Skip to content
All posts

GDPR and Your Devices: What UK SMEs Need to Know

Most UK SMEs have done some work on GDPR. Privacy policies, data processing agreements, maybe some staff training. But there's one area that often gets overlooked: your devices.

Every laptop, phone, and tablet in your business is potentially holding personal data. And how you manage, secure, and eventually dispose of those devices has direct implications for your GDPR compliance.

Here's what you need to know.

 

What GDPR says about devices

GDPR requires organisations to implement "appropriate technical and organisational measures" to protect personal data. For devices, that means:

  • Encryption on all devices that hold personal data

  • Strong access controls (passwords, biometrics, screen locks)

  • The ability to remotely wipe a lost or stolen device

  • Secure disposal when a device reaches end of life

  • A clear record of what data is held where

These aren't nice-to-haves. They're part of your legal obligation as a data controller.

 

The risks of getting it wrong

A lost or stolen device that isn't encrypted is a reportable data breach. If personal data is on it, e.g. customer details, employee records, financial information, you may be required to notify the ICO within 72 hours.

ICO fines for UK organisations can run into the thousands or even millions of pounds for serious breaches. But even beyond fines, the reputational damage of a publicly reported breach can be far more costly for a small business.

 

The device disposal problem

One of the most commonly overlooked GDPR obligations relates to device disposal. When a laptop, phone, or tablet reaches end of life, you can't just factory reset it and send it for recycling. A factory reset doesn't securely erase data - it just removes the pointers to it.

Proper data destruction requires certified wiping software or physical destruction, with documentation to prove it happened. Without that audit trail, you can't demonstrate compliance.

 

Building compliance into your device management

The good news is that when your device lifecycle management is set up properly, GDPR compliance largely takes care of itself. Encryption is standard. Remote wipe is built in. Disposal is handled with certification.

With Equipped, GDPR-aligned device management is baked in. If you're not confident that your current device setup meets your legal obligations, let's have a conversation...before a problem forces the issue.