Join our Newsletter — 33% off our NHI Course

Who is accountable when personal data leaves on removable media?

Accountability usually sits with the organisation that set the endpoint policy, the teams that approved the workflow, and the control owners responsible for evidence retention. Privacy and security frameworks expect demonstrable safeguards, so a missing audit trail is not just a technical gap, it is an accountability failure.

Why This Matters for Security Teams

When personal data is copied to removable media, accountability shifts from a vague policy concept to a test of operational control. Security teams need to know who authorised the transfer, which safeguards were active, and whether the organisation can prove what happened after the fact. That is why control evidence matters as much as the policy itself. Guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls treats access control, auditability, and media protection as linked obligations rather than separate checkboxes.

The practical risk is not only data loss. Removable media can bypass normal logging, evade DLP coverage, and create gaps between the user who handled the device, the manager who approved the process, and the control owner who should be able to evidence compliance. Under the EU General Data Protection Regulation (GDPR), organisations must be able to show appropriate technical and organisational measures, which means accountability cannot be assumed after the event.

In practice, many security teams encounter this only after a lost USB device, an exception request, or an audit finding has already exposed the weak point in their evidence chain.

How It Works in Practice

Accountability for personal data on removable media is usually shared, but it is not diffuse. The organisation remains responsible for the processing activity, while specific internal roles carry operational duties: endpoint security for device controls, privacy or data protection for policy alignment, business owners for approved use cases, and record owners for retention and incident evidence. Clear ownership is essential because a transfer is only defensible when the organisation can show who approved it, why it was necessary, and what safeguards applied.

In mature environments, the workflow typically includes device restrictions, encryption, endpoint monitoring, and logging of file movement or media insertion. The control objective is not to forbid every use of portable media, but to reduce the number of cases where data can leave unmanaged. The most important evidence usually includes:

  • policy approval for the exception or business need
  • asset and device inventory showing which media were authorised
  • logs proving encryption, copy events, or access approvals
  • retention records for audit and incident response
  • user acknowledgement or handling instructions where policy requires it

From a governance perspective, a removable-media event should map to the organisation’s privacy impact assessment, risk register, and incident escalation path. If the data is personal data, accountability also includes demonstrating lawful processing, minimisation, and security safeguards under GDPR principles. If the environment uses identity-based controls, the question extends to whether the user’s privileges were appropriate at the time of transfer and whether privileged workflows were subject to extra review. Current guidance suggests that technical controls without traceable ownership are insufficient for audit defence.

These controls tend to break down when unmanaged endpoints, contractor devices, or offline operational environments prevent central logging and policy enforcement.

Common Variations and Edge Cases

Tighter removable-media controls often increase operational friction, requiring organisations to balance data protection against legitimate fieldwork, manufacturing, healthcare, or incident-response needs. That tradeoff is real, and best practice is evolving rather than universal.

One common edge case is sanctioned offline work. In some environments, data must be transferred to removable media because connectivity is unreliable or the task is safety-critical. In those cases, the organisation should still maintain a documented exception, strong encryption, and post-use reconciliation. Another edge case is shared accountability across third parties: if a processor, contractor, or managed service provider handles the transfer, the controller still retains primary accountability, but the contract and operating procedures must make the processor’s obligations explicit.

Where the data includes special category or high-risk personal data, the expectation for safeguards rises, and a missing audit trail becomes harder to defend. There is no universal standard for this yet across all industries, but the direction of travel in privacy and security governance is clear: if an organisation cannot reconstruct who moved the data, when, and under what approval, it has not truly controlled the risk. In regulated environments, that problem is often identified during review of exception logs rather than during the transfer itself.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AC-4 Media transfers depend on controlled access and least privilege.
NIST SP 800-53 Rev 5 MP-7 Media use and sanitisation controls directly address removable-media risk.
NIST SP 800-63 Identity assurance supports confidence that the right person approved or used the media.

Restrict removable-media use to approved identities and review entitlements regularly.