
The Most Common Mistakes Businesses Make When Disposing of Confidential Documents
Ask most businesses about data security and you will hear about firewalls, passwords and cyber insurance. Ask what happened to the filing cabinet that got cleared out last spring and the answers get vaguer. Somebody dealt with it. It probably went in the recycling.
That gap between how carefully information is protected while in use and how casually it is thrown away is where a surprising number of data breaches begin. Paper still carries an enormous amount of sensitive material: personnel files, customer records, financial paperwork, signed contracts, medical correspondence. None of it stops being sensitive on the day you decide you no longer need it.
Disposal is a legal requirement, not housekeeping
Under the UK GDPR and the Data Protection Act 2018, organisations must protect personal data for as long as they hold it, right up to and including its destruction. The ICO’s storage limitation guidance says personal data should not be kept longer than necessary and must be disposed of securely once its retention period ends. Get this badly wrong and the fines can reach £17.5 million or 4 per cent of global turnover.
There is also a piece of legislation that rarely comes up in these conversations: the Environmental Protection Act 1990. It places a duty of care on every business for its waste, so even after you have finished with your paperwork, you remain responsible for what happens to it. Licensed carriers, proper disposal routes, the lot. We cover both angles in our guide to the UK GDPR and Data Protection Act.
So much for the law. Now for the mistakes themselves.
The recycling bin
This is the big one, partly because it feels responsible. Recycling is a good thing, so putting old paperwork in the recycling must be a good thing too. The trouble is that a general recycling collection was never designed to be secure. Paper sits in bins, gets collected, gets transported, gets sorted, and at every one of those stages the documents are still perfectly legible. If a file contains personal data, it needs destroying before it enters the recycling stream. Recycle the shreds by all means. We do.
General waste and skips
General waste has the same weakness with fewer good intentions. Bins are handled by lots of people on the way to their final destination, and an intact document can be read or removed at any point.
Skips deserve a special mention. Office refurbishments and relocations produce huge amounts of paperwork, and much of it ends up thrown into an open skip along with the broken chairs. A skip on the street is accessible to anyone who walks past, and a windy afternoon will distribute loose pages across half the neighbourhood. Bin raiding remains one of the oldest routes to identity fraud, something we go into in our guide to secure data disposal.
Archive boxes stacked in the corridor
Walk through enough offices and you will see them: boxes of old files sitting in corridors, reception areas and loading bays, waiting for someone to decide what happens next. Those boxes might hold a decade of employee records or client files, and while they sit there they can be opened by anyone. Staff, visitors, contractors, the window cleaner. Until documents are either locked away or destroyed, with a chain of custody covering the gap in between, they are exposed.
The printer tray
A smaller mistake, but a constant one. Printouts get forgotten beside the multifunction printer, picked up by the wrong person, or simply left in view. Secure print release helps. So does giving people somewhere sensible to put unwanted printouts, meaning a locked console rather than an open bin next to the machine.
Keeping everything, forever
Plenty of organisations avoid the disposal question entirely by never disposing of anything. It feels cautious. In practice it just means the eventual breach, flood or break in exposes twenty years of records instead of six. A written retention schedule should say how long each type of record is kept and what happens when the clock runs out. And when a backlog has built up, a single one-off shredding collection clears it far more safely than a week of skip runs.
The office shredder
Not a mistake in itself, but relying on one is. Most small shredders are strip cut machines at the lower DIN security levels, and strip cut output has been reconstructed by people with enough patience. Industrial cross-cut shredding to DIN Level 3 produces particles of 4mm x 30mm at most, which is past the point where reassembly is realistic. Our guide to shredder security levels explains the DIN 66399 classifications properly.
The other problem with office shredders is practical. Someone has to stand there feeding pages in, removing staples, emptying the bin, unjamming it. For a handful of documents a week, fine. For an archive clearance, hopeless.
Getting it right
A sound process is not complicated: locked consoles for day to day confidential waste, staff who know what goes in them, and certified destruction with paperwork to prove it. Professional shredding to the BS EN 15713 code of practice keeps material secure from collection through to destruction, and a Certificate of Destruction gives you documented evidence for auditors and regulators.
For steady volumes, scheduled collections under regular shredding contracts stop paperwork building up in the first place. If you want to watch it happen, mobile shredding brings the truck to your door. If you would rather keep costs down, shredding at our secure facility offers the same standards and the same certificate.
Whatever route suits you, the principle is the same: treat disposal as part of your security, not an afterthought at the end of it. If you would like to talk through how your organisation handles confidential shredding, contact Shredsec and we will help you work out what fits.
Contact Shredsec to discuss your shredding requirements.