GDPR-compliant Exchange Server – remove sensitive content

Remove sensitive content and stay GDPR-compliant with CodeTwo Email Signatures On-prem.

The General Data Protection Regulation (GDPR) introduced many changes in the way companies handle data. And although the regulations are the same for every company, the way each organization handles their data security is hardly similar. In this article, I will show you how you can get closer to complete GDPR compliance by blocking possible data leaks in your Exchange Server.

Emails are one of the most potent channels for data leaks – sometimes, an honest mistake can cause an email with personal data to leave an organization and end up in an unauthorized mailbox. Such a data breach is unacceptable and a disclaimer asking to “delete the email if it is not intended for this email address” is not enough under the regulations introduced by the GDPR. Thankfully, you can ensure a much higher data security level of your Exchange Server using CodeTwo Email Signatures On-prem.

Preventing accidental data leaks with DLP

Data Leak Protection (DLP) is a must for all companies who handle personal data at any point. Say, your company has introduced new procedures to handle clients’ personal data. You do not gather more personal data than you need, employees have access only to what they need to know. Thanks to those changes, only selected people ever come in contact with personal data.

There is one slight problem, though.

No matter how many procedures you deploy, there is always a human factor in every company. Mistakes happen and even the most experienced and cautious employees are not an exception. Especially when in a hurry, one might add the wrong person as a CC recipient of an email which contains personal data. Apart from causing potential data breaches, it might cause to spread classified information throughout the organization and out of control. As a result, you might not be able to comply with the right to be forgotten, introduced by the GDPR.

Luckily, you can use CodeTwo Email Signatures On-prem for advanced mail flow management.

CodeTwo Email Signatures On-prem is an email flow manager for the on-premises Exchange Server and a successor to the award-winning CodeTwo Exchange Rules Pro software. It can be used to control the content sent in emails, prevent data breaches, add automatic server-side email signatures, comply with corporate policies, law regulations and more. The scenario below shows how to use CodeTwo Email Signatures On-prem to prevent accidental data breaches.

How to prevent data leaks with CodeTwo Email Signatures On-prem

First, create a new rule which applies to messages by all employees and checks whether emails contain sensitive content. The program can use algorithms, wildcards, phrases, and regular expressions to determine whether the message contains sensitive data or not.

Defining rule conditions in CodeTwo Email Signatures On-prem.

Then, define what the rule should do when it finds personal information in an email. For example, you can mask the data which matches the filters you specify. As an additional step, you can add a disclaimer to those emails. With this disclaimer, you can inform your recipients that some data has been masked as a data-leak precaution.

Defining an action to remove sensitive content with CodeTwo Email Signatures On-prem.

The GDPR is a way to force companies to secure the way they handle personal data. However, it is important not to block your mail flow at the same time. That is where exceptions come into place. You can include all acceptable scenarios so that the program allows sending personal data if the message meets specific criteria.

Defining exceptions from the Remove sensitive content action in CodeTwo Email Signatures On-prem.

In the scenario above, the program simply masks sensitive content. However, in some cases, you might need to take more serious measures.

How to block a message with sensitive information and notify a security officer

In case of an accidentally-sent message, marking the sensitive content might be enough. However, data leaks might turn out to be not intentional but well-planned. If, in addition to that, your company deals with sensitive personal data, such data leaks might harm your company even more. That is why you should deal with any unauthorized attempts of sending personal data outside the company, immediately.

After choosing the criteria for the messages which pose a high data leak risk, tell the service to forward the message and block the email:

The Block message action in CodeTwo Email Signatures On-prem.

This way, your Data Privacy Officer is instantaneously notified of all data breach attempts and can react accordingly. From the sender’s perspective – the email is normally sent. Data Privacy Officer can forward the email if the message was intercepted or take any necessary steps to prevent an employee from causing data breaches.

What is more, you can allow remote access to rules, so that Data Privacy Officers can fine-tune the rules. This way the rules will apply only to those emails which pose a real threat.

Achieve a fully GDPR-compliant Exchange Server

Using DLP policies can greatly reduce the risk of a security breach in your company. CodeTwo Email Signatures On-prem can help your users switch to the secure and privacy-protecting ways of handling data thanks to advanced attachment management, a smart unsubscribe system and more.

Helping with achieving GDPR compliance is only a fraction of what CodeTwo Email Signatures On-prem can do. The program can also be used to promote your branding, unify your email signatures, and much more. For a full list of the program’s functionalities, visit its main page.

Tools for Microsoft 365

Recommended articles

How to migrate from Exchange Server 2016/2019 to Microsoft 365

How to migrate from Exchange Server 2016/2019 to Microsoft 365

Migrating Exchange data to the cloud is not rocket science – explore your options and launch the migration stress-free. As you may already know, Exchange Server 2016 and 2019 have reached end of life and are no longer officially supported by Microsoft. If your organization still uses either of these platforms to manage email, contacts, calendars, and tasks, keep in mind that: Your environment may become vulnerable to newly discovered security threats – Microsoft will no longer provide security updates for Exchange 2016 and 2019 (unless you’ve enrolled in the Extended Security Update program, which ends in October 2026). Your emails may get blocked – Microsoft has started to throttle and block emails sent from unsupported Exchange Server versions to Exchange Online (as I covered in this article). That said, migrating to a supported platform is now the only viable long-term option for keeping your organization’s email environment secure, supported, and fully operational. If your organization wants or needs to keep things on‑premises (and continue using Microsoft’s solutions for that), upgrading to Exchange Server Subscription Edition (SE) is the only path forward. But given Microsoft’s clear preference for its cloud services – evident in the faster rollout of new features and the many security capabilities available exclusively in Microsoft 365 (Office 365) – now is a great time to leave your on‑prem environment behind and migrate to Exchange Online as part of Microsoft 365. While switching over to a new platform might seem like a rough ride, I’ll show you some easy ways to follow when migrating mailboxes from Exchange Server 2016/2019 to Microsoft 365. How to prepare for email migration to Microsoft 365 Before you start the migration process, you need to make sure your environment is ready for the move. For this purpose, you can use this guide in the Microsoft 365 admin center – it will help you connect your organization to Microsoft 365 and integrate your existing user accounts with Microsoft Entra ID. Microsoft also recommends completing the steps below: Set up an SPF record to determine valid email sources for your organization’s Microsoft 365 domain. Set up the Exchange Online Protection service as a means of protection against spam and malware. If you’re behind on updates, make sure to install the latest Cumulative Update (CU). And here is my quick, less obvious Microsoft 365 migration checklist: Verify if your software will work in Microsoft 365 (especially when it comes to server software). Microsoft 365 migration might be the time you learn that there is crucial legacy software that half the company uses and which is hard to replace. Encourage the whole company to clean up projects. It’s much easier to do this before the migration and start fresh. Gather as much information about your on‑premises environment as possible. For example, you might need to recreate access roles and permissions from scratch in the cloud or set up mail flow rules. Without prior research, it will be much more difficult. Verify if you need to migrate service accounts. There can be a lot of them on‑premises and in most cases, you won’t need them after the move. Review mailbox size limits in Exchange Online before migration to see which licenses you’ll need and whic
New-ComplianceSearch: how to use the newer version of Search-Mailbox

New-ComplianceSearch: how to use the newer version of Search-Mailbox

Microsoft retired the Search-Mailbox cmdlet – now what? Discover how to use New-ComplianceSearch, its key advantages and how to make the switch seamlessly.
How to start remote PowerShell session to Exchange or Microsoft 365

How to start remote PowerShell session to Exchange or Microsoft 365

One of many features of the PowerShell command line tool is its ability to connect with and manage the Exchange Server remotely. The procedure described below applies to the classic on-prem Exchange server and to the Microsoft 365/Exchange Online version.

Leave a Reply

Your email address will not be published.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

*

CodeTwo sp. z o.o. sp. k. is a controller of your personal data.
See our Privacy Policy to learn more.