Email Received from Ex-Board Member

Email Received from Ex-Board Member

We are aware that yesterday around 13.15 some of our longer term members and subscribers received an email from a previous board member’s personal email account. The email was sent to those who were members/subscribers approximately 2 – 2.5 years ago.

First and foremost we would like to assure our members and subscribers that their email details and preferences are stored securely on Mailchimp and NO ex-board members have the log in for that service. We change the password on a regular basis and only current board members are privy to the up to date log in details.

In relation to the membership database, this is stored on a secure password protected drive accessible only to the secretary and membership secretary. All other documents received of a personal nature are stored on a secure password protected portable drive, which remains in the possession of the Society Secretary. When there is a change in secretary the portable drive will be handed over to the new secretary along with the password. No personal details are held on any board members personal computer.

We carried out an urgent investigation as to what happened yesterday, speaking with both the ex-board member involved and the ICO as well as running a systems check on our servers to check for any breaches. No breaches were found on our servers.

The ex-board member informs us that he had found a draft email in his email draft folder that he had completely forgotten was there and in the course of attempting to delete it accidentally sent it out. The draft email had a list of recipients stored on it and was automatically sent to each recipient individually as opposed to all recipients en masse. He contacted the secretary to report this as soon as he realised what had happened.

He has since been through his draft email folder to ensure there are no further drafts sat in there. He has assured us that he has deleted his sent list both from the sent folder and the trash folder. He further assures us that he has gone through all of his contacts and deleted any that are not personal friends of his. We have in writing from him that he has taken these steps to ensure no further incident of this nature occurs. He has asked us to pass on his apologies to all members/subscribers who were affected.

We have spoken with the ICO who advise there is no reportable breach of GDPR by the Cherries Trust.

Whilst this is a regrettable incident, we as a Trust are satisfied, with support from the ICO, that the security measures put in place when the new board took over in November 2022 are working as they should be. We will continue to monitor them on a regular basis and update them as needed.

We apologise to our members and subscribers that this incident occurred and wish to reassure you that we are working hard to ensure it does not happen again.

Kind regards,
Gayle Hope
Society Secretary

Post a Comment