Back to Blog
GDPR

What happens to personal data when an employee leaves

Published 10 September 20263 min readBy EmberHound

Offboarding checklists cover accounts, licences and hardware. They rarely cover the customer data in the leaver's local files, mailbox exports and downloads, which is still there when the machine is reissued.

A standard leaver process disables the account, reclaims the licences, collects the laptop, and closes the ticket. It handles access. It does not handle the personal data the leaver accumulated locally over several years, which is still on the disk when the machine is reimaged and reissued, or sitting in a mailbox archive nobody opens again.

This is a data protection problem before it is a security one. Article 5(1)(f) requires appropriate security of personal data, and Article 32 requires measures appropriate to the risk. Personal data on an unreviewed device that has changed hands satisfies neither.

Where it accumulates

  • Downloads. Exports pulled from the CRM, finance system or ticketing tool for one piece of analysis, then left in place.
  • Desktop and Documents folders. Spreadsheets built for a single meeting two years ago.
  • Mailbox archives and local mail exports, which carry attachments long after the source records were deleted.
  • Local copies of shared drive content taken for offline work on a train.
  • Screenshots from support and troubleshooting, which routinely capture names, addresses and account numbers.
  • Personal cloud folders synced into the corporate profile.

The common thread is that all of it was created for a legitimate reason and none of it was ever registered anywhere. It is not in the ROPA, not in the retention schedule, and not in the search scope for an access request.

What the leaver's data does to your other obligations

ObligationEffect
Access request (Article 15)In-scope data on an unindexed local profile is the usual cause of a missed one-month deadline
Erasure (Article 17)Deleting the CRM record does not delete the spreadsheet copy of it
Article 30 recordProcessing that nobody documented, because nobody knew it existed
Breach notification (Article 33)A lost or reissued device with unreviewed contents widens the assessment and lengthens it
RetentionData outlives its schedule because nothing was tracking the copy

A leaver process that covers data, not just access

  1. 1Run a discovery pass over the device and the mailbox before the machine is reimaged. Reimaging is the point of no return, and it usually happens within days.
  2. 2Classify what comes back. Most of it will be copies of data that still exists in a system of record, which makes the decision easy.
  3. 3Move anything the business genuinely needs into the system it belongs in, so it inherits that system's retention and access controls.
  4. 4Delete the rest, and record that you did, with the date and the scope.
  5. 5Handle the mailbox as its own decision. Decide the retention period for the archive, apply it, and write down the reasoning.
  6. 6Only then wipe and reissue the hardware.
  7. 7Record the outcome against the leaver, so the position is evidenced if it is questioned two years later.
Sequencing is the part teams get wrong. Disabling the account promptly is the right security move; reimaging the device before anyone has looked at what is on it removes the only chance to answer the data question.

The recurring version of the same problem

Leavers are the visible case. The same accumulation happens on every active device continuously, and it is only noticeable at offboarding because that is the one moment somebody looks. A periodic discovery pass across the estate turns it into a number you manage rather than a discovery you make at the worst possible moment.

Sources & references

  1. Article 5 - Principles relating to processing of personal data, UK GDPR - legislation.gov.uk
  2. Article 32 - Security of processing, UK GDPR - legislation.gov.uk
  3. A guide to data security - ICO
  4. Employment information and records - ICO

Related resources

Want more of this in Google?

See what personal data your endpoints are hiding

EmberHound scans your devices for GDPR and PCI data automatically - no manual discovery required.

Your cookie choices

We use cookies to run this site, measure how it is used, and to advertise on other platforms. You can accept or refuse each purpose separately.

Keeps you signed in and remembers this choice. Always on.

Google Analytics, Sentry and Vercel. Which pages are used, and what breaks.

LinkedIn, X and Meta pixels, loaded through Google Tag Manager.

Cookie policy