TL;DR: Removable media encryption only satisfies compliance expectations when organisations can classify what was copied, enforce policy at write time, and preserve audit evidence, according to Strac’s analysis of SOC 2, GDPR, and US privacy requirements. Encryption alone reduces exposure, but governed content inspection is what turns portable media controls into defensible evidence.
NHIMG editorial — based on content published by Strac: Importance of Removable Media Encryption for SOC 2, GDPR, US Privacy Compliance
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
Questions worth separating out
Q: How should organisations control sensitive data copied to removable media?
A: Treat removable media as a policy-enforced data movement channel, not a simple encryption problem.
Q: Why is removable media still a compliance risk when encryption is enabled?
A: Encryption reduces exposure if the device is lost or stolen, but it does not prove what information left the environment or whether the copy was permitted.
Q: What breaks when removable-media policies do not inspect file content?
A: If the endpoint cannot inspect content, the organisation cannot distinguish benign transfers from copies of regulated data.
Practitioner guidance
- Classify before write to removable media Inspect each file before it is copied to USB, external disks, or SD cards so policy decisions are based on content type rather than user intent.
- Bind actions to data classes and channels Create explicit rules for PII, financial data, PHI, and other regulated content so the endpoint can block, warn, audit, or encrypt per channel.
- Retain device-level evidence for audits Store logs that show which file moved, which device received it, and which control was applied so SOC 2 and privacy reviews have defensible evidence.
What's in the full article
Strac's full article covers the operational detail this post intentionally leaves for the source:
- Per-platform enforcement guidance for macOS, Windows, and Linux removable-media workflows
- Jurisdiction-by-jurisdiction compliance references for SOC 2, GDPR, CPRA, Utah, and Virginia
- Examples of how content inspection and encryption are combined in endpoint policy
- The vendor's per-channel framing for block, warn, and audit decisions
👉 Read Strac's analysis of removable media encryption for SOC 2 and GDPR →
Removable media encryption: what SOC 2 and GDPR teams miss?
Explore further
Removable media encryption is an evidence problem before it is a technology problem. Organisations often assume that encrypted portable storage satisfies control intent, but compliance regimes care about demonstrable handling of data, not just unreadable bytes. When a drive leaves the environment, the key question is whether the organisation can prove what was copied and why. Practitioners should treat content-aware logging as part of the control, not a reporting add-on.
A question worth separating out:
Q: Who is accountable when personal data leaves on removable media?
A: Accountability usually sits with the organisation that set the endpoint policy, the teams that approved the workflow, and the control owners responsible for evidence retention. Privacy and security frameworks expect demonstrable safeguards, so a missing audit trail is not just a technical gap, it is an accountability failure.
👉 Read our full editorial: Removable media encryption is a governance problem, not just a tool choice