Skip to content
Security calendar_today Updated: 24 September 2026 schedule 4 min read

Data Security for Paper Documents

verified Last reviewed 24 September 2026 · GDPRWise legal team

The GDPR also applies to personal data kept in organised paper files. This article explains how to protect physical documents, including when you replace paper copies with electronic records.

summarize Key Takeaways
  • check_circle Protect paper files containing personal data against unauthorised access, loss and damage.
  • check_circle Restrict access and store sensitive records securely; choose measures appropriate to the risk.
  • check_circle Securely destroy paper you no longer need, including originals that have been properly digitised when no separate reason requires their retention.
  • check_circle Apply retention and security measures to electronic scans as well as paper records.

The GDPR also applies to personal data kept in organised paper files. This article explains how to protect physical documents, including when you replace paper copies with electronic records.

Don’t forget your paper files

A filing cabinet containing customer or personnel records can be part of your personal-data processing. Paper on an open desk can be seen or removed just as an unprotected digital file can be opened or copied. Map and protect both.

Which paper documents contain personal data?

Examples include:

  • Personnel files, employment contracts, payslips and performance reviews
  • Customer records, registration cards, contracts and correspondence
  • Invoices, bank statements and tax documents that identify individuals
  • Complaints, legal correspondence and case files
  • Medical records and other documents containing health information

A document’s contents and how it is used matter. Paper records organised so that information about people can be found are within the GDPR’s scope.

Practical security measures

Storage

  • Keep documents in lockable cabinets or rooms where appropriate to the sensitivity and volume of the records.
  • Limit access to people who need the information for their work.
  • Organise and label files so authorised staff can find, review and dispose of records without leaving them exposed.

Clean desk policy

  • Do not leave personal data unattended in public or shared spaces.
  • Put files away when you leave your workspace.
  • Keep incoming post with personal data away from an open reception desk.

Destruction

  • Shred or securely dispose of documents when they are no longer needed, taking account of applicable local or sector-specific retention rules.
  • Use a suitable cross-cut shredder or a reputable destruction provider for larger volumes; keep evidence of disposal where appropriate.
  • Include duplicate printouts, drafts and notes in the disposal process.
  • If you digitise a paper original, first check that the scan is complete, readable, properly stored and accessible to authorised staff. GDPR does not generally require you to keep both versions. You can normally securely destroy the paper original if no applicable legal, contractual or evidentiary reason requires it. Protect the scan and keep it only for its justified retention period.

Transport

  • Use sealed packaging and a delivery method suited to the sensitivity of the material. For important documents containing personal data, use registered post with tracking or a trusted courier.
  • Do not leave files unattended in vehicles or public places.
  • Confirm that the intended recipient can safely receive the material.

Don’t forget to document

Record where paper and scanned files are kept, who can access them, how they are transferred or destroyed, and which retention periods apply. Check local or sector-specific rules before setting those periods. If a paper archive is converted to digital form, document how you verify scan quality, secure the new files and dispose of originals.

auto_awesome Document your security measures

GDPRWise helps you document security measures for both physical and digital records.

Share share LinkedIn mail Email
GW
GDPRWise Editorial

This article was written by the GDPRWise team and reviewed by our privacy experts. We regularly review our content for accuracy and legal correctness.