GDPR compliant office storage means lockable, risk-appropriate cabinets and cupboards paired with documented access controls, retention schedules and destruction procedures. It’s not about buying a filing cabinet with a key. The immediate step is to identify which filing holds sensitive data, appoint someone accountable for it, and get anything high-risk into locked storage promptly, in line with the ICO and UK GDPR Article 32.
TL;DR:
- Lockable cabinets must be selected based on the sensitivity of stored data, with higher-risk records requiring stronger locks and stricter access controls.
- Regular testing of storage security measures and maintaining an information asset register are essential to demonstrate compliance and promptly address breaches.
- Proper operational procedures include centralized key management, role-specific access, and documented disposal processes to prevent unauthorized data exposure.
- Physical storage locations should be secured in restricted areas, anchored properly, and checked regularly, especially when records are transferred or relocated.
- Hybrid storage environments require comprehensive risk assessments and consistent access policies for both physical and digital records to maintain compliance.
Article 32 of the UK GDPR doesn’t specify lock types or cabinet gauges. It requires “appropriate technical and organisational measures” scaled to the risk of the data you’re processing, and it obliges you to test that effectiveness regularly rather than set it once and forget it.
The ICO translates that into three practical obligations for any office holding paper records:
Proportionality matters here. A cabinet of general correspondence doesn’t need the same protection as a drawer of health assessments or disciplinary files. The ICO is explicit that more sensitive categories, personnel records, medical information, financial data, demand stricter access controls and stronger locks than routine business paperwork. Sorting records by sensitivity before you buy storage saves you from over-specifying (and overpaying) for cabinets that hold nothing riskier than supplier invoices.
Buying storage for compliance purposes is different from buying storage for tidiness. Lock quality, build integrity and layout all affect whether you can defend your setup if the ICO ever asks how you protect records.
Pro Tip: Buy one size class larger than you think you need. Understaffed compliance teams almost always underestimate how fast archived HR and contract files accumulate, and an overflowing cabinet gets propped open, which defeats the point entirely.
A locked cabinet with keys left in a desk drawer isn’t secure storage, it’s decoration. The ICO’s guidance on records management treats organisational controls as equally important to the hardware itself.
Start by defining roles clearly:
Key handling is where most breaches actually start. In practice, that means centralised key-holding with a clear rekeying policy whenever a keyholder leaves the business, rather than hoping nobody made a spare. Decide in advance who manages spares, and set a trigger point (resignation, role change, disciplinary action) that forces a rekey or credential revocation.
Whether you log access digitally or on paper matters less than doing it consistently. CCTV covering storage areas is common in larger offices, but weigh it against privacy expectations for staff working nearby. Finally, record every storage location, and the retention schedule it supports, in your information asset register so a new starter (or an ICO auditor) can see the full picture in one document.
You should only keep personal data for as long as it’s needed, and the ICO’s storage guidance expects you to document that decision, not just apply it informally. Retention periods should tie back to your lawful basis for processing and any sector-specific rules (tax records, employment claims, safeguarding files often carry statutory minimums).
Secure disposal needs the same rigour as storage:
Practitioners often pair lockable cabinets with a nearby secure destruction bin so sensitive papers never travel loose across the office on the way to the shredder. Don’t forget decommissioned storage units themselves: clear old filing cabinets fully and check for stray documents wedged behind drawers before you resell, recycle or scrap them.
Where you put a locked cabinet matters almost as much as the lock itself. Reception areas, open corridors and shared kitchens are the wrong locations for anything holding personal data, however good the lock is, because foot traffic makes supervision impossible.
If you outsource to an external storage facility instead of keeping everything on site, that changes your due diligence. Any contract with an offsite provider needs secure destruction clauses and audit rights, so you can prove chain of custody if a client or regulator asks.
Article 32 explicitly requires you to test your security measures, and treating physical storage checks as part of that testing programme is the simplest way to stay defensible.
A missing key, an unlocked cabinet found after hours, or a filing box left in a taxi are all physical data breaches, and UK GDPR treats them exactly the same as a hacked database in terms of your obligations.
The first move is containment: change locks or rekey affected units immediately, and establish what was actually accessible, not just what was technically exposed. Was the cabinet full of general correspondence, or did it hold unredacted personnel files? That distinction decides your next steps.
Document the incident properly from the start: what happened, when it was discovered, who was told, and what containment action was taken. This record matters because certain breaches involving personal data must be assessed against the threshold for notifying the ICO within 72 hours, and you can’t make that assessment without a clear timeline.
Build a simple response protocol before you need it:
Rehearsing this once, even as a short tabletop exercise, exposes gaps that only surface under pressure, like nobody actually knowing who holds the spare keys.
Locks and registers don’t compensate for a member of staff who props a cabinet open all day because carrying keys is inconvenient. The ICO’s own guidance is clear that organisational measures matter as much as equipment, and training is where that principle either sticks or fails.
Keep training practical rather than theoretical. New starters who’ll handle personnel files, client data or health records need a short induction covering which cabinets they can access, how sign-out logging works, and what counts as a reportable incident. Refresher sessions once a year catch the habits that creep in, taped-open drawers, keys left in locks, boxes stacked temporarily in corridors “just for today.”
Make the rules specific to your office rather than generic GDPR theory. Staff remember “the HR cabinet in Room 4 gets signed out on the clipboard by the door” far better than an abstract policy document. Nominate a records champion in each department who flags problems early, a jammed lock, a lost key, a cabinet that’s clearly outgrown its filing, before they become compliance failures. And make sure leavers’ access is revoked as part of the standard offboarding process, not as an afterthought someone remembers three weeks later.

Moving paper records between offices, to an archive, or to a new site during a refurbishment is one of the highest-risk moments in the whole storage lifecycle, because records are briefly outside any locked, monitored environment.
Plan transfers the way you’d plan any other data-handling activity. Use lockable transit boxes or cases rather than open crates, and keep records in locked storage right up until the point they’re loaded for transport. Assign one person accountability for the transfer, someone who signs records out at origin and signs them back in at the destination, creating a paper trail that matches the access-logging principle you apply to static cabinets.
If a third-party removals or storage firm is involved, treat that relationship like any other data processor: get assurance about vehicle security, transit time, and what happens if a box goes missing en route. For genuinely sensitive material, personnel files, health records, financial data, avoid unaccompanied courier transit altogether and use a dedicated, supervised transfer instead.
Update your information asset register the moment records move. A register that says files are in Building A when they’ve actually been sitting in a van, or a new office, for three weeks is worse than no register at all, because it gives false confidence during an audit.

Most offices in 2026 run a hybrid mix of paper personnel files and digital HR systems, and treating the two as separate compliance projects creates gaps. A cabinet full of signed contracts is only half the picture if a scanned copy also sits on a shared drive with looser access permissions than the physical original.
Start by mapping which records exist in both forms. Where a document is scanned and stored digitally, the physical original often becomes redundant sooner, which should shorten its retention period rather than leaving two versions live indefinitely. Where removable media, USB drives, backup discs, are used to move digital records, the ICO recommends encrypting that content and storing the media itself in a locked cabinet when it’s not in active use.
Access permissions should mirror each other across formats. If only HR managers can open the physical personnel cabinet, the digital HR folder shouldn’t be readable by the wider office network. A single information asset register covering both physical and digital locations, rather than two disconnected spreadsheets, makes it far easier to answer a subject access request or an ICO enquiry without hunting across systems.
Hybrid working has pushed more offices toward a mixed estate: a head office archive, a smaller satellite office, and staff occasionally working from home with digital access to records. Each environment needs its own risk assessment, because the weakest link sets your actual exposure, not the strongest.
A locked cabinet in a controlled head office is only as good as the laptop a home-based manager uses to access the scanned equivalent. If that device isn’t encrypted or password-protected, you’ve effectively built a strong physical control next to a weak digital one, and Article 32’s requirement to assess risk holistically means you can’t sign off compliance by looking at storage in isolation.
Practical steps for hybrid estates: keep an inventory of every location, physical or digital, where personal data lives, including any records that occasionally travel to someone’s home. Apply consistent access rules regardless of location, and be explicit with staff about what may and may never leave the office, physically or as an email attachment. Review your hybrid setup at the same cadence as your storage audits, since remote-access risks tend to shift faster than a filing cabinet ever will.
A common question from procurement and HR teams is: which cabinet is “GDPR compliant”? The honest answer is that no cabinet, on its own, earns that label. Compliance sits in the pairing of the right lock and build quality with the access policy wrapped around it.
A good range of products helps at the practical layer: options for bulk ordering for offices standardising storage across multiple departments, delivery services that help avoid delays when a compliance gap needs closing quickly, and anchoring guidance so anti-tilt cabinets get fitted correctly rather than left as a theoretical safety feature. Good hardware makes good policy easier to enforce, not the other way round.
— Furniture
There are lockable filing cabinets, anti-tilt units and secure cupboards built to meet the checklist covered above, without forcing businesses into oversized safes when a well-specified cabinet does the job.

If you’re standardising storage across several departments, bulk pricing and free UK mainland delivery make it straightforward to fit out multiple offices at once rather than ordering piecemeal. Every cabinet ships with anchoring guidance so anti-tilt fittings actually get used, not left in the box. Browse the full office storage range to compare lock types and sizing against your own retention schedule, and get in touch if you need help specifying storage for a mixed-sensitivity filing system across a multi-site refurbishment.
A lockable steel cabinet is sufficient for most personnel and business records; reserve certified safes for the highest-risk items like cash, master keys or unencrypted removable media.
There’s no single fixed period; the ICO expects you to set retention lengths based on your lawful basis for processing and any sector-specific statutory minimums, then document that decision.
A simple checklist, an access log and signed review notes are enough to show quarterly or annual testing, provided you can link them back to your information asset register.
Rekey or replace the lock immediately, log the incident with a timeline, and assess whether the exposure meets the threshold for notifying the ICO within 72 hours.
Yes, Furniture For Business’s office storage range includes lockable and anti-tilt cabinets suited to different sensitivity levels, alongside anchoring guidance for correct installation.
Phone: 0330 043 4114
VAT no. GB 991 8681 60
Company no. 07250570