Print security and GDPR
Printers and multifunction devices are a data protection risk that is easy to overlook because they do not look like IT equipment. Documents sit in output trays for anyone passing to read, devices store scanned and printed content on internal hard drives long after the job is done, and few businesses have thought about who can walk up to a shared machine and what they can see or do once there. This is general information to help you ask the right questions under UK GDPR, not legal advice, and if your obligations are unclear you should take proper legal advice for your specific circumstances.
Documents left in output trays
The most ordinary print security failure is also the most visible: a document sent to a shared printer, printed immediately, and left sitting in the output tray until someone unconnected to it walks past. In an office handling personal data, financial information or anything client-confidential, that is an exposure that happens dozens of times a day without anyone treating it as one.
The scale of this depends entirely on how the device is used. A single printer serving a small team where everyone collects their own output promptly is a lower risk than a shared device in a busy area serving people from several departments who print and then get pulled into something else before collecting the page.
Secure release and pull printing
Secure release, sometimes called pull printing, holds a job in a queue until the person who sent it authenticates at the device, typically with a PIN or a card, to release it. Nothing sits in the output tray unclaimed, because nothing prints until someone is standing there to collect it. This is one of the more direct fixes available for the output tray problem, and it is worth asking any supplier whether it is available on the devices you are considering and what it costs to enable.
What happens to data on multifunction device hard drives
Most modern multifunction devices, the machines that print, copy and scan, contain an internal hard drive that stores images of documents that pass through them, often for longer than most people assume and sometimes as a byproduct of print queuing rather than a deliberate scan-and-store feature. A device that has handled years of scanned and copied documents can hold a meaningful volume of sensitive content on that drive.
This matters most at the end of a lease. When a leased device is returned or exchanged, ask explicitly what happens to the data on its hard drive: whether it is wiped, how, and by whom, and ask for that in writing rather than as a verbal assurance. This is a reasonable question to put to any supplier and one a credible supplier should be able to answer without hesitation.
Scan-to-email and scan-to-folder
Multifunction devices that scan directly to an email address or a network folder are convenient, and also a route for personal data to leave a controlled environment without passing through the checks that would normally apply to that kind of transfer. Ask whether scan destinations are restricted to a known list rather than free text, whether large or sensitive scans trigger any additional check, and who is able to add a new scan destination in the first place. A device that lets any user type in an arbitrary external email address and scan directly to it is a wider gap than most people picture when they think about print security.
Access control
Ask who can access each device, physically and digitally. Physical access is about location: a device in an open area accessible to visitors and contractors carries different risk from one inside a controlled office area. Digital access is about authentication: whether the device requires a login to use its scan-to-email or scan-to-folder functions, and whether those functions are restricted to specific users or open to anyone on the network.
Audit trails
Ask whether the device or fleet management software keeps a record of who printed, copied or scanned what, and when. An audit trail will not prevent an incident on its own, but it is what allows you to establish what happened after the fact, which matters both for internal investigation and for any obligation to report a personal data breach.
Print security as part of a wider policy
Print and scan devices should sit inside the same data protection thinking as any other system that touches personal data, not be treated as a separate category because they are physical hardware rather than software. If your business already has a data protection policy covering systems and access, it is worth checking explicitly whether print and multifunction devices are named in it or have simply been overlooked because they do not look like the rest of the IT estate. Many are bought and managed by an office or facilities function rather than IT, which is often exactly why they end up outside a policy that was written with servers and laptops in mind.
Retention
Ask how long print, scan and copy logs are kept, and where. This is worth checking against your own data retention policy rather than assuming the device defaults are appropriate for your business, because a manufacturer’s default retention period was not set with your specific obligations in mind.
UK GDPR framing
Under UK GDPR, personal data processed through printing and scanning, whether that is customer records, HR files or financial documents, is subject to the same principles as data held anywhere else in the business: it should be secured appropriately, retained no longer than necessary, and accessible only to those who need it. The Information Commissioner’s Office is the relevant UK regulator and publishes guidance on data security obligations that is worth consulting directly if you handle a significant volume of personal data through print and scan devices. None of this is a substitute for your own data protection officer or legal adviser reviewing your specific setup.
Sectors with particular exposure
Print security tends to matter most in sectors handling a high volume of sensitive documents day to day. Our guides on managed print for healthcare and managed print for legal practices cover some of the sector-specific considerations in more depth, and our page on secure printing solutions covers the practical features, such as pull printing and access control, that reduce this risk on the device side.
Multi-site and remote considerations
A business with more than one location has an extra layer to think about: whether print security settings, such as pull printing configuration and scan destination lists, are applied consistently across every site or set up individually per location by whoever happened to install each device. Inconsistent configuration across sites is a common gap, not because any one site is careless but because nobody owns the whole picture. Our guide on managed print for multi-site organisations covers some of the wider coordination issues that come with running print across more than one location, print security among them.
Questions worth putting to a supplier
Ask whether pull printing or secure release is available and what it costs to enable. Ask what happens to hard drive data at the end of a lease and for that answer in writing. Ask whether devices support user authentication for scan functions. Ask how long logs are retained and whether that retention period can be adjusted to match your own policy. A supplier who answers these clearly, without needing to check, has likely been asked before and taken the answer seriously.