Offboarding checklists cover accounts, licences and hardware. They rarely cover the customer data in the leaver's local files, mailbox exports and downloads, which is still there when the machine is reissued.
A standard leaver process disables the account, reclaims the licences, collects the laptop, and closes the ticket. It handles access. It does not handle the personal data the leaver accumulated locally over several years, which is still on the disk when the machine is reimaged and reissued, or sitting in a mailbox archive nobody opens again.
This is a data protection problem before it is a security one. Article 5(1)(f) requires appropriate security of personal data, and Article 32 requires measures appropriate to the risk. Personal data on an unreviewed device that has changed hands satisfies neither.
Where it accumulates
- Downloads. Exports pulled from the CRM, finance system or ticketing tool for one piece of analysis, then left in place.
- Desktop and Documents folders. Spreadsheets built for a single meeting two years ago.
- Mailbox archives and local mail exports, which carry attachments long after the source records were deleted.
- Local copies of shared drive content taken for offline work on a train.
- Screenshots from support and troubleshooting, which routinely capture names, addresses and account numbers.
- Personal cloud folders synced into the corporate profile.
The common thread is that all of it was created for a legitimate reason and none of it was ever registered anywhere. It is not in the ROPA, not in the retention schedule, and not in the search scope for an access request.
What the leaver's data does to your other obligations
| Obligation | Effect |
|---|---|
| Access request (Article 15) | In-scope data on an unindexed local profile is the usual cause of a missed one-month deadline |
| Erasure (Article 17) | Deleting the CRM record does not delete the spreadsheet copy of it |
| Article 30 record | Processing that nobody documented, because nobody knew it existed |
| Breach notification (Article 33) | A lost or reissued device with unreviewed contents widens the assessment and lengthens it |
| Retention | Data outlives its schedule because nothing was tracking the copy |
A leaver process that covers data, not just access
- 1Run a discovery pass over the device and the mailbox before the machine is reimaged. Reimaging is the point of no return, and it usually happens within days.
- 2Classify what comes back. Most of it will be copies of data that still exists in a system of record, which makes the decision easy.
- 3Move anything the business genuinely needs into the system it belongs in, so it inherits that system's retention and access controls.
- 4Delete the rest, and record that you did, with the date and the scope.
- 5Handle the mailbox as its own decision. Decide the retention period for the archive, apply it, and write down the reasoning.
- 6Only then wipe and reissue the hardware.
- 7Record the outcome against the leaver, so the position is evidenced if it is questioned two years later.
Sequencing is the part teams get wrong. Disabling the account promptly is the right security move; reimaging the device before anyone has looked at what is on it removes the only chance to answer the data question.
The recurring version of the same problem
Leavers are the visible case. The same accumulation happens on every active device continuously, and it is only noticeable at offboarding because that is the one moment somebody looks. A periodic discovery pass across the estate turns it into a number you manage rather than a discovery you make at the worst possible moment.
Sources & references
- Article 5 - Principles relating to processing of personal data, UK GDPR - legislation.gov.uk
- Article 32 - Security of processing, UK GDPR - legislation.gov.uk
- A guide to data security - ICO
- Employment information and records - ICO


