· بقلم L'équipe EnvoiFaxGratuit
Fax Sent to the Wrong Number: What to Do Within 72 Hours
A fax sent to the wrong recipient is a data breach. Hour-by-hour procedure, CNIL notification, internal register, evidence to preserve, and measures to prevent it happening again.
هذا المقال غير متوفر بلغتك بعد؛ إليك النسخة الإنجليزية.

Short answer: a fax that reaches the wrong recipient is not a minor slip-up — in legal terms it is a personal data breach within the meaning of Article 4(12) of the GDPR, as soon as the document contains identifying information. The procedure comes down to five steps: freeze the evidence (transmission report, number dialled, timestamp) before it disappears, contact the unintended recipient to have the document destroyed, record the incident in the breach register — mandatory even when nothing is reported —, assess the risk to the individuals concerned, and notify the CNIL within 72 hours if that risk cannot be ruled out. The countdown starts the moment you became aware of the mistake, not the moment the fax was sent. And an internal memo saying "please double-check numbers" does not count as a corrective measure.
Why fax remains the leading cause of wrong-recipient errors
Email has safety nets: an address book, autocomplete, a bounce message when the address does not exist, sometimes a few seconds to recall the message. Fax has none of this. You dial ten digits by hand, often from a handwritten note or a half-faded stamp, and the machine asks no questions. If the number exists, it transmits. If it does not, it retries a few times and gives up — but if a mistyped digit happens to match another working fax machine, the pages come out at a stranger's premises with no signal coming back to you.
European data protection authorities have been documenting this scenario for years. The UK's ICO, in its incident reviews, regularly ranked "fax sent to the wrong number" among the most frequent breaches in the healthcare sector, alongside letters placed in the wrong envelopes. The CNIL, in its publications on reported data breaches, files these cases under "data sent to the wrong recipient", which remains one of the leading causes of notifications — ahead, in sheer volume, of many sophisticated cyberattacks.
Three factors make the risk worse with fax:
- Neighbouring numbers. Within the same organisation, the front-desk fax and the accounts department fax often differ by a single digit. Transposing two digits still yields a plausible — and therefore deliverable — number.
- Recycled numbers. A practice closes, its number goes back into the operator's pool and is reassigned to an unrelated business, sometimes to a voice line that forwards to a software fax.
- Machine memory. Speed-dial keys programmed ten years ago by someone who left long ago are rarely audited.

The first thirty minutes: freeze the evidence
The first reaction is almost always the wrong one: people immediately resend to the correct number, clear the log to "start clean", and move on. Yet the very items needed to classify the incident, document it and protect you are precisely the ones the machine is about to overwrite.
Collect, in this order:
- The transmission report for the faulty send. It contains the number actually dialled, the date, the time, the number of pages and the status. It is the central piece of the file.
- The communications log from the fax machine or online service, over a wide time window — it shows the context, in particular whether the error was repeated.
- A copy of the document sent, with an exact list of the fields it contained: name, date of birth, social security number, diagnosis, bank details, and so on.
- The identity of the person who sent it and the time the error was discovered. It is this second date that starts the 72-hour clock.
On a physical device, the log purges itself automatically after a limited number of entries: print it immediately, or export it. Many services keep a longer online history, but do not rely on that without checking. In practices handling sensitive files, keeping a small portable document scanner next to the workstation means the paper report can be digitised straight away and filed with the incident record, rather than left in an in-tray where it will end up in the recycling.
Do not alter anything, do not reprint the document over it, do not annotate the original report. If a dispute arises later, the consistency of the timestamps will be scrutinised — we covered this in our analysis of the evidential value of a fax before a judge.
Classifying: is it really a data breach?
Not every wrong-number incident triggers the same obligation. The reasoning has three stages.
Does the document contain personal data? A purchase order for office supplies with no individual's name does not. A sick note, a test report, bank account details, a named appointment letter, an employment contract: yes, without question.
Was confidentiality lost? As soon as the pages came out at an unauthorised third party, the answer is yes, even if that third party is acting in good faith and says everything has been destroyed. A completed breach cannot be "undone" retroactively; that said, prompt, documented destruction reduces the risk, which affects what follows.
What is the risk to the individuals concerned? This is the criterion that determines whether to notify. The CNIL and the European Data Protection Board (EDPB) guidelines on breach notification call for an assessment of the nature of the data, its volume, how easily individuals can be identified, the severity of the possible consequences, and whether special-category data is involved.
| Situation | CNIL notification | Informing individuals |
|---|---|---|
| Supplier invoice, no individual's name | No (no personal data) | No |
| List of 3 appointments with names and times, known recipient, destruction confirmed | Register entry only, notification unlikely | Not as a rule |
| Named medical report sent to an unknown recipient | Yes | Yes, generally |
| File of 200 employees with IBANs | Yes | Yes |
The key point: entering the incident in the internal breach register is mandatory in every case, including when you conclude there is no risk. Article 33(5) of the GDPR. That register is the first thing the CNIL asks for during an inspection, and a company whose register is empty while its staff fax documents daily rarely comes across as credible.
Getting back in touch with the unintended recipient
Calling the number dialled by mistake is often possible: many fax lines sit behind a switchboard, or the number appears in a business directory. The aim is not to apologise, it is to obtain three things: confirmation of receipt, destruction of the document and, if possible, written confirmation of that destruction, even in the form of a two-line email.
Keep the request simple, without detailing the document's contents — there is no point drawing attention to something the person may not have read:
Hello, a document was sent to your fax number in error on [date] at [time]. It was not intended for you and contains confidential information. Could you please destroy it and confirm in writing? Thank you.
Keep this exchange in the incident file. A recipient who is identified, professional, themselves bound by professional secrecy and who has confirmed destruction is a mitigating factor you can put to the CNIL. Conversely, a number that does not answer and is not linked to any known entity means the document is out in the wild: the risk must be assessed upwards.
Notifying the CNIL: deadline, content, partial notification
The 72-hour deadline runs from the moment the controller becomes aware of the breach. A discovery on Friday at 4 p.m. means notification by Monday at 4 p.m. at the latest: weekends count.
Notification is submitted online, through the CNIL's breach notification service. It must describe the nature of the breach, the categories and approximate number of individuals and records concerned, the contact details of the data protection officer or a point of contact, the likely consequences, and the measures taken or planned.
Two useful reflexes:
- Notification can be made in phases. If the internal investigation is not complete, notify with the information available and follow up afterwards. An incomplete notification within the deadline beats a perfect one submitted late.
- Beyond 72 hours, notify anyway, explaining the delay. Article 33(1) expressly provides for this.
As for informing the individuals concerned (Article 34), this is required where the risk is high: health data, banking data, information likely to expose someone to discrimination, identity theft or reputational harm. It must be written in clear, plain language, stating the nature of the breach, its likely consequences and the measures taken. For healthcare professionals, these obligations stack with the specific framework governing the hosting and processing of health data, which we set out in our article on medical faxing and the law.

Preventing a repeat: what actually works
The CNIL does not penalise isolated human error; it penalises the absence of reasonable measures. After an incident, the authority expects structural measures, not an internal memo. Here are the ones that hold up.
A validated recipient directory. Ban manual dialling for regular contacts and allow only verified entries, reviewed once a year. Typing errors become impossible on 90% of sends.
Double-checking for sensitive documents. Two pairs of eyes on the number before any send containing health or banking data, with a record of the sign-off. A simple inked control stamp applied to the cover sheet and initialled is enough to make the step tangible — provided it is genuinely carried out.
A cover sheet with a confidentiality clause. It prevents nothing technically, but it informs the accidental recipient of their obligations and makes the destruction request easier. It must never contain sensitive information: no diagnosis, no detailed reason, no overly revealing file reference.
Moving to online fax. A cloud-based service brings three things a desktop machine cannot offer: a complete timestamped history, delivery confirmation still viewable months later, and above all the disappearance of the printed document sitting in an output tray. We set out the full process in our six-step migration plan; the /faq page answers practical questions about sending and delivery receipts.
Handling residual paper. As long as a physical machine remains, drafts, duplicates and reports must end up in a cross-cut shredder, not a waste-paper basket. And for files moving between offices, opaque document wallets prevent accidental reading in corridors. These are small details, but most documented breaches come down to exactly that.
Short, repeated training. Fifteen minutes twice a year beats a full day every five years. Organisations that hand their teams a printed practical GDPR guide to keep by the workstation find that questions come up before the incident rather than after.
What you must absolutely not do
- Wait until you are certain. The 72-hour deadline is not suspended while you investigate internally.
- Delete the fax machine's log to "tidy up". That is destruction of evidence, and it will be read as such.
- Call the recipient to threaten legal action if they read the document. You have no basis for it, and you undermine their cooperation.
- Overlook processors. If the send went through a service provider, Article 33(2) requires them to alert you without undue delay — check that your contract says so.
- Assume that no complaint means the matter is closed. The register is still required, and an individual concerned can complain to the CNIL months later.
Frequently asked questions
Does the 72-hour deadline start when the fax is sent or when the error is discovered?
When it is discovered. The GDPR refers to "after having become aware of it". If a fax sent on the 3rd is reported on the 17th, the countdown starts on the 17th — but you will have to explain why fourteen days passed without detection, which will point to a monitoring failure.
Do I still need to notify if the recipient destroyed the document?
Not automatically. Prompt, documented destruction by an identified recipient bound by professional secrecy sharply reduces the risk. If the data is neither sensitive nor financial, a register entry may be enough. Document your reasoning precisely: that is what will protect you.
I received a fax by mistake — do I have any obligations?
Yes, both ethical and practical. Do not circulate the document, do not keep it, destroy it and report the error to the sender if their identity appears on the cover sheet. If the document contains health data and you are yourself a healthcare professional, confidentiality applies as a matter of course.
Does online fax eliminate the risk of dialling the wrong number?
No, it reduces it. You can still enter a wrong number. But the full history allows immediate detection, the record is preserved, and the document no longer exists in paper form at your premises. The residual risk is handled through the recipient directory and double validation.
Who has to notify: the practice or the fax provider?
The controller, meaning you. The provider, as a processor, must inform you without undue delay so that you can notify. Check that your contract contains this clause and a stated deadline.
In summary
- A fax sent to the wrong number containing personal data is a data breach under the GDPR, regardless of the recipient's good faith.
- Freeze the evidence first: transmission report, log, copy of the document, time of discovery. Purge nothing.
- The breach register is mandatory in every case; notification to the CNIL only where the risk cannot be ruled out, within 72 hours of becoming aware.
- Inform the individuals concerned where the risk is high: health data, banking data, identity theft.
- Obtain written confirmation of destruction from the unintended recipient: it is the single best mitigating factor.
- The corrective measures that convince are structural: a validated directory, double-checking, a neutral cover sheet, a move to online fax, and secure paper destruction.


