Skip to main content
Physical Records Under GDPR: A Security Engineer's Field GuideSecurity & Breach Notification
5 min readFor Records & Information Managers

Physical Records Under GDPR: A Security Engineer's Field Guide

Your team has invested in encryption, access controls, and cloud security posture management. But what about the filing cabinets in the basement and the boxes in off-site storage? The Data Protection Commission's €645,000 fine against the Health Service Executive proves that physical records remain a compliance risk you can't afford to ignore.

Scope: What This Guide Covers

This field guide addresses the physical storage and security requirements for paper records containing personal data under GDPR. It's designed for security engineers responsible for implementing technical and organizational measures across both digital and physical environments.

In scope:

  • Physical storage facilities (on-site and third-party)
  • Paper medical records, personnel files, and archived documents
  • Access controls for physical spaces
  • Environmental protections for stored records

Out of scope:

  • Digital document security (covered separately)
  • Records retention schedules (a governance function)
  • Destruction procedures for physical media

Key Concepts and Definitions

Physical processing operations: Any collection, storage, consultation, or destruction of paper records falls under GDPR's definition of processing (Article 4(2)). Your obligations don't change based on format.

Controller responsibility: You remain the controller for physical records. You can't outsource accountability by moving boxes to a third-party warehouse. If you use external storage, that provider acts as your processor, and Article 28 processor requirements apply.

Appropriate technical and organizational measures: Article 32 requires security "appropriate to the risk." For physical records, this means environmental controls, access restrictions, and integrity monitoring that match the sensitivity of the data you're storing.

Requirements Breakdown

Article 5(1)(f): Security of Processing

Obligation: Process personal data in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

Physical record implications:

  • Locked facilities with controlled access
  • Environmental protections (fire suppression, moisture control, pest management)
  • Intrusion detection and monitoring
  • Regular integrity checks to verify records haven't been damaged or accessed without authorization

Article 32: Security of Processing (Detailed Requirements)

Obligation: Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

Specific measures for physical storage:

  • Access control systems (badge readers, sign-in logs, escort requirements)
  • Physical barriers (locked doors, cages, restricted areas)
  • Surveillance systems where proportionate to the risk
  • Environmental monitoring (temperature, humidity, water detection)
  • Documented access procedures and authorization lists

Article 33: Personal Data Breach Notification

Obligation: Notify your supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to rights and freedoms.

Physical breach scenarios:

  • Unauthorized access to storage facilities (as occurred at St. Loman's Hospital and St Conal's Hospital)
  • Loss or theft of records during transport
  • Environmental damage (flood, fire) affecting record integrity
  • Discovery that records were improperly disposed of

Implementation Guidance

Integrating Physical Storage Into Your Risk Framework

Start with a records inventory. You can't secure what you don't know exists. Map every location where paper records are stored, including:

  • Active file rooms in operational facilities
  • Basement archives and storage closets
  • Off-site commercial storage facilities
  • Records held by processors (medical transcription services, scanning vendors)

Classify these records using the same sensitivity framework you apply to digital data. Medical records, personnel files, and documents containing special category data (Article 9) require stronger physical protections than general correspondence.

Access Control Implementation

Minimum viable controls:

  • Physical locks on storage rooms (deadbolts, not spring latches)
  • Access logs recording who entered and when
  • Defined authorization lists updated quarterly
  • Escort requirements for unauthorized personnel

Enhanced controls for high-risk data:

  • Electronic access control systems with audit trails
  • Dual-control requirements (two authorized persons required for access)
  • Video surveillance with retention periods matching your breach detection window
  • Intrusion detection systems with 24/7 monitoring

Environmental Protection Standards

Your records need protection from physical deterioration, not just unauthorized access.

Essential environmental controls:

  • Temperature: 18-22°C (65-72°F)
  • Relative humidity: 30-50%
  • Fire suppression systems (dry chemical or gas-based for paper storage)
  • Water detection sensors in basements and ground-level storage
  • Pest control programs with documentation

Processor Due Diligence for Third-Party Storage

If you use commercial storage facilities, Article 28 requires written contracts specifying the processor's security obligations. Don't accept generic terms.

Required contract provisions:

  • Specific security measures (access controls, environmental protections, surveillance)
  • Your right to audit the facility
  • Breach notification procedures with defined timelines
  • Data return or destruction protocols
  • Sub-processor restrictions

Pre-contract assessment:

  • Tour the facility before signing
  • Review their physical security certifications (ISO 27001 if applicable)
  • Check their breach history and incident response capabilities
  • Verify insurance coverage for data loss or damage

Common Pitfalls

Disused facilities: The HSE case involved former psychiatric hospitals where records remained after the facilities closed. When you decommission a building, your security obligations for any records remaining inside don't disappear. Either relocate the records to a secured facility or implement temporary security measures until proper destruction.

Inadequate breach detection: Unauthorized access at St. Loman's Hospital and St Conal's Hospital was discovered when intruders posted videos to social media. You need proactive monitoring, not discovery by public embarrassment. Regular facility inspections and intrusion detection systems provide earlier warning.

Split responsibility: Don't assume facilities management owns physical security while you handle "cyber." As the security engineer, you're responsible for ensuring appropriate technical and organizational measures across all processing operations. Work with facilities teams, but verify their controls meet GDPR standards.

Overconfidence in locks: A locked door isn't sufficient if the building has broken windows, accessible roof hatches, or other entry points. Conduct regular physical penetration assessments.

Ignoring records in transition: Records moving between facilities, to scanning vendors, or to destruction services face elevated risk. Require chain-of-custody documentation, GPS tracking for transport vehicles, and verification of delivery or destruction.

Quick Reference Table

Requirement Article Physical Control Examples Verification Method
Confidentiality 32(1)(b) Locked storage, access logs, escort policies Quarterly access log review, unannounced facility checks
Integrity 32(1)(b) Environmental controls, regular inspections Monthly condition assessments, environmental monitoring logs
Availability 32(1)(b) Fire suppression, offsite backups for critical records Annual system testing, backup inventory verification
Breach detection 32(1)(d) Intrusion alarms, surveillance systems, inventory audits Test alarm response quarterly, review surveillance coverage
Processor oversight 28 Contractual security obligations, audit rights Annual processor audits, contract compliance reviews
Breach notification 33 Documented incident response procedures Tabletop exercises, notification template testing

Your physical records deserve the same security rigor you apply to your cloud infrastructure. The HSE's €645,000 fine demonstrates that supervisory authorities will hold you accountable for every format in which you process personal data.

You Might Also Like