How to treat E-mail services as a means of storing Personal data?

Work for a small company, engaged in the professional development of teachers. Often teachers, and the students themselves, sent by e-mail (Yandex) copy of the passport, for the purchase of tickets, negotiation of contracts, etc.

Based on this manual, I determined the class Q3, 3 category, the volume of data is small.

In connection with this question, we have 10 employees have access to a single post where all of this data. Is it enough to take subscription of the "notice to disclose" passwords mail, and prohibit downloading applications containing personal data on a work PC (since the service allows you to view scans of your passport online).

Should immediately remove the data from the mail and keep a copy for example on a separate computer accessible only via the local network, well, etc.
