Privacy violation and data protection

The senior manager of the IT team possesses very sensitive personal information that he must send to one of his employees. He fails to take the proper technical measures to protect this personal data e.g. medical information, social security numbers, payment information, etc., and sends the file via unencrypted e-mail. Is this type of disrespect toward personal information a violation of privacy?

