/
Data Privacy
/
Who Controls Sensitive Information After It’s Shared?
•
Written by:

For Nordic municipalities, public-sector organisations, law firms and accounting firms, protecting sensitive information is no longer only about securing internal systems. Increasingly, the bigger question begins when that information leaves the organisation.

A confidential document may be encrypted when it is stored. A case file may sit behind a secure login. A municipality may have strict access controls around citizen information. But the moment that data needs to be shared with a client, citizen, supplier, lawyer, auditor or another external organisation, the security environment changes.

That is where organisations need to ask a more difficult question: who controls sensitive information after it has been shared? The issue is becoming increasingly relevant across Norway and the wider Nordic region. Norway’s Data Protection Authority recorded 3,191 notifications of personal-data security breaches in 2024, representing a 13% increase from the previous year. For organisations managing personal information every day, those figures underline that data protection cannot be treated purely as an internal IT responsibility.

At European level, the threat landscape is also changing rapidly. ENISA’s 2026 Threat Landscape found that public administration remained the most targeted sector in the EU, accounting for 32% of recorded incidents. The agency also noted that 73% of targeted organisations were entities considered essential or important under the NIS2 framework.

For Nordic municipalities and semi-government organisations, this matters because digital communication is now fundamental to everyday public services. Citizens submit personal information digitally. Departments exchange documentation. External consultants and professional advisers are brought into cases. Sensitive files move between organisations, and communication increasingly happens outside traditional organisational boundaries.

The same challenge applies to law firms and accounting and audit firms. Legal professionals routinely exchange identification documents, case material, contracts and commercially sensitive information. Accountants and auditors work with payroll data, company financials, tax information, bank details and documentation that may contain personal information. In each case, secure communication is not a specialist cybersecurity issue. It is part of normal business operations.

Sending securely is only the beginning

Much of the conversation around cybersecurity has historically focused on encryption and secure transmission. Both remain essential. But secure delivery does not automatically mean continued control.

Once information has been sent through conventional email, organisations may have limited visibility into what happens next. Was the message opened? Was the attachment downloaded? Was it forwarded? Does another person now have access? Is the original recipient still authorised to view it months later? This distinction between secure sending and controlled communication is becoming increasingly important.

Human error remains one of the most persistent risks. Sensitive information can be sent to an incorrect recipient, an attachment can be included in the wrong email thread, or confidential material can remain accessible longer than intended. Cybersecurity therefore needs to account not only for deliberate attacks, but also for ordinary mistakes made during everyday communication.

At the same time, public-sector organisations face a growing external threat. ENISA has highlighted public administration as a prime target for cybercrime, hacktivism and state-linked activity. Although disruptive DDoS attacks account for a substantial share of public-sector incidents, data breaches and exposures can create significantly more serious consequences because they directly affect confidential information. For organisations entrusted with sensitive information, the objective should therefore extend beyond preventing an attacker from entering a system. It should include maintaining visibility and control throughout the full lifecycle of a conversation.

GDPR compliance continues beyond storage

The GDPR places significant responsibilities on organisations that process personal data. Yet compliance can sometimes be viewed too narrowly, with emphasis placed on how information is collected and stored rather than how it is subsequently communicated. In reality, organisations continuously share personal data with people outside their own systems. A municipality may need documentation from a citizen. A law firm may request identification from a client. An accountant may exchange financial records with a business owner. An auditor may require supporting evidence from several external stakeholders.

Every one of those interactions creates another point at which sensitive information needs to be protected. This is why GDPR-compliant communication, encrypted file sharing, secure external collaboration and access control are increasingly important components of an organisation’s broader information-security strategy. The question is no longer simply whether a file was encrypted during transmission. Organisations increasingly need to understand who was invited into the communication, who has viewed messages or documents and whether access remains appropriately controlled.

Moving beyond the traditional inbox

Email remains one of the most widely used communication tools in organisations, but it was not originally designed as a controlled environment for managing confidential workflows. Group email threads become fragmented. Attachments are duplicated. Information becomes distributed across several inboxes. Employees may struggle to establish which version is current or who has seen particular information.

For low-risk communication, those inefficiencies may be manageable. For sensitive information, however, they can become a security and governance problem. Secure communication platforms are increasingly designed around a different model: creating controlled digital spaces where communication, participants and files remain connected to a particular case, client or project. Verji uses this room-based approach. Only invited participants can access a communication room, while messages and file sharing are encrypted. Organisations can also see who has viewed messages and files, creating greater visibility around external communication. Verji additionally supports BankID signing within encrypted rooms.

The significance of this approach is not simply technological. It changes how organisations think about information ownership after sharing. Instead of treating a confidential attachment as something that disappears into another inbox, communication can remain within a structured environment where participation and access are clearer.

Trust increasingly depends on how information is handled

For municipalities, public institutions and professional-services firms, information security is also a question of trust. Citizens expect public bodies to protect their personal information. Clients expect lawyers to preserve confidentiality. Businesses expect accounting and audit firms to handle financial records responsibly.A security incident can therefore create consequences beyond the immediate exposure of data. It can damage confidence in the organisation itself.

That makes secure digital communication an increasingly visible component of professional responsibility. Organisations should be able to answer fundamental questions about sensitive information: who currently has access, whether the recipient can be verified, where the conversation is stored and whether the organisation still has meaningful visibility after information has been shared. As external collaboration increases, these questions will become more important rather than less. The future of secure communication is therefore unlikely to be defined simply by stronger encryption. Encryption will remain fundamental, but organisations will increasingly require a combination of secure file sharing, controlled access, GDPR compliance, authentication, traceability and structured external communication.

For Nordic municipalities, law firms, accounting firms and organisations responsible for confidential information, the shift is straightforward. Security should not stop at the moment information leaves the organisation. Because when the information is sensitive, the most important question may not be “Did we send it securely?” It may be: “Do we still know who controls it?”


Do you want to know more about Verji? Take advantage of the opportunity for a 30-day free trial period. 

Curious about Verji?

Verji is suitable for any business that needs to communicate securely, simply and efficiently in line with GDPR.

RELATED ARTICLES

Verji
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.