a claim. What damages are available. How to word the agreement so the claim is stronger.

That literature exists because breaches happen, and it is useful once one has. The prevention side is thinner, and the advice it does give tends to be encryption, access control, and training. Those three protect against three things that are rarely what went wrong.

Confidential information usually leaves through an authorised person, in an authorised message, sent from an authorised device. Encryption protects that message perfectly, all the way to the wrong recipient.

The four moments it actually happens

Working backwards from breach cases, four routes account for most of it. None of them involves anyone doing anything they knew was wrong.

1. Reply-all. A thread has grown to include an external adviser, a counterparty, or a former colleague whose address is still in the chain. Someone replies with the internal answer. The failure is that the recipient list was inherited rather than chosen.

2. The history under a forward. A message is forwarded for a legitimate reason: to bring someone up to speed, to ask a question, to escalate. Underneath the top message sits the thread history, and in it are the terms, the numbers, or the board discussion. Nobody wrote anything confidential in the message that was sent.

3. The attachment to the adjacent domain. Autocomplete offers a similar name at a different organisation. The document is correct, the recipient is not, and the send looks entirely normal.

4. The quote pasted into a new thread. Somebody copies a paragraph to give context in a fresh message. The paragraph carries pricing, a client name, or a term that was confidential in its original setting and is now in a conversation with someone who has no relationship to it.

Why the standard controls miss all four

Control What it does Why the four routes pass through
Encryption Protects the message from third parties in transit The recipient is the problem, and encryption delivers to them faithfully
Access control Decides who can open the source document The sender legitimately has access, which is why they can send it
Pattern-based DLP Detects structured data and labelled files A pasted paragraph of commercial terms carries no pattern and no label
Annual training Establishes the rule The rule is known. The recipient list is what was not checked

Each of these is worth having. Together they still leave the four routes open, because all four turn on a question none of them asks: is this particular recipient entitled to this particular content.

The fact that decides it lives outside the mailbox

Here is the structural problem. Whether a sentence is a breach depends on the relationship between your organisation and the recipient, and that relationship is recorded in a contract, not in an email system.

A counterparty under a mutual NDA can receive the deal terms. A contact at the same company who is outside the agreement’s scope cannot. A supplier whose agreement covers technical specifications but not pricing can receive one and not the other. Identical sentences, different outcomes, and the deciding fact sits in a contracts folder.

This is why content scanning alone reaches a ceiling. A scanner reading only the message can tell you the paragraph looks commercially sensitive. It cannot tell you whether this recipient is allowed to have it, because that information was never in the message.

What a working control needs

Five properties, in the order they matter.

  1. It evaluates content and recipient together. Either alone produces noise. Content alone flags every commercial email. Recipient alone flags every external send.
  2. It knows who signed what. The agreement register has to be in the system, kept current, and specific enough to distinguish categories where your agreements do.
  3. It reads the whole message. Including the thread history and the attachment, since two of the four routes hide there.
  4. It acts before sending. After the send, the remedy is disclosure and negotiation.
  5. It leaves a record. Both for the audit question and because a control with no record cannot be improved.

Property three is the one most often skipped, and it is where two of the four routes live. A check that reads only the newly typed text will miss the forwarded history and the attachment every time.

What happens after it goes

Understanding the downstream cost explains why the position of the control matters so much.

Once confidential information reaches someone outside the agreement, the options narrow immediately. You can ask them to delete it, which relies on their goodwill and produces no enforceable certainty. You can notify the counterparty whose information it was, which is often contractually required and always damaging to the relationship. If personal data is involved, a regulatory notification clock may start, and in the EU that clock is measured in hours rather than weeks.

None of those options restores the position. Confidentiality is one of the few obligations where the remedy cannot undo the breach, because the thing protected was the fact that the recipient did not know.

That asymmetry is the argument for spending on prevention here rather than on response. For most risks the two compete on roughly equal terms. For this one, response is damage limitation from the first minute.

Getting the agreement register in place

The practical objection to all of this is usually that nobody knows who signed what. That objection is fair, and the work is smaller than it sounds.

Start with the counterparties your teams actually email. In most organisations that is a much shorter list than the full contract inventory, and it is heavily concentrated: a few dozen relationships account for most of the confidential traffic. Record the organisation, the agreement, the date, and the categories it protects.

Keep it in one place that the check can read, and give one person the job of updating it when an agreement is signed or expires. An expired NDA that still shows as current is the failure mode to design against, because it produces false confidence rather than a missing check.

Where a pre-send check fits

All five properties above describe a control positioned at the moment of writing, with access to the agreement register. That combination is what our NDA Guard is built to do: it holds the signed agreements, reads the draft including the thread beneath it, and flags the combination of confidential content and an uncovered recipient while the message is still open.

It works alongside archiving and DLP rather than instead of them. Keep the pattern rules for structured data, keep the archive for the record, and put the recipient question where the decision is made.

The takeaway

Prevention for this risk is a recipient problem before it is a content problem. Take the four routes above to your next team meeting and ask which of them your current controls would catch. If the answer for the forwarded thread is no, that is where to start, because it is the route where nobody writes anything wrong. For the legal shape of what counts, see our guide to what actually counts as an NDA breach by email.

See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.

See VerbaPulse in action →
← The information was in the file all along Client confidentiality in private banking: the four moments it breaks →