← Blog ·

How to Keep Data Secure Under GDPR: Practical Steps for UK Businesses

Keeping data secure under GDPR means applying appropriate technical and organisational measures at every stage of the data lifecycle — from collection through to deletion and device disposal. UK GDPR Article 5(1)(f) does not prescribe specific technologies, but it does require that the measures chosen are proportionate to the risk of the data being processed.

How to Keep Data Secure Under GDPR: Practical Steps for UK Businesses

What Does “Appropriate Security” Mean Under UK GDPR?

Article 5(1)(f) of UK GDPR — the integrity and confidentiality principle — requires that personal data be “processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.”

Article 32 elaborates on this, requiring organisations to implement measures “appropriate to the risk”. This risk-based approach means there is no single prescribed checklist. A GP surgery holding patient records faces different risks to a florist holding customer email addresses, and their security measures should reflect that difference.

The ICO’s guidance at ico.org.uk sets out a practical framework for thinking about appropriate security, structured around technical and organisational measures. Both categories are required — technical controls alone are insufficient if staff are not trained to use them correctly.

Technical Measures to Keep Data Secure

Technical measures are controls implemented in your systems and infrastructure. Key examples include:

Encryption
Encrypting data at rest (on devices and servers) and in transit (across networks) significantly limits the impact of unauthorised access. If an encrypted laptop is stolen, the data on it is not readily accessible without the encryption key. The ICO consistently cites encryption as a baseline expectation for portable devices holding personal data.

Access controls
Role-based access controls ensure that staff can only access the personal data they need to do their jobs. Strong authentication — ideally multi-factor authentication — reduces the risk of unauthorised access through compromised credentials.

Patching and updates
Unpatched software is one of the most common routes through which attackers gain access to personal data. A systematic approach to applying security patches promptly is a basic but important technical measure.

Network security
Firewalls, intrusion detection systems and secure Wi-Fi configurations reduce the risk of external attackers accessing your systems.

Secure data destruction
When a device reaches end of life, the data it holds must be securely destroyed. Certified data wiping (overwriting all sectors to a recognised standard) or physical destruction of the storage media are the accepted methods. Standard file deletion is not sufficient — data deleted in this way remains recoverable using freely available tools.

Organisational Measures to Keep Data Secure

Organisational measures are policies, processes and practices that govern how people handle data.

Staff training
Human error is responsible for a significant proportion of personal data breaches. Staff must understand what personal data they handle, why it is sensitive, and what to do if they suspect a breach. Regular training — not a one-off induction — is expected.

Data retention policies
A documented retention policy specifying how long each category of data is kept — and how it is deleted when the retention period expires — directly supports the storage limitation principle and reduces the volume of data at risk.

IT asset disposal procedures
A formal procedure for retiring hardware should specify that all devices are wiped or destroyed before leaving the organisation’s control, and that a certificate of data destruction is obtained and retained. Ad hoc disposal without a process is a common source of breaches.

Supplier and vendor management
Where personal data is processed by third-party suppliers, data processing agreements must be in place. You should assess your suppliers’ security practices and ensure they are contractually required to meet appropriate standards.

Incident response plans
If a breach does occur, you need a documented procedure for identifying it, containing it, assessing the risk to individuals, and reporting it to the ICO within 72 hours where required. Practising this procedure through tabletop exercises significantly improves the response.

Security Measures by Stage of the Data Lifecycle

Lifecycle stage Key technical measure Key organisational measure
Collection Encrypted transfer (HTTPS/TLS) Privacy notice; minimal data collection
Storage Encryption at rest; access controls Retention policy; regular audits
Sharing Encrypted transmission; secure portals Data processing agreements
Deletion Certified data wiping or physical destruction IT asset disposal procedure; certificate of destruction

The Relationship Between Security and Accountability

Article 5(2) of UK GDPR requires organisations to be able to demonstrate that they are complying with the security principle, not merely assert it. This means keeping records: training completion records, security audit logs, supplier contracts, and — crucially — certificates of data destruction for retired hardware.

The ICO expects organisations to maintain documentation proportionate to their size and the risk of their processing activities. Larger organisations and those processing special category data (such as health records or criminal conviction data) will be expected to have more comprehensive documentation.

Where Disposal Fits Into Your Security Programme

Secure disposal is a security measure, not an afterthought. Under UK GDPR, an organisation that fails to securely destroy data on retired hardware has failed the security principle. If that data is subsequently accessed by an unauthorised party, a personal data breach has occurred and must be reported to the ICO.

We provide certified data destruction for businesses of all sizes, with a certificate issued for every device. For devices that can be refurbished after wiping, we pass them free to digitally-excluded Londoners — combining your compliance with a positive social outcome.

Learn more about what certified data destruction involves on our data destruction service page, and read our article on GDPR and old IT equipment for guidance on the disposal process.

To discuss building secure disposal into your IT lifecycle management, contact Recycle4Charity.

Blog

Frequently asked questions

UK GDPR Article 32 does not specify a fixed list of technologies, but it does require measures appropriate to the risk. The ICO considers encryption of personal data (particularly on portable devices), access controls, multi-factor authentication and secure data destruction at end of life to be baseline expectations for most organisations.

Encryption is an important measure during active use, but it does not substitute for certified data destruction at disposal. When a device is retired, the storage media should be wiped to a recognised standard or physically destroyed. A certificate of data destruction provides the accountability evidence UK GDPR requires.

Training should cover what personal data the organisation holds, why it is sensitive, how to handle it correctly, how to recognise and report a suspected breach, and the organisation's specific procedures — including how to handle devices securely. Training should be repeated regularly, not delivered as a single induction event.

A data retention policy documents how long each category of personal data is held and what happens to it when the retention period expires. UK GDPR's storage limitation principle (Article 5(1)(e)) requires that data not be kept longer than necessary. A written policy supports both compliance and accountability.

Yes. The security principle applies to all personal data, including data stored on physical devices — laptops, mobile phones, USB drives, servers, photocopiers and backup tapes. Secure physical destruction or certified data wiping is required when these devices are no longer needed.

Need secure IT disposal in London?

Certified data destruction and WEEE recycling — with refurbished devices going to people who need them.