Stolen Unencrypted Laptop Triggers GDPR Fines for Controller and Processor
A work laptop stolen from a parked car exposed landowners' names, addresses, and ID numbers because neither the data controller nor the processor had implemented adequate endpoint security measures such as full-disk encryption. The root failure was a lack of proper risk assessment and technical safeguards for portable devices holding personal data — a foundational GDPR requirement under Articles 24, 25, and 32. This case illustrates that physical theft remains a significant data breach vector and that 'appropriate technical measures' explicitly includes encryption of mobile devices. The dual fines against both controller and processor highlight that GDPR accountability extends across the entire data processing chain, and processors cannot simply defer security responsibilities to controllers.
Tactical Insight
Immediate actions
- Enforce full-disk encryption (e.g., BitLocker, FileVault) on all laptops and portable devices that store or access personal data.
- Audit all external/portable devices used by processors and contractors to verify baseline security controls are in place.
Long-term improvements
- Embed device security requirements (encryption, remote wipe, screen lock) into Data Processing Agreements (DPAs) with all processors.
- Conduct formal Data Protection Impact Assessments (DPIAs) for any processing involving portable devices or off-site data access.
- Implement a Mobile Device Management (MDM) solution to enforce and monitor security policies across all endpoints centrally.
Detection & response measures
- Enable remote wipe and geolocation capabilities on all company-issued laptops so lost or stolen devices can be neutralised immediately.
- Establish a device loss/theft response procedure with defined timelines for breach notification assessment under GDPR Article 33.