Personal data can be held in the cloud, on a laptop or in an organised paper file. Moving a record from paper to digital storage does not remove your GDPR responsibilities.
The misconception
“We moved everything to the cloud, so we’re covered by GDPR. Files on our local computer and in our filing cabinet do not count.”
The location of a record does not decide whether GDPR applies. What matters is whether personal data is being processed in a way covered by the regulation.
What the law actually says
The GDPR applies to personal data processed wholly or partly by automated means. It also applies to non-automated processing where personal data forms part of, or is intended to form part of, a filing system. A filing system is a structured set of personal data accessible according to specific criteria, such as customer files arranged by name or guest cards organised by departure date.
An isolated paper note does not automatically become a filing system just because it contains a name. Other applicable confidentiality or local rules may still matter. Once you scan a note or place it in a structured file, assess how GDPR applies to that processing.
Where personal data actually lives in your business
On paper
- Personnel files in binders
- Customer cards and guest registration cards in organised folders
- Signed contracts and correspondence
- Meeting notes filed by client or employee
On local systems
- Spreadsheets on a laptop or office computer
- Documents on a local server
- Downloaded email archives
- Scanned records in folders or on shared drives
In the cloud
- CRM and booking systems
- Hosted email
- Accounting software
- HR platforms
In less obvious places
- Work messages on company phones
- Customer service recordings
- CCTV footage
- Location data from company vehicles
Assess each source according to the information it contains and how it is used.
What you need to do
1. Inventory everything
Include cloud services, local devices and relevant paper filing systems when mapping processing activities. Identify the purpose, access and retention rule for each set of records.
2. Secure paper files
Store records appropriately and restrict access. Dispose of paper securely when no longer needed. If you replace a paper file with a reliable scan, check whether a local rule or genuine evidentiary need requires the original before destroying it.
3. Don’t forget local devices
Control access to computers and shared folders, protect devices with appropriate security measures, and include important local files in your backup and recovery arrangements. Apply the same care to scanned documents.
4. Clean up old archives
Review paper and digital archives regularly. Check applicable local or sector-specific retention requirements, then securely dispose of information that is no longer needed. Moving an old paper archive onto a computer does not start a new retention period automatically.
GDPRWise helps you document processing across digital systems and physical files.