BG Beter Geregeld ICT
Security zonder IT-afdeling · 5 min leestijd · 15 August 2026

Emailing a scan to your accountant: how to do it properly

A passport copy, payslip, or contract sent in a hurry — it happens in every office. Here's how to do it without regretting it later.

It happens in every office: someone walks to the printer, scans a document, and emails it on. To the accountant, an insurer, a client. Quick, easy, done. But that scan often contains more than you realise: a national ID number, a passport photo, a salary figure, an IBAN, a signature. And the email you send it in is usually far less private than you assume.

In this post we walk through what you should and shouldn't do the next time something needs to be "quickly forwarded".

Why a regular email attachment isn't always a good idea

Technically speaking, an email is more like a postcard than a sealed envelope. Along the way it is temporarily stored by multiple parties, scanned for viruses, and sometimes forwarded. For most everyday correspondence that's fine. But as soon as personal data is involved, three things come into play:

  • The attachment sticks around forever. In your Sent Items, in the recipient's inbox, in potential backups on both sides. Years later, that passport copy is still sitting there.
  • One wrong address = lost document. Autocomplete can easily pick the wrong "Jan" from your contacts. Recalling the message rarely works in practice.
  • Forwarding takes one click. A recipient can send the file on to someone else without asking. You lose all visibility from that point on.

Under GDPR you as the sender are often jointly responsible for what happens with that data. That doesn't mean you can never email anything again — but it does mean you should think before you hit send.

Four questions to ask yourself before you send

  1. Does the whole document need to go? Often the recipient only needs one piece of information (an IBAN, a date of birth, an amount). A short line of text in the email body is then better than attaching the entire PDF.
  2. Is there anything in it that doesn't need to be there? A national ID number on an ID copy isn't required for many purposes. A payslip doesn't always need to show the full bank account number for an insurance query.
  3. Is the email address definitely correct? Don't just look at the display name in your contacts — check the actual address behind it. Especially with new contacts.
  4. Is there a portal? Accountants, banks, insurers, and payroll providers almost all have an upload environment these days. It is nearly always more secure than email.

Reduce what you send: redacting unnecessary data

For identity documents a simple rule applies: only send what the recipient genuinely needs. The Dutch government has a handy app for this (KopieID), but in practice this also works well: convert the scan to PDF and black out the fields you don't want to share. Think of the national ID number, the document number, and the MRZ code at the bottom (those two lines of characters with dashes). Make sure the text is truly removed — a black box over a screenshot is fine, but in PDF editors you need to check that the underlying layer is gone too, not just covered up.

Add a note stating what the copy is for, and include the date. That makes misuse harder if the document ever ends up somewhere it shouldn't.

Two file types, two habits

In day-to-day practice, there are two kinds of scans that come across your desk:

Invoices, quotes, contracts

These can generally be emailed without issue. A few good habits: send them as PDF (not as an editable Word file), include the amount and invoice number in the subject line, and always check the account number on incoming invoices. Does the IBAN match what you normally see from this supplier? If you're unsure, a quick check to see whether the IBAN is technically valid in the first place can be done with our IBAN check. That won't catch fraud, but it will catch a typo.

Personal data, ID copies, medical documents

The rule of thumb here is: preferably not as a loose attachment. Better options are a shared folder (for example in your business Microsoft 365 or Google Workspace environment) with an expiring link, or the receiving party's own portal. If email really is the only option, reduce what the document contains (see above) and agree with the recipient that they will delete it once processed.

The printer-scanner itself: worth a thought too

The multifunction device in the corner of the office often remembers more than people realise. Many devices temporarily store scanned documents on an internal drive, and some leave them in the email output queue until someone hits "delete". Two simple agreements help:

  • Don't leave scanned documents in the mail queue or on the printer's drive. Delete them immediately after sending.
  • When a device is replaced or disposed of, explicitly request that the internal drive be wiped. This is not done by default.

Quick summary

  • Send as little as possible, for as short a time as possible.
  • Redact the national ID number and MRZ on ID copies, and note the purpose.
  • Use a portal or shared link wherever possible.
  • Always check the account number on invoices — validation takes ten seconds.
  • Clear scanned documents from the printer.

Want to make sure the emails you send can't easily be spoofed in your name from a technical standpoint? That's handled with SPF, DKIM, and DMARC. We can help you get that sorted — see our email security page. And for that quick IBAN check on incoming invoices, there's our IBAN check.

Onderwerpen

#avg #privacy #Mail Beveiliging #Documenten #Mkb Praktijk

Volledige gids: Security for SMBs without an IT department: what should you do this quarter?

Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →