Skip to content
ADVERTISEMENT

Over 11,000 paperwork-related data breaches occur over the past five years, analysis finds

Analysis from Officeology showed that 11,141 incidents involving lost, stolen or incorrectly disposed paper records were recorded between 2020 and 2025.

ADVERTISEMENT

More than 11,000 paperwork-related data breaches have been reported in the UK over the past five years, with thousands of employees potentially affected, according to analysis by Officeology.

The data, based on reports to the Information Commissioner’s Office (ICO), showed that 11,141 incidents involving lost, stolen or incorrectly disposed paper records were recorded between 2020 and 2025.

Nearly one in five (2,103) of these breaches involved employee data, including personal, financial and health information.

In 2025 alone, 1,820 paperwork-related breaches were reported, with 330 involving employee data.

Based on the size of the organisations affected, this could have impacted up to 28,000 employees.

ADVERTISEMENT

Paper-based breaches are classified as “non-cyber” incidents, meaning they do not involve digital systems or malicious online activity.

Despite increased digitisation across many sectors, the number of these incidents has remained relatively consistent.

The analysis also found that many organisations are failing to meet reporting deadlines.

ADVERTISEMENT

Under UK GDPR rules, data breaches must be reported within 72 hours, yet 41% of paperwork-related incidents in 2025 were reported late.

In 399 cases, it took more than a week to notify the ICO.

ADVERTISEMENT

For employee data breaches specifically, 39% were reported after the 72-hour deadline.

ADVERTISEMENT

The most commonly affected data includes basic personal identifiers such as names, addresses and dates of birth, which were involved in 39% of incidents in 2025. Health data accounted for a further 23%.

Despite the volume of incidents, relatively few cases result in formal regulatory action.

Fewer than 5% of paperwork breaches between 2020 and 2025 led to a formal investigation. In 2025, just 12 cases were escalated, with only one involving employee data.

Adam Butler of Officeology said: “Our analysis of ICO data has highlighted areas of concern, specifically businesses using paper-based systems.

ADVERTISEMENT

“While cybersecurity dominates the news, physical theft, loss or the incorrect disposal of paper records remains a significant risk to companies’ data security, including their own employees’ private information.

“GDPR legislation, the legal framework that aims to protect the privacy and personal data of individuals, is technology-neutral and applies whether data is processed online or offline. It covers any filing system intended to be used in a searchable way.

“Paper-based processes are inherently more vulnerable to human error. Adopting document management systems allows businesses to streamline workflows and store information in secure, centralised environments, helping organisations to better safeguard data and maintain compliance.”