---
title: Tips on GDPR compliance for mobile data
description: Take a strategic approach to data protection you’re well on the way to achieving compliance, and there are some useful tools available to help you address the mobile issue.
image: https://blog.fordway.com/hubfs/mobile_data.jpg
---

T. 01483 528 200 [How can we help?](https://www.fordway.com/contact-us) [Contact us](https://www.fordway.com/contact-us)

[![fordway-logo](https://www.fordway.com/wp-content/uploads/2019/07/fordway-logo.png "fordway-logo")](https://www.fordway.com/)

- [Home](https://www.fordway.com)
- [Insights](https://www.fordway.com/insights/blog)
- [Cloud Services](https://www.fordway.com/services/cloud)

# Fordway Blog

## [Tips on GDPR compliance for mobile data](https://blog.fordway.com/mobile-data-and-gdpr)

 \[fa icon="calendar"\] Oct 27, 2017 10:44:32 AM / by [Richard Blanford](https://blog.fordway.com/author/richard-blanford)

- [Tweet](https://twitter.com/share)

![mobile_data](https://blog.fordway.com/hubfs/mobile_data.jpg)

 

With GDPR only seven months away now, one aspect of compliance we all need to consider is how to secure personally identifiable information (PII) on laptops and other mobile devices. This data is harder to control and at a greater risk of being compromised because it’s not behind the company firewall.

However, I believe that there’s no need to panic. If you take a strategic approach to data protection you’re well on the way to achieving compliance, and there are some useful tools available to help you address the mobile issue.

The first step is to work out where your PII actually is. Around 20 per cent is likely to be in specific applications such as databases and CRM systems, and this is straightforward to identify and protect. It should be easy to find any copies on mobile devices, and if they don’t need to be there you can simply move them to secure internal storage or delete them.

The remaining 80 per cent of data is harder to categorise. But do you actually need to protect most of this information? Material such as proposals, reports, technical documentation and internal quality, process and admin documents all contain minimal PII – primarily just the name and job title of the recipient, which is already in the public domain on LinkedIn etc. These documents aren’t are a significant GDPR risk and normal good security practice will be suitable.

[![Download our free Roadmap Through the Cloud for cloud strategy and planning tips to help you realise the benefit of cloud for your organisation.](https://no-cache.hubspot.com/cta/default/2198812/7169a780-199a-4117-ab7f-adce3f96487f.png)](https://cta-redirect.hubspot.com/cta/redirect/2198812/7169a780-199a-4117-ab7f-adce3f96487f)

If you believe there’s PII on corporate mobile devices, you can use software tools such as Druva inSync to scan files and data as part of the device’s backup and recovery process. This will identify potential PII and other sensitive data, which you can then protect or delete in line with your company policy. You don’t even have to buy the software yourself - we offer this capability as a service, and as well as providing backup and restoration we offer compliance and legal hold with scalable, encrypted backup storage.

Most important of all, you need a data security policy for your company’s mobile devices which is enforceable, realistic, unambiguous, acceptable to users and avoids violating personal privacy laws. The key is to minimise the amount of data transferred to or held on the device. There are various ways to do this, and we’re happy to advise you on the options.

Overall I believe GDPR is a business issue, not a technology problem. Technology can help by providing useful search and archive tools but the key is a clearly defined and well understood GDPR adherence policy, with appropriate business processes to ensure compliance and continual good cyber security discipline.

[There’s more information in my recent article](https://gdpr.report/news/2017/10/13/gdpr-compliance-mobile-workers/?platform=hootsuite) in GDPR:Report.

 Topics: [GDPR](https://blog.fordway.com/topic/gdpr), [Cloud Security](https://blog.fordway.com/topic/cloud-security), [Data Protection](https://blog.fordway.com/topic/data-protection)

![Richard Blanford](https://blog.fordway.com/hs-fs/hubfs/Blog%20images/bloggers/RB_Headshot.png?width=100&height=100&name=RB_Headshot.png)

#### Written by [Richard Blanford](https://blog.fordway.com/author/richard-blanford)

[\[fa icon="linkedin-square"\]Linkedin](https://www.linkedin.com/in/richard-blanford-508563/) [\[fa icon="twitter-square"\]Twitter](https://www.twitter.com/fordwaybloke)

### Get updates directly to your inbox

 Submitting your information tells us you are okay recieveing blog updates and you are agreeing to our [privacy policy](http://www.fordway.com/privacy-policy) and [cookie policy](http://www.fordway.com/use-of-cookies). You can of course, opt out of these communications at any time!

- Recent
- Popular
- Categories

### Lists by Topic

- [Cloud (16)](https://blog.fordway.com/topic/cloud)
- [IT Strategy (13)](https://blog.fordway.com/topic/it-strategy)
- [Security (13)](https://blog.fordway.com/topic/security)
- [IT Transformation (10)](https://blog.fordway.com/topic/it-transformation)
- [Technology (10)](https://blog.fordway.com/topic/technology)
- [cloud intermediation (10)](https://blog.fordway.com/topic/cloud-intermediation)
- [Cloud migration (9)](https://blog.fordway.com/topic/cloud-migration)
- [Cloud Security (8)](https://blog.fordway.com/topic/cloud-security)
- [enterprise cloud (8)](https://blog.fordway.com/topic/enterprise-cloud)
- [Insider (7)](https://blog.fordway.com/topic/insider)
- [Strategy (7)](https://blog.fordway.com/topic/strategy)
- [Cloud Shock (6)](https://blog.fordway.com/topic/cloud-shock)
- [Fordway Managed Services (6)](https://blog.fordway.com/topic/fordway-managed-services)
- [GDPR (6)](https://blog.fordway.com/topic/gdpr)
- [managed cloud (6)](https://blog.fordway.com/topic/managed-cloud)
- [Azure (5)](https://blog.fordway.com/topic/azure)
- [Disaster Recovery (5)](https://blog.fordway.com/topic/disaster-recovery)
- [New Technology (5)](https://blog.fordway.com/topic/new-technology)
- [legacy (4)](https://blog.fordway.com/topic/legacy)
- [tactical (4)](https://blog.fordway.com/topic/tactical)
- [#ChooseToChallenge (3)](https://blog.fordway.com/topic/choosetochallenge)
- [#IWD2021 (3)](https://blog.fordway.com/topic/iwd2021)
- [Cloud Monitoring (3)](https://blog.fordway.com/topic/cloud-monitoring)
- [Data Protection (3)](https://blog.fordway.com/topic/data-protection)
- [Fordway (3)](https://blog.fordway.com/topic/fordway)
- [Governance (3)](https://blog.fordway.com/topic/governance)
- [ITIL (3)](https://blog.fordway.com/topic/itil)
- [Risk Management (3)](https://blog.fordway.com/topic/risk-management)
- [cloud first (3)](https://blog.fordway.com/topic/cloud-first)
- [remote working (3)](https://blog.fordway.com/topic/remote-working)
- [trends (3)](https://blog.fordway.com/topic/trends)
- [Cyber Security (2)](https://blog.fordway.com/topic/cyber-security)
- [Meet the team (2)](https://blog.fordway.com/topic/meet-the-team)
- [Ransomeware, incident response, CISO, Security (2)](https://blog.fordway.com/topic/ransomeware-incident-response-ciso-security)
- [Ransomware (2)](https://blog.fordway.com/topic/ransomware)
- [case study (2)](https://blog.fordway.com/topic/case-study)
- [compliance (2)](https://blog.fordway.com/topic/compliance)
- [technical debt (2)](https://blog.fordway.com/topic/technical-debt)
- [Cloud Paging (1)](https://blog.fordway.com/topic/cloud-paging)
- [Connectivity (1)](https://blog.fordway.com/topic/connectivity)
- [DaaS (1)](https://blog.fordway.com/topic/daas)
- [DraaS (1)](https://blog.fordway.com/topic/draas)
- [Incident Response (1)](https://blog.fordway.com/topic/incident-response)
- [Managed Services (1)](https://blog.fordway.com/topic/managed-services)
- [Microsoft Sentinel (1)](https://blog.fordway.com/topic/microsoft-sentinel)
- [Networking (1)](https://blog.fordway.com/topic/networking)
- [Optimised Infrastructure (1)](https://blog.fordway.com/topic/optimised-infrastructure)
- [Patch Management (1)](https://blog.fordway.com/topic/patch-management)
- [Patching (1)](https://blog.fordway.com/topic/patching)
- [Project Management (1)](https://blog.fordway.com/topic/project-management)
- [Technology Services 2 (1)](https://blog.fordway.com/topic/technology-services-2)
- [Web hosting (1)](https://blog.fordway.com/topic/web-hosting)
- [hyperconvergence (1)](https://blog.fordway.com/topic/hyperconvergence)
- [information security (1)](https://blog.fordway.com/topic/information-security)
- [shared services (1)](https://blog.fordway.com/topic/shared-services)
- [vdi (1)](https://blog.fordway.com/topic/vdi)
- [virtual desktop (1)](https://blog.fordway.com/topic/virtual-desktop)

see all

## [Older Fordway Posts](http://www.fordway.com/blog/archive)

 

[Tweets by @Fordway](https://twitter.com/Fordway)

### CONTACT

01483 528 200

[Privacy Policy](https://www.fordway.com/privacy-policy)  
[Anti-Slavery Policy](https://www.fordway.com/anti-slavery-policy)

 

### This is Ermincloud the Fordway cow

[Find out why she matters to us!](https://www.fordway.com/ermincloud)

[![](https://fw-dev-neu-webasp-001.azurewebsites.net/wp-content/uploads/2019/07/twitter-footer-icon.png)](https://twitter.com/Fordway) [![](https://fw-dev-neu-webasp-001.azurewebsites.net/wp-content/uploads/2019/07/facebook-footer-icon.png)](https://www.facebook.com/Fordway-358130410947628/) [![](https://fw-dev-neu-webasp-001.azurewebsites.net/wp-content/uploads/2019/07/youtube-footer-icon.png)](https://youtube.com) [![](https://fw-dev-neu-webasp-001.azurewebsites.net/wp-content/uploads/2019/07/linkedin-footer-icon.png)](https://www.linkedin.com/company/fordway-solutions)

Copyright © 2020 Fordway Solutions

\[fa icon="chevron-up"\]Back to top

![](https://dc.ads.linkedin.com/collect/?pid=94312&fmt=gif)