Fax & Data Protection: What are the data protection implications when transmitting information via fax?

- Sending personal data by fax is insecure under data protection law.
- Fax machines transmit data unencrypted and are easily accessible to unauthorized parties.
- Faxing over unencrypted internet lines poses data protection risks.
- GDPR-compliant alternatives: end-to-end encrypted emails and postal mail.
- Transmitting sensitive data via fax can lead to formal warnings and fines.
The fax machine is a piece of office history. While generally a reliable device, it still leaves much to be desired when it comes to data protection. The Bremen State Commissioner for Data Protection and Freedom of Information (LfDI)*, Imke Sommer,has published a statement on the topic of fax machines and data protection. Read on to learn exactly what the problems are and what alternatives companies have to ensure secure, GDPR-compliant communication in the future.
Is sending personal data via fax GDPR-compliant?
Personal data such as names, email addresses, personal addresses, and similar information are subject to special protection under the GDPR. Therefore, it is essential to choose a secure transmission method when sending or sharing such data. This can be done, for example, using encrypted letters or emails. The fax machine, however, belongs to a different technological generation, one where secure and privacy-compliant transmission was not a priority. Since the introduction of the GDPR, these factors have become increasingly important. Because fax machines remain standard equipment in many offices, finding a suitable solution is often difficult. When personal data is faxed, it is not secure because faxing lacks the level of data security required to guarantee privacy. In practical terms, a fax is transmitted in a way that allows anyone with access to the receiving device to view it. This severely compromises data confidentiality, as the fax transmits information openly and unencrypted. The inability to control access is also a major issue; it is nearly impossible to track who has already viewed the documents received via fax.
Furthermore, faxing often relies on unencrypted internet lines. Years ago, end-to-end encrypted telephone lines were the standard. Additionally, there is the risk of dialing the wrong number or having the fax received by the wrong destination. There is no question that this represents a clear data protection loophole.
Another problem is that there are no specific regulations for fax traffic. Neither the GDPR nor other sets of rules address this issue. These problems persist even when incoming faxes are automatically digitized and stored in a mailbox (so-called digital fax services or cloud fax services).
Data protection not guaranteed with faxes: Letters and emails as alternatives
In summary, it is not advisable from a data protection perspective to transmit confidential data via fax. But what are the alternatives? Unfortunately, fax transmission remains a common communication method. According to a survey by the digital association Bitkom, one in five doctors still relies on the fax machine to communicate with colleagues. Aside from the fact that digitalization has yet to reach many medical practices, this highlights another problem: according to Sommer*, transmitting personal data that requires special protection under the GDPR (such as health data) via fax is considered inadmissible. If (particularly sensitive) personal data is transmitted via fax, it can lead to warnings and fines (see, for example, case 11 LA 104/19 of the Higher Administrative Court of Lüneburg, which ruled at the end of 2020 that unencrypted faxes are not sufficiently secure and therefore disclose information openly). To avoid potential fines, there are several things you need to keep in mind.
Fax and data protection: What you should keep in mind
- Do not transmit confidential and/or personal data via fax.
- If you intend to send a fax, you must first determine the protection requirements of the data in accordance with Article 32(1) of the GDPR. A fax must meet the security requirements for processing outlined therein. You must also conduct a risk assessment of the processing and implement appropriate security measures where necessary.
- End-to-end encrypted emails
- If you need to send something quickly, you can use end-to-end encrypted emails. Of course, for less urgent matters, you still have the option of sending important and sensitive information by post. While this takes a little longer, according to *Sommer, this method of transmission ensures you are on the safe side.
The aforementioned statement further notes that "the Bremen administration assumes that all fax machines will be replaced by more secure technologies by the end of 2022." We are confident: You can do it faster!
---
* Note: In principle, the respective authority of a (federal) state is always responsible; this is therefore not a decision that applies to the entire EU or Germany.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.












