Corresponding with HMRC electronically — CC/FS83
Published 22 May 2024
Use the following information to decide whether you want to deal with us electronically using email or Dropbox.
We take the security of personal information very seriously. Email is useful for corresponding with us, but is not secure. Dropbox is useful for sending us information and is more secure, but still has risks. It’s very important that you understand the risks of each before you use them to correspond with us.
Before we can use email or Dropbox for your personal or sensitive data, you must read the risks detailed below. You must confirm in writing that you understand and accept them.
The main risks associated with using email that concern us are:
- confidentiality and privacy – there’s a risk that emails sent over the internet may be intercepted
- confirming your identity – it’s crucial that we only communicate with established contacts at their correct email addresses
- there’s no guarantee that an email received over an insecure network, like the internet, has not been altered during transit
- attachments could contain a virus or malicious code
To reduce the risks:
- we’ll desensitise information, for example by only quoting part of any unique reference numbers
- we can also use encryption, we can discuss how you may do the same but still give the information
we need - we carry out regular assurance to make sure all precautions are being followed
Dropbox
The main risks associated with using Dropbox are:
- unauthorised access to data held in Dropbox
- scammers posing as HMRC to get customers to upload data to them
To reduce the risks:
- access to Dropbox is restricted to named licence holders
- Dropbox data is held in secure storage and is not held in Dropbox for more than 24 hours
- a link to upload your files will be sent to you from an HMRC email address
- time to upload your files to Dropbox using the link will be restricted to 48 hours
- once the files are received we will confirm receipt and retrieval of the data by email
If you do not want to use email or Dropbox
You may prefer that we do not respond by email, for example because other people have access to your email account. If so, we’re happy to respond by another method. We’ll agree this with you either by telephone or in writing by post.
If you do want to use email, Dropbox or both
If you would like to use email or Dropbox as one of the ways HMRC will contact you, we’ll need you to confirm in writing by post or email that:
- you understand and accept the risks of using email, Dropbox or both
- you’re content for financial information to be sent by email, Dropbox or both
- attachments can be sent with email
If you’re the authorised agent or representative we’ll need you to confirm in writing by post or email that your client understands and accepts the risks.
Please also:
- send us the names and email addresses of all people you would like us to use email with — for example, yourself, your staff, your representative, your agent
- check that your junk mail filters are not set to reject or automatically delete HMRC emails
How we use your agreement
Your confirmation will be held on file and will apply to future email or Dropbox correspondence. We’ll review the agreement at regular intervals to make sure there are no changes.
Opting out
You may opt out of using email, Dropbox or both at any time by letting us know.
More information
For more information about HMRC’s privacy policy, go to ÌìÃÀÓ°Ôº and search ‘HMRC Privacy Notice’.