Call us 01603 513 271
Search

Can’t find what you’re looking for? Get in touch today.

Top results for ''

View all ()

No results for ''

Please try searching again with a different term, visit our FAQs page or get in touch.

Product has been added to your cart

View Cart
4.9/5

Businesses are still mishandling paperwork and devices containing personal information

GDPR came into effect in the UK in May 2018. Years have passed, yet hundreds of UK businesses are still breaching data by not securing paperwork and devices.

The Data Security Incident Trends report published by the Information Commissioner’s Office indicates that there were 20,409 data breaches reported between 2019 and 2025, caused by:

  • The incorrect disposal of paperwork

  • The incorrect disposal of hardware

  • The loss or theft of paperwork or data left in insecure locations

  • The loss or theft of devices containing personal data.

Of these, 11,525 of the organisations that suffered the breaches have had an investigation against them pursued or informal action taken. The highest number of these types of incidents was reported by the health sector, followed by the education and childcare sector. Some of the most sensitive personal information available is held by these two sectors, so this is a cause for great concern.

2019 - 2025: Incidents by sector.

Sector

Number of incidents

Central Government

497

Charitable and voluntary

1,946

Education and childcare

3,922

Finance, insurance and credit

884

General business

820

Health

3,943

Justice

985

Land or property services

630

Legal

1,805

Local government

1,980

Marketing

25

Media

35

Membership association

208

Online Technology and Telecoms

127

Political

30

Regulators

52

Religious

121

Retail and manufacture

693

Social care

1,314

Transport and leisure

326

Unknown

17

Utilities

19

The table above shows the data security incidents by sector between 2019-2025, where the cause of the breach included the incorrect disposal of paperwork or hardware, the loss/theft of paperwork or data left in insecure locations, and the loss/theft of devices containing personal data.

With GDPR now firmly ingrained in the UK business landscape, it raises two questions. First, why is this still happening? The second is how can we prevent it?

The BSIA's YouGov study on confidential information disposal

A 2023 study by YouGov, commissioned by the BSIA, revealed some shocking findings. One of the key findings was that 31% of microbusinesses, 19% of small businesses, 8% of medium businesses, and 3% of large businesses surveyed have no waste stream in place for paper - neither for recycling nor confidential documents. This raises the question: Is confidential paperwork remaining unprotected despite the obligation for businesses to keep personal data secure?

Another key finding was that many decision makers in businesses are not aware of the industry standards that apply when securely destroying confidential information - specifically GDPR and EN 15713 security shredding standards. This lack of awareness was higher in businesses with a smaller turnover, indicating that a lack of expertise could be due to a lack of resources. Interestingly, the understanding of these standards varied significantly by industry, and the medical and health service sector organisations surveyed reported having the overall highest amount of awareness despite suffering the most breaches in the ICO's incident trends reports. A reason for these somewhat contradictory findings could be the sheer scale of the healthcare sector, with the NHS alone thought to be the largest employer in the whole of Europe.

So, how can we improve knowledge around GDPR and secure destruction standards, and reduce the risk of breaches?

Improve employee awareness of GDPR

Data breaches often occur because of human error. Ensuring GDPR is on your employees’ minds is the best way to avoid human error occurring. One way to do this is by providing GDPR training. At Shred Station, every employee is trained on GDPR and its core principles as part of their onboarding. We also provide training on EN 15713 security shredding standards. However, as time goes on, we also believe it’s important to provide bite-sized refresher training to ensure these principles are not forgotten. One platform we highly recommend is uSecure. This platform has an extensive, ready-built course library including training in all key areas of information security. It also has the ability for you to create custom courses. You can even use the platform to conduct phishing tests, identifying any employees who may need extra help in recognising other information security red flags.

Another way to get employees thinking about GDPR is by using dedicated bins for confidential waste. This is especially important for employees who process a lot of paperwork. By positioning confidential waste bins around your premises and displaying awareness posters about what can and cannot be placed inside them, you can keep document and device security at the forefront of your employees’ minds.

Implement a ‘Shred Everything’ policy.

Implementing a ‘Shred Everything’ policy will reduce the risk of human error. Destroying all paper or devices you no longer need will prevent employees from making the wrong judgement call when it comes to whether documents or devices should be treated as confidential. It will also help to ensure you are not keeping any personal information longer than is necessary. This is another requirement of GDPR (Principle E).

You can further improve the security of your unwanted devices and documents by outsourcing their destruction. Reputable and fully accredited shredding service suppliers will be able to provide regular or one-off services to suit you. The right company will provide the option of on-site shredding or off-site, giving you the option to witness the destruction as it occurs or to simply have it taken away for destruction at a secure facility. By using a shredding service, you entrust your confidential materials to the safe hands of security-vetted personnel and ensure you receive proof of destruction. This proof of destruction will serve as evidence of compliance with GDPR.