How advanced email forwarding can help you stay GDPR-compliant

One of the main requirements of the GDPR is to keep personal data safe. When it comes to electronic communication, you need to use every means possible to ensure that this type of data is not disclosed or accessed by any unauthorized persons, including your employees as well as people outside your organization. And since emails are sent in both directions, to and from your company, it would be beneficial to be able to manage the flow of all messages in your organization. With an appropriate tool in place, you can rest assured that all emails are always sent to the appropriate recipient and that no email containing sensitive data leaves your organization. And CodeTwo Email Signatures On-prem is just that kind of tool.

CodeTwo Email Signatures On-prem

CodeTwo Email Signatures On-prem is an email signature and email flow manager for Exchange Server Subscription Edition that is packed with many features that can help you process, protect, and monitor personal data exactly as you want. One of these features is advanced email forwarding. You can forward emails to specific recipients based on many different factors, for example:

  • whether the message contains specific keywords in its body or subject (such as “name”, “address”, “date of birth”, etc.),
  • who the sender of the message is (specific email address, email address included (or not) in your Active Directory, the message comes from outside of your company, etc.),
  • whether the message contains attachments,
  • whether the message is a new email, reply, forward, etc.

Take a look at the following examples of use for the email forwarding feature in relation to the GDPR and see how easy it is to implement automatic and controlled processing of personal data.

Access personal data in a timely manner

The GDPR requires that all matters related to personal data are handled promptly. You also need to know exactly where this data is stored at all times. Therefore, you intend to keep all emails containing personal data, as well as consents and requests pertaining to this type of data, in one place. This will allow you to react swiftly whenever you receive a request to update or delete personal details or need to prove the validity of received consent, etc.

You decided that it would be best to automatically redirect all emails containing consents and personal data to a specific mailbox, accessible only by your Data Protection Officers (DPO) or any person designated to process that type of data. By using CodeTwo Email Signatures On-prem, you can set up a rule that will forward particular emails to such a mailbox, i.e., emails sent by users outside of your company that contain specific keywords in the body or subject of the message. Additionally, it is possible to create another condition that will forward all replies to emails sent by your employees in which they are asking for consent to process personal data.

Forwarding conditions in CodeTwo Email Signatures On-prem

If the conditions are met, you now want the program to forward these messages to a specific mailbox; however, at the same time, you don’t want them to reach the original addressee. To do so, you can use the Forward message action to redirect all messages to a designated mailbox. Next, below the first action, you should add another one – Block message. That way, the original addressee will not receive the email with sensitive content.

Message forwarding action in CodeTwo Email Signatures On-prem

Forward all sensitive data to Data Protection Officer

You need to make sure that no personal data leaves your organization without your knowledge. For that reason, you intend to forward all emails that could lead to a possible data breach to your DPO. Additionally, you don’t want to allow any message that includes one or more attachments to leave your company without your knowledge, as these attachments can also contain personal data. Of course, those users who are appointed to process such data should be able to do so without any restrictions.

In CodeTwo Email Signatures On-prem, you can create a rule that applies to messages sent by users within your organization. Since the program comes with many sensitive content dictionaries which can be used to detect certain phrases in emails, it would be a good idea to use one of them as a rule condition to make it possible to detect personal data. You can also modify this dictionary, adding custom words and phrases that are used in your company. All that’s left to do is to add another condition that will apply to emails that have at least one attachment.

Forwarding conditions for internal senders in CodeTwo Email Signatures On-prem

Now, you can create an exception to this rule, because you don’t want to forward any such emails sent by your DPO or members of your Data Security group.

Forwarding exceptions in CodeTwo Email Signatures On-prem

On the Actions tab, you need to add two actions: Forward message and Block message. The first one forwards the original message to your DPO to verify if the email can leave your company. The second action blocks the message to prevent a possible data breach.

Stay GDPR-compliant

Email forwarding can be a very powerful feature when it comes to the GDPR. The number of possible combinations of conditions and exceptions is virtually unlimited. Use this opportunity to tailor email forwarding rules exactly to your requirements. Implementing CodeTwo Email Signatures On-prem to centrally manage the flow of incoming and outgoing emails can help you stay compliant with the GDPR.

Tools for Microsoft 365

Recommended articles

How to migrate from Exchange Server 2016/2019 to Microsoft 365

How to migrate from Exchange Server 2016/2019 to Microsoft 365

Migrating Exchange data to the cloud is not rocket science – explore your options and launch the migration stress-free. As you may already know, Exchange Server 2016 and 2019 have reached end of life and are no longer officially supported by Microsoft. If your organization still uses either of these platforms to manage email, contacts, calendars, and tasks, keep in mind that: Your environment may become vulnerable to newly discovered security threats – Microsoft will no longer provide security updates for Exchange 2016 and 2019 (unless you’ve enrolled in the Extended Security Update program, which ends in October 2026). Your emails may get blocked – Microsoft has started to throttle and block emails sent from unsupported Exchange Server versions to Exchange Online (as I covered in this article). That said, migrating to a supported platform is now the only viable long-term option for keeping your organization’s email environment secure, supported, and fully operational. If your organization wants or needs to keep things on‑premises (and continue using Microsoft’s solutions for that), upgrading to Exchange Server Subscription Edition (SE) is the only path forward. But given Microsoft’s clear preference for its cloud services – evident in the faster rollout of new features and the many security capabilities available exclusively in Microsoft 365 (Office 365) – now is a great time to leave your on‑prem environment behind and migrate to Exchange Online as part of Microsoft 365. While switching over to a new platform might seem like a rough ride, I’ll show you some easy ways to follow when migrating mailboxes from Exchange Server 2016/2019 to Microsoft 365. How to prepare for email migration to Microsoft 365 Before you start the migration process, you need to make sure your environment is ready for the move. For this purpose, you can use this guide in the Microsoft 365 admin center – it will help you connect your organization to Microsoft 365 and integrate your existing user accounts with Microsoft Entra ID. Microsoft also recommends completing the steps below: Set up an SPF record to determine valid email sources for your organization’s Microsoft 365 domain. Set up the Exchange Online Protection service as a means of protection against spam and malware. If you’re behind on updates, make sure to install the latest Cumulative Update (CU). And here is my quick, less obvious Microsoft 365 migration checklist: Verify if your software will work in Microsoft 365 (especially when it comes to server software). Microsoft 365 migration might be the time you learn that there is crucial legacy software that half the company uses and which is hard to replace. Encourage the whole company to clean up projects. It’s much easier to do this before the migration and start fresh. Gather as much information about your on‑premises environment as possible. For example, you might need to recreate access roles and permissions from scratch in the cloud or set up mail flow rules. Without prior research, it will be much more difficult. Verify if you need to migrate service accounts. There can be a lot of them on‑premises and in most cases, you won’t need them after the move. Review mailbox size limits in Exchange Online before migration to see which licenses you’ll need and whic
New-ComplianceSearch: how to use the newer version of Search-Mailbox

New-ComplianceSearch: how to use the newer version of Search-Mailbox

Microsoft retired the Search-Mailbox cmdlet – now what? Discover how to use New-ComplianceSearch, its key advantages and how to make the switch seamlessly.
How to start remote PowerShell session to Exchange or Microsoft 365

How to start remote PowerShell session to Exchange or Microsoft 365

One of many features of the PowerShell command line tool is its ability to connect with and manage the Exchange Server remotely. The procedure described below applies to the classic on-prem Exchange server and to the Microsoft 365/Exchange Online version.

Leave a Reply

Your email address will not be published.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

*

CodeTwo sp. z o.o. sp. k. is a controller of your personal data.
See our Privacy Policy to learn more.