Please or to access all these features

AIBU?

Share your dilemmas and get honest opinions from other Mumsnetters.

AIBU to think writing confidential HR notes on a train is inappropriate?

387 replies

Elphabababa · 28/05/2026 17:19

I am on a train in the UK.

Someone on the seat in front of me is writing up meeting notes from work. All clearly visible through the gaps between seats. I am slightly long sighted mind you.

I have seen that:

  • She works in HR for company X
  • The meeting was for an employee named Y (I can see his name and job title), following him raising a grievance about a GDPR breach of his data within work.
  • Subsequent notes of the meeting about this grievance.

She's still typing her notes now.

AIBU for thinking that people should be very mindful of what work they complete in public places? And that this is inappropriate, and if Y found out that these notes were being written in full public view, they would have a further grievance on their hands?

Or am I a nosey parker?

(Or both?)

OP posts:
BanditTheCat · 28/05/2026 22:46

I haven’t read all the comments but as someone who had a fairly long career in HR, it isn’t breaking any law, and honestly that person was probably just trying - like a lot of people in the corporate world - to use an opportunity where there’s a bit of dead time and they’re not being interrupted to get on top of their work. HR people do work on trains as well as other people do. Just because it’s HR and we deal with work confidential to the company, doesn’t mean just because someone’s taking a peek at that work that we’ve breached any type of ethics. And people saying “Ring the company!” are the same type of people who comment on threads about not being able to put offers in on houses that are already sold by offering the solution of “Just knock on the door and demand a viewing.”

Hellohelga · 28/05/2026 22:42

Report or say something, if you can be bothered. So many MNers minimise and condone unprofessional behaviour. Raise your standards. At my firm this would be a disciplinary.

Kitestring · 28/05/2026 22:40

Imagine if HR woman was reading this thread. She would be having a worrying evening.

I think the suggestion of reporting it in a generic way is the way to go. To tell the company that their employees need a reminder of the importance of protecting data. Give non identifiable details but impress upon them it was a data breach plus could cause major embarrassment to the company if you were minded to take it further than à general warning.

blubberyboo · 28/05/2026 22:26

LatteLady · 28/05/2026 22:12

Twenty years ago, I worked at KPMG, Colin Sharman was the managing partner... he would go ballistic with anyone discussing client business in the lift because you did not know who else was in the lift with you. This is the reason, also, back then if you were working on client business, you travelled first class with a privacy screen. It's basic commonsense, so yes, report it.

Not the case in this train situation but it can be highly criminal to disclose market sensitive insider information to those not entitled to know it. Either with loose tongues in public places or having someone see a computer screen.

It can mean those outside are able to manipulate markets and share prices by trading on the inside information and severely influence prices. If OP had instead seen something like a merger being discussed and then traded shares using this info the little train typist could have ended up in prison!

blubberyboo · 28/05/2026 22:18

Soonbbbqweather · 28/05/2026 21:33

Not quite relevant to GDPR but nosey Parker’s, DD when studying became aware of a bloke who would look over her shoulder at the station every morning at whatever she was reading. Getting quite fed up with it, as she was studying for a medical qualification, she located a photo of a severely diseased male penis! His reaction the next day resulted in him never standing near her again!

And I concur with the other posters who advised it should have been raised at the time. No she shouldn’t have been doing it but also was entitled to assume nobody would peer through the seats and read her screen. We always used to put a warning page in confidential papers regarding awareness of reading them in public.

Sorry she certainly was not entitled to assume nobody would peer through a train seat.

when you are responsible for someone’s data that doesn’t mean you get a pass for assuming that the general public are to take responsibility for averting their eyes

we live in a world where criminals are trying to harvest data all the time. The responsibility lies firmly with the data controller to protect it from everyone.

If she needed to work on the train she should have used a privacy screen or typed her notes up on a word document anonymising the personal data until she could transfer it to the file in a private place

no excuse and she deserves to be reported

BlushingBrightly · 28/05/2026 22:15

plsdontlookatme · 28/05/2026 22:00

There's no point intervening in the actions of people who are fundamentally stupid, careless, and selfish. It's a waste of time. Someone thick enough to be waving confidential info around on the train isn't going to have a data protection revelation from a stranger tapping them on the shoulder.

This. Someone who's had HR training and still thinks it's ok to do this isn't going to see the light because of anything some random says on a train. They'll just dismiss her as a busybody (ironically, like many posts on here)and carry on. Which is why you should report this to the company with as much detail as you can, as it's the only way to stop this stupid and unprofessional behaviour.

LatteLady · 28/05/2026 22:12

Twenty years ago, I worked at KPMG, Colin Sharman was the managing partner... he would go ballistic with anyone discussing client business in the lift because you did not know who else was in the lift with you. This is the reason, also, back then if you were working on client business, you travelled first class with a privacy screen. It's basic commonsense, so yes, report it.

Goatsarebest · 28/05/2026 22:11

ManintheCity · 28/05/2026 21:57

My manager was aware of this and trusted me not to gossip. I was in a role where discretion was expected.

'Not to gossip' and 'descretion' is minimising what a data breach is. These are the norms in any organisation with any data, but you said it was specific data you shouldn't be privy to. That's a systems failure and needs to be reported and addressed. If you manager is doing that then fine, but it's not what you said.

Flyingintotheunknown · 28/05/2026 22:04

plsdontlookatme · 28/05/2026 22:03

Without even trying - because I'm not weird - I recently found that I could very easily see the argument a girl sitting in front of me was having over text with her boyfriend.

Yeah it’s easy to see with the layout of the seating on trains. Makes me paranoid lol

Flyingintotheunknown · 28/05/2026 22:03

MrsColinRobinson · 28/05/2026 22:01

She knows best apparently cos Beryl did her training in a nice chat, rather than the recorded training modules with tests to validate understanding conducted annually like every organisation in the UK 🙄

Haha sounds about right. Anyone who has had rigorous GDPR training and how to deal with confidential documents know that the responsibility is on them to keep that information out of the public eye. But according to her “training” it’s the passengers on the train who have the responsibility of addressing it lol

plsdontlookatme · 28/05/2026 22:03

Flyingintotheunknown · 28/05/2026 21:43

You’ll be surprised how many people peer over seats/ look through gaps on the train. I once caught someone sat behind me Ona train trying to read a WhatsApp conversation I was having with my bf

Without even trying - because I'm not weird - I recently found that I could very easily see the argument a girl sitting in front of me was having over text with her boyfriend.

MrsColinRobinson · 28/05/2026 22:01

Flyingintotheunknown · 28/05/2026 21:58

It is NOT the op’s responsibility as a member of public riding on a train to tap her on the shoulder and tell her they could see the information, anymore than it would be the responsibility of an elderly couple on the train off on a day out or a child passenger! Don’t be so ridiculous!

She knows best apparently cos Beryl did her training in a nice chat, rather than the recorded training modules with tests to validate understanding conducted annually like every organisation in the UK 🙄

ManintheCity · 28/05/2026 22:01

Rarely have I read so much self-righteous crap!

plsdontlookatme · 28/05/2026 22:00

There's no point intervening in the actions of people who are fundamentally stupid, careless, and selfish. It's a waste of time. Someone thick enough to be waving confidential info around on the train isn't going to have a data protection revelation from a stranger tapping them on the shoulder.

plsdontlookatme · 28/05/2026 21:58

Even working in events - so not especially sensitive personal data, just names and email addresses - I was SO careful if I was working on the train. This is ridiculous

MrsColinRobinson · 28/05/2026 21:58

Arlanymor · 28/05/2026 21:51

I know full well how serious data breaches are - I had to deal with a hospital data issue where the trust was fined to the tune of £250,000. All I have said is to address it at the time if you're someone who is remotely sensible. How can you argue with that logic? Then any legal fallout follows. Report after if you need to. But to just sit there and spy on someone and only post on here, rather than let the woman know at the time is honestly ridiculous. I'm not arguing against responsibilities, but you are rather proving that common sense isn't all that common.

Edited

Wow your arrogance knows no bounds.

Anyone who undertook and actually understood the training knows I'm correct. You're making yourself look ever so silly now

Flyingintotheunknown · 28/05/2026 21:58

Arlanymor · 28/05/2026 21:56

I didn't say it was the OP's responsibility. I was pointing out the fact that if she had just tapped her on the shoulder and said that information could be seen, then that would help negate the potential for it to be seen by others and/or misused. There is no child in this, you're just being silly now. Report after the event if you wish. But why is it so hard for you to understand that a heads up to someone would be better than just sitting there and doing nothing until after?

It is NOT the op’s responsibility as a member of public riding on a train to tap her on the shoulder and tell her they could see the information, anymore than it would be the responsibility of an elderly couple on the train off on a day out or a child passenger! Don’t be so ridiculous!

ManintheCity · 28/05/2026 21:57

Goatsarebest · 28/05/2026 21:44

Well you shouldn't. You should at least let those that have made you privy to the information know.

My manager was aware of this and trusted me not to gossip. I was in a role where discretion was expected.

plsdontlookatme · 28/05/2026 21:56

This is beyond parody - what a shit company. I would report them to their ombudsman or similar (depending on the sector)

Arlanymor · 28/05/2026 21:56

Flyingintotheunknown · 28/05/2026 21:49

A GDPR breach is a GDPR breach. It is not the op’s or any other member of the public riding on that train to have training on GDPR and how to address it just in case someone happens to have confidential information on full view. Are you seriously telling me that the op, along with other members of the public on that train should have the responsibility of addressing the issue with the person who is breaching the data? Seriously? What if it happened to be a child passenger who saw it instead of the op? Would the onus be then on the child to address this with HR woman? I think not!

I didn't say it was the OP's responsibility. I was pointing out the fact that if she had just tapped her on the shoulder and said that information could be seen, then that would help negate the potential for it to be seen by others and/or misused. There is no child in this, you're just being silly now. Report after the event if you wish. But why is it so hard for you to understand that a heads up to someone would be better than just sitting there and doing nothing until after?

Arlanymor · 28/05/2026 21:51

MrsColinRobinson · 28/05/2026 21:47

You're so wrong it's not worth trying reason with you, but I hope for your organisations sake you aren't able to access data out of a secure environment. Data breaches are a huge issue taken extremely seriously as they can lead to enormous fines.

But keep arguing against many repeating the actual responsibilities under the legislation.

I know full well how serious data breaches are - I had to deal with a hospital data issue where the trust was fined to the tune of £250,000. All I have said is to address it at the time if you're someone who is remotely sensible. How can you argue with that logic? Then any legal fallout follows. Report after if you need to. But to just sit there and spy on someone and only post on here, rather than let the woman know at the time is honestly ridiculous. I'm not arguing against responsibilities, but you are rather proving that common sense isn't all that common.

Flyingintotheunknown · 28/05/2026 21:49

Arlanymor · 28/05/2026 21:45

Not once have I said it's fine for the person to be doing this on a train, have I? No, not once. But if you have done proper GDPR training then rather than post online and ask others about it, you would address the person directly to halt the potentiality for information to be seen by people who shouldn't see it. You would do it on a hospital ward, you would do it in a bank. Halt it at at the source. Up to you if you want to report it afterwards, but the obvious thing to do, if you are trained, is to make the person aware. That's GDPR 101.

A GDPR breach is a GDPR breach. It is not the op’s or any other member of the public riding on that train to have training on GDPR and how to address it just in case someone happens to have confidential information on full view. Are you seriously telling me that the op, along with other members of the public on that train should have the responsibility of addressing the issue with the person who is breaching the data? Seriously? What if it happened to be a child passenger who saw it instead of the op? Would the onus be then on the child to address this with HR woman? I think not!

Denim4ever · 28/05/2026 21:49

I was on a train recently and a teacher was doing a virtual staff meeting discussing strategies for pupils. With camera off, but we could all hear her side of the conversation. She was really loud and it was all about really personal specific pupil problems.

Goatsarebest · 28/05/2026 21:48

Soonbbbqweather · 28/05/2026 21:33

Not quite relevant to GDPR but nosey Parker’s, DD when studying became aware of a bloke who would look over her shoulder at the station every morning at whatever she was reading. Getting quite fed up with it, as she was studying for a medical qualification, she located a photo of a severely diseased male penis! His reaction the next day resulted in him never standing near her again!

And I concur with the other posters who advised it should have been raised at the time. No she shouldn’t have been doing it but also was entitled to assume nobody would peer through the seats and read her screen. We always used to put a warning page in confidential papers regarding awareness of reading them in public.

If she has confidential information she is not entitled to assume nobody would look if she access it in public.

MrsColinRobinson · 28/05/2026 21:47

Arlanymor · 28/05/2026 21:28

I have done the training and thankfully a normal person delivered it to me and who made clear that if you are concerned you can talk to the person directly first. Which is much more effective in terms of protecting data than letting a whole train journey go by first. If you care about GDPR you tell the person at the time. It's not shifting responsibility, it's dealing with the situation in the moment. Like an adult.

Edited

You're so wrong it's not worth trying reason with you, but I hope for your organisations sake you aren't able to access data out of a secure environment. Data breaches are a huge issue taken extremely seriously as they can lead to enormous fines.

But keep arguing against many repeating the actual responsibilities under the legislation.

Swipe left for the next trending thread