Accidentally sent an email to the wrong person? Here’s what to do (2026)

3 March 2026

Accidentally sent an email to the wrong person? It happens far more often than most organisations realise. Email remains one of the most common causes of personal data breaches in the UK, and the numbers continue to confirm this.

Recent data from the Information Commissioner’s Office (ICO) shows that misdirected emails were the most common type of data security incident in Q4 2024, accounting for 21% of all reported incidents. Similarly, ICO statistics for Q1 2024 highlight that 18% of all reported incidents involved emails sent to the wrong recipient.

With inboxes busier than ever and email auto‑complete features making mistakes easy, it’s important to know exactly what to do the moment you realise an email has gone astray.

1. Stay calm and act quickly

Your instinct might be to panic, especially if the message contains sensitive or confidential information, but staying calm will help you respond effectively. The quicker you act, the better your chances of containing the incident and limiting risk.

2. Contact the unintended recipient immediately

Get in touch with the person who received the email as soon as possible. Politely ask them to:

  • Delete the email without reading it
  • Delete any attachments
  • Confirm they have done so

Many breaches caused by human error in local authorities or schools, for example, involve simple misdirected emails. Rapid action and cooperation often prevent further impact.

3. Try recalling the email (if applicable)

In some environments, recalling a message may work, but only under specific conditions.

Microsoft Outlook recall can work if:

  • You and the recipient are within the same organisation
  • Both accounts use the same Exchange or Microsoft 365 environment
  • The email remains unread

If any of these conditions aren’t met, recall will not succeed. Even if you attempt recall, always follow up directly to confirm the outcome rather than assuming it worked.

4. Assess what information was disclosed

Understanding the level of risk helps determine the next steps. Ask yourself:

  • Did the email contain personal data?
  • Was any of it sensitive or special category data (e.g., health, financial, safeguarding)?
  • Does the recipient pose a risk of onward sharing?

An accurate assessment will help your data protection team decide whether the incident needs to be escalated or reported externally.

5. Report the incident internally — within 24 hours

Once initial containment steps are underway, report the incident to:

  • Your line manager
  • Your organisation’s Data Protection Officer (DPO) or information governance team

Reporting is essential even if you believe the recipient deleted the message, no personal data was involved, or the incident appears to be a “near miss”.

Organisations track all incidents so they can identify patterns, mitigate future risks, and comply with legal obligations. ICO guidance requires organisations to report notifiable data breaches within 72 hours, which means internal teams must be informed promptly.

6. Follow advice from your DPO or IG team

Your data protection lead may need to:

  • Contact the unintended recipient
  • Notify affected individuals
  • Conduct a risk assessment
  • Determine whether to report the incident to the ICO
  • Document the breach and identify lessons learned

Their priority is to minimise harm and prevent recurrence.

7. Avoid future errors with preventative measures

Misdirected emails remain a top risk in UK organisations due to reliance on auto‑complete and fast‑paced working environments. A few practical safeguards include:

Check before you send
  • Pause before clicking Send
  • Double‑check all recipients, especially when using CC or Reply All
Adjust email settings
  • Turn off or limit auto‑complete
  • Introduce a short send delay (e.g., 10 seconds) to catch mistakes
Use technical controls where available
  • Email DLP (Data Loss Prevention) tools
  • Recipient confirmation prompts
  • Encryption and access revocation tools
Ongoing staff training

Human error remains one of the most persistent causes of data breaches, especially misdirected emails, which means effective, ongoing staff training is one of the most powerful controls an organisation can invest in. Training should go beyond a one‑off induction session. It needs to be continuous, practical, and tailored to real‑world scenarios.

Key takeaway

Sending an email to the wrong person is one of the most common, and preventable, data breaches in the UK. Acting quickly, reporting promptly, and adopting simple preventative measures can significantly reduce the risk and impact of such incidents.

If your organisation needs support reviewing email‑related risks or improving incident response processes, an information governance specialist can help.