What Does “Appropriate Security” Mean Under UK GDPR?
Article 5(1)(f) of UK GDPR — the integrity and confidentiality principle — requires that personal data be “processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.”
Article 32 elaborates on this, requiring organisations to implement measures “appropriate to the risk”. This risk-based approach means there is no single prescribed checklist. A GP surgery holding patient records faces different risks to a florist holding customer email addresses, and their security measures should reflect that difference.
The ICO’s guidance at ico.org.uk sets out a practical framework for thinking about appropriate security, structured around technical and organisational measures. Both categories are required — technical controls alone are insufficient if staff are not trained to use them correctly.
Technical Measures to Keep Data Secure
Technical measures are controls implemented in your systems and infrastructure. Key examples include:
Encryption
Encrypting data at rest (on devices and servers) and in transit (across networks) significantly limits the impact of unauthorised access. If an encrypted laptop is stolen, the data on it is not readily accessible without the encryption key. The ICO consistently cites encryption as a baseline expectation for portable devices holding personal data.
Access controls
Role-based access controls ensure that staff can only access the personal data they need to do their jobs. Strong authentication — ideally multi-factor authentication — reduces the risk of unauthorised access through compromised credentials.
Patching and updates
Unpatched software is one of the most common routes through which attackers gain access to personal data. A systematic approach to applying security patches promptly is a basic but important technical measure.
Network security
Firewalls, intrusion detection systems and secure Wi-Fi configurations reduce the risk of external attackers accessing your systems.
Secure data destruction
When a device reaches end of life, the data it holds must be securely destroyed. Certified data wiping (overwriting all sectors to a recognised standard) or physical destruction of the storage media are the accepted methods. Standard file deletion is not sufficient — data deleted in this way remains recoverable using freely available tools.
Organisational Measures to Keep Data Secure
Organisational measures are policies, processes and practices that govern how people handle data.
Staff training
Human error is responsible for a significant proportion of personal data breaches. Staff must understand what personal data they handle, why it is sensitive, and what to do if they suspect a breach. Regular training — not a one-off induction — is expected.
Data retention policies
A documented retention policy specifying how long each category of data is kept — and how it is deleted when the retention period expires — directly supports the storage limitation principle and reduces the volume of data at risk.
IT asset disposal procedures
A formal procedure for retiring hardware should specify that all devices are wiped or destroyed before leaving the organisation’s control, and that a certificate of data destruction is obtained and retained. Ad hoc disposal without a process is a common source of breaches.
Supplier and vendor management
Where personal data is processed by third-party suppliers, data processing agreements must be in place. You should assess your suppliers’ security practices and ensure they are contractually required to meet appropriate standards.
Incident response plans
If a breach does occur, you need a documented procedure for identifying it, containing it, assessing the risk to individuals, and reporting it to the ICO within 72 hours where required. Practising this procedure through tabletop exercises significantly improves the response.
Security Measures by Stage of the Data Lifecycle
| Lifecycle stage | Key technical measure | Key organisational measure |
|---|---|---|
| Collection | Encrypted transfer (HTTPS/TLS) | Privacy notice; minimal data collection |
| Storage | Encryption at rest; access controls | Retention policy; regular audits |
| Sharing | Encrypted transmission; secure portals | Data processing agreements |
| Deletion | Certified data wiping or physical destruction | IT asset disposal procedure; certificate of destruction |
The Relationship Between Security and Accountability
Article 5(2) of UK GDPR requires organisations to be able to demonstrate that they are complying with the security principle, not merely assert it. This means keeping records: training completion records, security audit logs, supplier contracts, and — crucially — certificates of data destruction for retired hardware.
The ICO expects organisations to maintain documentation proportionate to their size and the risk of their processing activities. Larger organisations and those processing special category data (such as health records or criminal conviction data) will be expected to have more comprehensive documentation.
Where Disposal Fits Into Your Security Programme
Secure disposal is a security measure, not an afterthought. Under UK GDPR, an organisation that fails to securely destroy data on retired hardware has failed the security principle. If that data is subsequently accessed by an unauthorised party, a personal data breach has occurred and must be reported to the ICO.
We provide certified data destruction for businesses of all sizes, with a certificate issued for every device. For devices that can be refurbished after wiping, we pass them free to digitally-excluded Londoners — combining your compliance with a positive social outcome.
Learn more about what certified data destruction involves on our data destruction service page, and read our article on GDPR and old IT equipment for guidance on the disposal process.
To discuss building secure disposal into your IT lifecycle management, contact Recycle4Charity.