Law vs. email disclaimers: overview of existing international legislation

Law vs. email disclaimers: overview of existing international legislation

But when exactly is this the case? Contrary to reports floating around on the web, email disclaimers are rarely specifically mentioned in legal acts, regardless if these acts focus on electronic correspondence exclusively, aim to regulate commercial messages in general or put restrictions on communication in certain branches of the economy. Neither are disclaimers a surefire protection against security breaches and lawsuits.

Below I discuss to what extent legal systems in different regions of the world mandate the use of email disclaimers and determine their status.

USA

The Health Insurance Portability and Accountability Act (HIPAA)

Applies to: All US companies transmitting patients’ personal healthcare data.

Requirements: Implementation of appropriate administrative, technical and physical safeguards to guarantee the confidentiality of patients’ personal healthcare data.

Email disclaimers: While HIPAA does not explicitly require healthcare companies to use email disclaimers, they are considered a supplementary measure used to discourage unauthorized use, disclosure or distribution of message contents. They are also a good method of informing patients about the risks related to sending their individual healthcare information via email.

Reference: https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html  

Gramm-Leach-Bliley Act (GLBA)

Applies to: Messages sent by financial institutions in the US.

Requirements: Messages containing recipients’ personal information must be vastly protected – this includes using protected channels, encryption, etc.

Email disclaimers: Since they do not ensure 100% confidentiality, they can only be used in an auxiliary capacity, e.g. to, quote: “Caution customers against transmitting sensitive data, like account numbers, via email or in response to an unsolicited email or pop-up message”.

Reference: https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act  

Internal Revenue Service (IRS) regulation Circular 230 

A broad set of rules governing written tax advice, which, due to the unclear formulation, used to cause a “this email does not constitute tax advice” disclaimer to be added to most messages sent by law firms.

Starting from June 12, 2014, the Circular 230 rule that contributed to overuse of the “safety disclaimer” is no longer in force.

Email disclaimers: Not required.

Reference: http://www.bloomberg.com/news/2014-06-23/circular-230-tax-disclaimers-head-to-the-trash-business-of-law.html
Full text of revisions to Circular 230: http://www.irs.gov/file_source/pub/irs-utl/TD_9668_6-9-14_Cir%20230_6-9-14_Final_Reg.pdf

CANADA

Canada’s Anti-Spam Legislation (CASL)

Applies to: All commercial messages sent to recipients in Canada.

Requirements: Aside from a few exceptions, Canadian users must always be given the option to provide express and informed consent before they receive any commercial messages from a company or individual. Messages must also include clear sender’s identification and a readily available opt-out mechanism.

Email disclaimers: Mandatory. To comply with CASL any person or company who sends commercial messages must append them with clear and up-to-date sender’s identification, i.e.:

  • name
  • business
  • name of a person on whose behalf the message is sent (if applies)
  • current mailing address
  • phone number
  • email or web address
  • unsubscribe link or information about opt-out phrase (requests must be fulfilled within 10 days)

Reference: http://fightspam.gc.ca/eic/site/030.nsf/eng/00288.html

UNITED KINGDOM

Under the Companies Act 2006 businesses are required to append electronic messages with the following details:

  • company’s registered name
  • part of the UK where the company is registered
  • company’s registration number
  • registered office physical address
  • the fact that it is a limited company in the following cases: if the company is exempt from adding the word “limited” to its name; if the company is a community interest company which is not a public company
  • amount of paid up share capital (if the company has chosen to display shared capital).

Source and more information: http://www.companieshouse.gov.uk/about/gbhtml/gp1.shtml#ch10

EUROPEAN UNION

General Data Protection Regulation (GDPR)

Applies to: All messages containing personal data of EU citizens (including ones exchanged within a work environment).

Requirements: EU citizens’ personal information can only be collected and processed if the party concerned gives consent after having been informed in detail about:

  • The identities of the data collector/processor and their representatives (if present)
  • The reason for data collection/processing
  • Third parties involved in data collection/processing
  • Whether the personal data is required for the provision of services
  • Means of directing claims and opting out of data collection

Email disclaimers: Disclaimers are commonly accepted as a medium for providing a link to the company’s Privacy Policy and other documents used to share the abovementioned information with concerned parties. 

Regulations implemented under the GDPR predecessor, European Union Directive 95/46/EC, are currently part of the UK’s Data Protection Act, Germany’s Federal Data Protection Act (Bundesdatenschutzgesetz), Netherlands’ Personal Data Protection Act (Wet bescherming persoonsgegevens), and other legislation of the EU member states.

Note: Monitoring of employees’ correspondence by the employer can also be considered to fall into the category of personal data processing.

Source and more information: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng

European Union Directive 2017/1132

Applies to: All corporate correspondence.

Requirements: Messages must contain the legal form of the sender’s company, registered office physical address, as well as information where the company is registered and under what number. If the company is being wound up, the fact must be stated.

Email disclaimers: Mandatory.

Reference: https://eur-lex.europa.eu/eli/dir/2017/1132/oj/eng  

Examples of implementation of the directive in EU member states:

———————–

Ireland

As stated in the Companies Act 2014, companies are required to include in all letters and order forms (paper or any other medium):

  • the company’s name and legal form
  • the place of registration and Company Registration Number (CRN)
  • the physical address of the registered office

Sources and more information: 

https://www.irishstatutebook.ie/eli/2014/act/38/section/49/enacted/en/html

https://www.irishstatutebook.ie/eli/2014/act/38/section/151/enacted/en/html#sec151

Germany

Starting from January 1, 2007, the Gesetz über elektronische Handelsregister und Genossenschaftsregister requires commercial emails to state the following:

  • company name in accordance with the Commercial Register
  • legal form (for example, K., KG, OHG, GmbH, AG, GmbH & Co.KG, Ltd.)
  • place of the establishment with street and address
  • registration court and registration number
  • all directors or board members
  • if present, the Chairman of the Supervisory Board with the family name and a complete first name
  • the chairman of the board, if one is designated as such
  • information on capital, in cases when it has not been fully paid up; additionally joint venture companies (AG) must additionally specify the amount of share capital and total value of outstanding shares, while limited liability companies (GmbH) must specify the share capital value and, if it has not been paid up yet, the value of outstanding deposits.

For traders who do not have a firm registered in the commercial register, §15b of the Trade Regulation applies, requiring that on all business letters that are addressed to a specific recipient, they provide their surname with at least one complete first name. The requirement does not apply to messages exchanged within existing business relationships, for which standard forms with separate disclosure rules are used.

Source and more information: http://www.internetrecht-rostock.de/email-pflichtangaben.htm

France

Article R 123-237 of the French Commercial Code, amended by decree of May 9, 2007, extends the category of correspondence onto external corporate emails, which henceforth have to include:

  • the company’s unique registration number (SIREN number)
  • Register of Commerce (RCS) in which company is registered
  • registered office physical address
  • information regarding insolvency proceedings (if applies)
  • in case the company belongs to a corporate entity with registered office overseas, emails must include all of the above, as well as the overseas company’s name and legal form
  • the fact that the company is run by a lease manager (locataire-gérant) or an authorized management agent (gérant-mandataire) (if applies).

Source and more information: http://larevue.squirepattonboggs.com/Implementation-in-France-of-European-Directive-2003-58-on-compulsory-corporate-information-on-correspondence_a1025.html

Additional comments

A common practice among both corporate and private users is to append emails with confidentiality disclaimers, waivers of legal responsibility, etc. The main point to stress here is that the status of these types of notices varies from country to country. Where one legislature may imbue them with indisputable legal substantiality, another can view them as unenforceable.

The United Kingdom is an example of the former. Its existing law dictates that, if a message is expressly or implicitly confidential, a recipient cannot disclose its contents or use it for a purpose unintended by the sender (source: http://www.weblaw.co.uk/articles/legal-position-of-email-disclaimers/). It is evident that in this case stamping your email with an immediately visible confidentiality disclaimer makes all the difference. A person choosing to reveal the contents of such an email automatically comes into conflict with the law and is subject to penalty.

This is less clear cut in the USA, where each case may go either way based on the ruling of the jury. It can, however, be argued that confidentiality disclaimers generally hold up in American courts, as do to a large extent notifications of sender’s lack of contractual authority.

To conclude, as you noticed, my article does not cover the entire scope of international email disclaimer legislation. Countries I failed to mention may enforce their own unique or very similar laws. Judging by the current trend of increasing Internet regulation and the budding (one can hope) recognition of end-user rights to privacy and transparency, I would guess the latter is or will soon be true.

As to voluntary disclaimers, if you’re still on the fence about attaching a standard one to your business emails, remember that regardless how the matter is treated by the legislation in force in your country or state, it can always be used as a supplementary measure informing recipients of potential legal ramifications of the correspondence, encouraging or discouraging certain behavior, or helping reduce damage caused by unexpected events. And the worst-case scenario is that it will go unnoticed.

NOTE: Information in this article does not constitute legal advice or legal opinions. You should not act or rely on it without first seeking the advice of an attorney.

Software tips

CodeTwo Email Signatures 365: Automatic legal email disclaimers directly under latest reply/forward.

CodeTwo Email Signatures On-prem: Full legal email compliance including legal disclaimers, email content inspection and control, management of attachments, and more.

CodeTwo Email Signatures 365 is the only fully Microsoft 365 Certified email signature solution (the entire infrastructure reviewed & pen-tested by Microsoft). It's an Azure-based cloud service that supports all devices and email apps. Co-engineered and awarded by Microsoft, it also holds the highest user satisfaction ratings. With ISO 27001 & 27018 certification and a proprietary 4-layer security system, it's the most secure signature manager on the market. Watch a short product video

CodeTwo offers solutions for organization-wide email signature management, data backup and migration for Microsoft 365 & Exchange Server, developed since 2007 and used by over 140k organizations worldwide, including Facebook, Samsung and UNICEF.


Recommended articles

How to migrate Exchange public folders to Microsoft 365 with CodeTwo

How to migrate Exchange public folders to Microsoft 365 with CodeTwo

CodeTwo Office 365 Migration is your best option for migrating public folders to the cloud ahead of EWS retirement in Exchange Online. 
Holiday email signature ideas and inspirations from CodeTwo

Holiday email signature ideas and inspirations from CodeTwo

Add a festive touch to your email communications with CodeTwo Email Signatures 365.
Using gender pronouns in email signatures

Using gender pronouns in email signatures

See the easiest way to control gender pronouns in organization-wide email signatures and learn why it's a thing. Gender pronouns have become an essential part of professional email communication. Some companies now tend to include gender information in their email signature policy, while others ban them. In this article we’ll highlight the importance of gender pronouns and show you how to use them in email signatures in your organization.

Comments

    • avatar
      Paweł Krzemiński says:

      Hi Huan,
      Maybe in part 2, but no promises. In any case, suggestions of specific laws I should write about are welcome.
      Best regards,
      Pawel

Leave a Reply

Your email address will not be published.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

*

CodeTwo sp. z o.o. sp. k. is a controller of your personal data.
See our Privacy Policy to learn more.