ALL MATERIAL COPYRIGHT BEYOUROWN 2026

More Than A Third Of Uk Paper Disposal Breaches Not Reported To The Ico Within The Legal 72-Hour Window

More Than A Third Of Uk Paper Disposal Breaches Not Reported To The Ico Within The Legal 72-Hour Window

New analysis of data security incident records reveals that more than a third of the 846 paper disposal data breaches reported by UK organisations between 2019 and 2025 were not flagged to the ICO within the legally required 72-hour window.

The research, from Fellowes, a UK specialist in manufacturing shredders and other office equipment, examined data published by the Information Commissioner's Office (ICO) on the incorrect disposal of paperwork which contained personal data that had been disposed of without being shredded or otherwise destroyed, leaving personal information identifiable.

Paper Disposal Breaches Top 840 Between 2019 - 2025

The data, which covers the period 2019 to 2025, shows that incidents involving paper document disposal have persisted at a similar level throughout.

A spike in 2019 saw 209 breaches reported, followed by a fall in 2020 to 57, when many offices closed during the pandemic and physical document handling was reduced.

However, as workplaces reopened numbers rebounded, with 117 incidents recorded in 2021. Following that, a sustained level of 90 to 140 cases per year were recorded.

Reported breaches by year:

  • 2019: 209 incidents
  • 2020: 57 incidents
  • 2021: 117 incidents
  • 2022: 90 incidents
  • 2023: 122 incidents
  • 2024: 140 incidents
  • 2025: 111 incidents

The Health Sector Reports the Most Paper Disposal Breaches

Health organisations accounted for 227 breaches (26.83%), making the sector by far the most frequently reported. Education and childcare followed with 185 cases (21.87%).

Together, the five sectors account for more than 72% of all reported incidents, identifying a clear concentration of risk in organisations that routinely process patient records, client files, case notes and other sensitive documentation.

Top five sectors by reported incidents:

  1. Health: 227 incidents (26.83%)
  2. Education and childcare: 185 incidents (21.87%)
  3. Local government: 69 incidents (8.16%)
  4. Social care: 67 incidents (7.92%)
  5. Charitable and voluntary: 62 incidents (7.33%)

"Paper documents containing personal data are processed in large volumes every day across health, education and public sector settings," says Louise Shipley, Head of European Marketing for Workplace Health Solutions at Fellowes.

"The consistent level of breaches we're seeing across this seven-year period suggests that the risk is not being managed as a routine operational matter in the way it needs to be. In many cases, the solution is straightforward, but the issue requires awareness, the right equipment and a clear disposal process to be in place."

Legal Reporting Deadlines Missed in More than 300 Cases

Under Article 33 of the UK GDPR, organisations are required to report personal data breaches to the ICO within 72 hours of becoming aware of them. The analysis found that 63.24% of incidents in the dataset were reported within that window, with 147 cases (17.38%) reported in under 24 hours and 388 cases (45.86%) reported between 24 and 72 hours.

However, 208 incidents (24.59%) were reported between 72 hours and one week after discovery, and a further 103 cases (12.17%) took longer than a week to report. Delayed reporting can complicate the response process for affected individuals and may indicate that internal detection or escalation procedures are not operating effectively.

Time taken to report a breach to the ICO:

  • Under 24 hours: 147 incidents (17.38%)
  • 24 to 72 hours: 388 incidents (45.86%)
  • 72 hours to one week: 208 incidents (24.59%)
  • More than one week: 103 incidents (12.17%)

Informal Action Taken in Two Thirds of Cases

When it comes to the action taken following a reported incident, the ICO opted for informal action in the majority of cases, accounting for 527 of the reports where a decision had been reached (66.21%). No further action was taken in 227 cases (28.52%), while a formal investigation was pursued in 31 cases (3.89%).

While the proportion of formal investigations is relatively low, the ICO's own guidance makes clear that the technical and organisational measures an organisation had in place at the time of a breach are a factor in any consideration of regulatory action. The nature of the informal action taken in the majority of cases is not publicly detailed, but for the organisations involved the process carries a regulatory and reputational burden regardless of the outcome.

Action taken by the ICO:

  • Informal action taken: 527 cases (66.21%)
  • No further action: 227 cases (28.52%)
  • Formal investigation pursued: 31 cases (3.89%)
  • Not yet assigned: 11 cases (1.38%)

"The fact that informal action outnumbers formal investigation by a significant margin should not be interpreted as a signal that the risk is low," adds Shipley.  

"Every incident in this dataset represents a failure to adequately protect personal data that belonged to real people. The reputational, operational and human cost of that should be the starting point for any organisation reviewing how it manages document disposal."

What Better Document Disposal Looks Like in Practice

Incorrect disposal of paper documents typically occurs through inadequate shredding, failure to follow disposal procedures or reliance on third-party services without proper oversight.

Shipley sets out the practical steps organisations should be taking:

"First, organisations need to have a clear, written policy on how paper documents containing personal data are disposed of, and that policy needs to be communicated to all staff who handle such records. Second, where documents are shredded on site, the equipment used should meet the appropriate security level for the type of data being processed. DIN 66399 provides a recognised standard for document shredding, and for most personal data a cross-cut or micro-cut shredder at security level P-4 or above is appropriate.

"Third, where third-party disposal services are used, organisations need documented assurance that those providers are handling material securely and in line with data protection requirements. Finally, staff training is essential. Many disposal failures are the result of people not recognising the sensitivity of what they are discarding or not knowing what the correct process is."

Methodology

Fellowes analysed published data security incident records from the Information Commissioner's Office (ICO), filtering specifically for incidents attributed to incorrect disposal of paperwork. The dataset covers the period 2019 to 2025. Sector breakdowns, reporting timelines and ICO action categories are drawn directly from ICO published records.

Sources

https://ico.org.uk/action-weve-taken/complaints-and-concerns-data-sets/data-security-incident-trends/