As reported in This is Money, P&O Ferries mistakenly shared personal details relating to 432 passengers through a customer service text message on 31 August 2026. The report, by Simon Lambert, concerned the midday sailing from Calais to Dover.
For organisations that send customer updates, this raises a practical question: what stops an internal customer list from being included in an external message?
A useful review should cover the whole sending process, from preparing the information to checking the final message. Staff need to know what to look for, and the systems they use should help them catch mistakes before information leaves the organisation.
What This is Money reported
According to the report, the message directed customers to an attachment containing a passenger spreadsheet. The information included names, customer IDs, booking numbers, email addresses and phone numbers.
In a statement quoted by This is Money, P&O Ferries described an isolated incident in which a link containing information about customers on one sailing was accidentally shared with some of those customers. It apologised and said it was contacting affected customers directly.
The distinction matters: 432 is the reported number of passengers whose details were included, not a confirmed count of recipients. The report does not establish the underlying technical cause or how many people accessed the information. Those questions would need investigation before drawing conclusions about which controls failed.
Why routine customer messages deserve a data protection check
The ICO explains that a personal information breach can include accidental disclosure, such as sending information to the wrong person. An organisation can therefore have a breach while using its usual systems for an ordinary business task.
For example, consider a customer service team sending an update about a delayed appointment. The team may need an internal booking list to identify the right recipients. That does not mean those recipients need to receive the list itself. Preparing the audience and preparing the content are separate tasks, with different information requirements.
Contact details also need to be assessed in context. An email address combined with a booking reference could help someone make an unsolicited message sound convincing. A request to confirm a booking or pay an additional charge may appear more credible when it includes details the recipient recognises. This is a possible risk to consider, not evidence that fraud followed the P&O incident.
When assessing a disclosure, ask what information was exposed, who could receive it and what they might do with it. The ICO’s guidance on assessing breach risks makes the recipient and the circumstances part of that assessment. The number of records alone cannot tell you how serious a breach is.
Four checks before sending customer communications
The following four controls can reduce the chance of an accidental disclosure. They are practical steps for other organisations to consider, rather than findings about P&O Ferries’ systems or staff.
- Train staff and give them clear reminders. Anyone sending customer communications should understand the risk of accidental disclosure and be reminded to check the message before sending it. The check should cover the recipients, message, attachments and links. Training should use the tools and decisions staff encounter at work, rather than relying only on a general policy.
- Test the complete communication. Send it first to a small group of trusted internal recipients. They should open the communication as a customer would, follow its links and inspect every attachment. This confirms what recipients will actually see and helps identify incorrect or additional data that may not appear in the message preview.
- Use an independent reviewer. A second person, separate from the person who prepared the communication, should verify it before the wider send. Their role is to confirm that the content is accurate, the intended audience is correct, required legal information is present and no unnecessary personal data is included. The review should be recorded so it is clear who approved the send and what they checked.
- Provide a clear escalation route. Staff should know how to pause a send and who to contact if they discover a mistake or suspected breach. The process should explain the immediate containment steps, what evidence to preserve and who will assess whether affected people or the ICO must be notified. It should also cover incidents discovered outside normal office hours.
Our data protection training matrix guide provides a starting point for matching training to responsibilities. Customer service staff who send communications, managers who approve them and administrators who configure access and sharing will need different examples and checks.
Respond quickly and record your decisions
If information has been shared incorrectly, start by containing the exposure where possible. Pause further sends, restrict the affected link and preserve the information needed to investigate. Establish what was sent, when, to whom and whether access or download records are available. Asking recipients to delete information may help, but does not prove that every copy has been removed.
The ICO’s personal data breach guide distinguishes between reporting to the regulator and informing affected people. Under the UK GDPR, a controller must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to people’s rights and freedoms.
Where a breach is likely to result in a high risk, affected people must also be informed without undue delay, subject to the applicable exceptions. All personal data breaches must be documented, including the reasoning behind a decision not to notify the ICO. These are general requirements; this article does not determine P&O Ferries’ reporting obligations or compliance.
For your own organisation, a useful first step is to walk through one real customer communication process with the people who use it. Identify where personal information enters the workflow, what gets checked before sending and how a mistake would be reported. Use the gaps you find to improve both the process and the training that supports it.
