Skip to main content
Paper Records Don't Need Digital SecuritySecurity & Breach Notification
5 min readFor Records & Information Managers

Paper Records Don't Need Digital Security

The conventional wisdom says GDPR compliance is a technology problem. You need encryption, access controls, cloud security frameworks, and incident response playbooks built for ransomware and phishing. Your DPO's job description probably mentions "cybersecurity" more than "filing cabinets."

This focus has left a blind spot the size of a shipping container.

Paper Records: The Overlooked Risk

GDPR doesn't distinguish between digital and paper records. Article 5(1)(f) requires you to process personal data "in a manner that ensures appropriate security." Article 32 demands "appropriate technical and organisational measures" without specifying that those measures must involve firewalls or multi-factor authentication.

Yet most compliance teams have built their programs around digital threats. You've mapped your cloud vendors, implemented data loss prevention tools, and run exercises for ransomware scenarios. Meanwhile, psychiatric records sit in mold-infested basements, accessible to anyone with a smartphone and a willingness to trespass.

The Irish Data Protection Commissioner's $750,000 fine against Ireland's Health Service Executive highlights this gap. The breaches didn't involve sophisticated attackers. They involved individuals walking into abandoned hospital facilities and filming disintegrating medical records for social media. The DPC's site inspections found documents "contaminated by animal droppings, covered in rubble or detritus, rotting due to the storage environment or water damaged." Records stored in disused bathrooms, shipping containers, rooms without functioning lighting.

This wasn't a technology failure. It was an organisational one.

The Evidence of Neglect

The HSE case shows what happens when you treat paper as a legacy problem that will solve itself through digitization. The DPC discovered the issues weren't isolated but systemic failures across multiple facilities. During inspections of 12 HSE sites, investigators found "storage areas in such profound disarray and neglect that the records contained within them could not be deemed to be filed in any organized or accessible manner."

The violations stacked up under multiple GDPR provisions. The HSE failed Article 5(1)(e)'s requirement to retain data only as long as necessary. They violated Article 32's security obligations by failing to restrict access and protect records from environmental damage. They breached Article 33's notification requirements by missing the 72-hour breach reporting window.

The DPC noted as an aggravating factor that the HSE had "committed similar previous infringements concerning the lack of appropriate security measures and the loss of control over personal data contained in paper healthcare records." This wasn't a one-off oversight. It was a pattern of deprioritizing physical security.

Britain's Information Commissioner's Office reported 131 breaches in early 2026 tied to incorrect disposal, loss, or theft of physical paperwork. Not 131 total breaches. Just the subset involving paper. The number has declined from 319 such incidents in late 2019, but the risk persists at scale.

Steps to Secure Paper Records

Start with an audit that treats paper records as seriously as your cloud infrastructure. The DPC ordered the HSE to "carry out a complete audit of all storage facilities where the HSE stores and retains paper files." You need the same inventory discipline for filing cabinets that you apply to databases.

Document what you're storing, where it's located, who has access, and why you still need it. If you can't answer those questions for a box of personnel files from 2003, you're violating Article 5(1)(e). Retention schedules apply to paper just as strictly as they apply to backup tapes.

Implement physical access controls that match the sensitivity of the data. Medical records require locked facilities with restricted key access and environmental controls that prevent mold, water damage, and pest contamination. Your risk assessment under Article 32 should evaluate whether the storage environment itself creates a security vulnerability.

Create a disposal process with the same rigor you'd apply to decommissioning a server. The DPC required the HSE to "expunge all unnecessary paper files" and implement a "robust" system to record and trace all stored data. You need documented procedures for shredding or pulping, processor contracts if you're outsourcing destruction, and certificates of destruction that prove compliance.

Test your controls. The DPC ordered the HSE to implement policies and procedures to verify compliance with paper record storage practices. That means periodic audits, not just assuming the filing room is fine because nobody's complained.

For organizations with remote work, recognize that paper security now extends into employees' homes. You can't assume staff have secure storage, access to shredders, or training on handling confidential documents outside the office. Your transparency obligations under Articles 13 and 14 should cover what employees can and can't do with printed materials.

Balancing Digital and Physical Security

Digital security deserves its prominence in compliance programs. The volume of personal data processed electronically dwarfs what most organizations store on paper. Cyber incidents can expose millions of records in seconds, while paper breaches typically involve smaller datasets and require physical access.

The sophistication of digital threats also justifies the investment in technical controls. Ransomware, supply chain attacks, and credential stuffing require specialized defenses that paper records don't need. Your security budget should still prioritize the risks that affect the most data subjects.

But treating GDPR as primarily a technology challenge creates organizational blind spots. The HSE case demonstrates what happens when you assume paper is someone else's problem or a legacy issue that will age out naturally. Records don't digitize themselves, and they don't stop being personal data just because they're moldering in a basement.

The real lesson isn't that you should shift resources away from cybersecurity. It's that Article 32's requirement for "appropriate technical and organisational measures" means both words matter equally. You need the organisational discipline to know what paper you're holding, where it's stored, and how you'll dispose of it. Without that foundation, your technical controls are protecting only part of your processing activities.

The DPC's enforcement action should prompt a simple question: when did you last inspect your filing rooms with the same scrutiny you apply to your firewall logs?

You Might Also Like