Your Biggest Data Breach Risk Isn’t a Hacker, It’s a Paper Run Sheet

Updated: July 21, 2026

Written by Road XS

  • Reading Time: 5 minutes

Around 75% of data breaches reported to the ICO involve human error, not cyberattacks, and lost paperwork ranks among the most common types every quarter. For community transport operators using printed run sheets, this is an immediate risk. Those sheets may carry special category data under UK GDPR, and when one goes missing, the organisation is legally liable, not the driver.

In This Article

Around 75% of the data breaches reported to the Information Commissioner's Office come down to human error, not hackers. Lost or mislaid paperwork appears among the most common types every quarter.

Any operator running printed run sheets, whether a community transport charity, a council, an NHS service or a contractor, is exposed.

Key Takeaways

  • Most UK data breaches are not hacks. Around 75% of incidents reported to the ICO come down to human error, and lost or mislaid paperwork appears among the most common types every quarter.
  • Run sheets carry special category data: health conditions, home addresses, mobility and safeguarding notes. Under UK GDPR this is the most protected information there is.
  • The organisation is liable, not the driver. Whether you are a charity, a council, an NHS service or a contractor, you are the data controller, and the ICO asks what controls you had in place.
  • A lost sheet can be a safeguarding risk, not only a data one. It can reveal exactly when a vulnerable passenger is away from home.
  • The fix is not banning paper overnight. It is moving to a system that logs who saw what and when, and easing drivers in at their own pace.

What is the most common data breach in the UK?

It is not a cyber attack. Around three quarters of the data security incidents reported to the ICO are non-cyber, meaning human error rather than hacking. Within that, loss or theft of paperwork appears among the most reported categories year after year. Sending information to the wrong recipient tops the list.

The ICO says its split between cyber and non-cyber is currently under review, so the exact proportions shift each quarter. The pattern underneath holds. Most breaches are human, and many are made of paper. That is as true for a council-run scheme or an NHS service as for a small charity.

Not malware. Not phishing. Paper.

What does a paper run sheet actually expose?

A single sheet can expose everything needed to identify and locate a vulnerable person. Picture a normal morning. A coordinator prints a run sheet for each driver. Whether the service is a dial a ride, a demand responsive route or a patient transport run, the sheet usually carries:

  • passenger names,
  • home addresses,
  • pickup times,
  • destinations.

Often there is more, such as:

  • "uses a walker,"
  • "has dementia, do not leave unattended,"
  • an emergency contact,
  • a note about medication.

The driver puts the sheet on the passenger seat and sets off. At the end of the day it goes back to the office, or into a glovebox, a kitchen drawer, or the recycling. Sometimes it is photographed to keep on a phone, then shared in a WhatsApp group or an email chain.

Recommended:
HMRC’s Mileage Rate Increase Is More Significant Than It First Appears

Every step of that routine creates the exact conditions the ICO records again and again. A paper process does not just risk one of the country's most common breaches. It manufactures the conditions for it, every single morning, then relies on luck.

Why is run sheet data "special category" data?

Because it reveals health and disability. A journey to a dialysis unit, a memory clinic or a mental health service reveals a health condition. A note about mobility describes a disability. Under UK GDPR these are special category data, the most protected class there is, and processing them lawfully takes two separate steps.

You need an Article 6 lawful basis and a separate Article 9 condition, documented before the data is used. Most services have never recorded either for a sheet that spends its afternoon in a glovebox. For SEND and home to school transport the bar is higher still, because children's data carries extra protection.

Is a lost run sheet a safeguarding risk too?

Yes, and this rarely reaches the risk register. Repeated journey records show when a person leaves home, where they go, and when they return. A single lost sheet showing a weekly hospital run is not just personal data. It is a map of someone's absence from their own house.

For a passenger fleeing domestic abuse, or living alone with dementia, that map is the danger, long before the ICO is ever involved. A conversation framed only around fines misses this entirely. It is the reason the risk matters as much to safeguarding leads as to data protection officers.

Who is liable, the organisation or the driver?

The organisation, every time. Nobody is questioning the drivers. Many services use paper precisely because some drivers, particularly older volunteers, prefer it to a smartphone. But a process built around what the workforce finds comfortable is a policy built around staff, not around the passengers whose sensitive data is being handled.

When something goes wrong, the driver does not carry the legal responsibility. The data controller does, whether that is the charity, the local council, the NHS trust or the contractor holding a central government agreement. The ICO will not ask which driver lost the sheet. It will ask what controls the organisation had in place.

Recommended:
Why Community Transport Matters More Than Ever

There is a clock running too. Where a breach is likely to put people at risk, it must be reported to the ICO within 72 hours of the organisation becoming aware. With paper, many services could not even establish what was lost inside 72 hours. "We have always done it this way" describes the problem, not a defence.

How do you fix it without banning paper overnight?

You show your working. The ICO's approach with smaller organisations leans towards advice, and most reported breaches end in no further action. What protects you is being able to prove what data existed, who could see it, and what happened to it. That is exactly what paper cannot do.

A purpose built system does it automatically. The Road XS driver portal gives each driver only the journey details they need, expires them when the run is done, logs every access, keeps messaging inside the platform instead of WhatsApp, and removes a leaver's access centrally in one click. Nothing is printed, so nothing is left to lose.

Because the obstacle is confidence, not willingness, change works best gradually. Tighten the paper process now: print less, return and shred, keep messaging off WhatsApp. Then pilot with your most willing drivers and let them bring the rest along. Most "I won't use technology" objections are really a fear of letting someone down.

Frequently asked questions

What is the most common type of data breach in the UK?

Most incidents reported to the ICO are non-cyber, with around three quarters coming down to human error rather than hacking. The single most common type is information sent to the wrong recipient, usually by email. Loss or theft of paperwork appears among the recurring categories every quarter. Cyber attacks such as phishing and ransomware make up the smaller share.

Is a lost run sheet a reportable data breach?

It can be. A run sheet usually holds special category data such as health conditions and home addresses. Where the loss is likely to risk the rights and freedoms of the people named, you must report it to the ICO within 72 hours of becoming aware. If there is no real risk, record the decision and your reasoning anyway.

Do these rules apply to councils and the NHS, not just charities?

Yes. UK GDPR applies the same way to a local council running a dial-a-ride, an NHS non-emergency patient transport service, a SEND or home-to-school team, and a community transport charity with volunteer drivers. Each is a data controller for the passenger data it handles. The duty does not depend on the organisation's size or type.

Recommended:
Why Paper and Spreadsheets No Longer Work for Transport Management

Who is liable when a driver loses a run sheet?

The charity, council, NHS body or contractor, as the data controller. The organisation carries the legal responsibility for how personal data is handled, not the individual driver. The ICO looks at the controls that were in place, not at who made the mistake. That is why "a trusted driver lost it" is not a defence.

What counts as special category data on a run sheet?

Information about health, disability or mobility is special category data under Article 9 of the UK GDPR. A note such as "has dementia, do not leave unattended," or a journey to a dialysis unit, reveals health data. Processing it lawfully needs both an Article 6 lawful basis and a separate Article 9 condition. Data about children carries extra protection again.

Does the ICO fine small organisations for paperwork breaches?

Not usually as a first step. The ICO's approach with smaller organisations leans towards guidance and support, and most reported incidents end in no further action. What matters is being able to show that reasonable controls were in place before anything went wrong, rather than proving nothing ever will.

How can transport services reduce paper-based data breaches?

Start by printing less, keeping messaging off WhatsApp, and returning and shredding sheets after each run. The stronger fix is a purpose-built system that gives drivers only the journey details they need, expires them when the journey ends, logs every access, and removes a leaver's access centrally, so there is nothing left in a glovebox to lose.

What would your next board or committee meeting conclude?

If a passenger's name, address and medical condition appeared in the local paper tomorrow because a run sheet went missing, could your organisation show the ICO it had done everything reasonable to prevent it? If the honest answer is no, one of the most common breaches in Britain is already on your risk register, written there or not.

This article is for educational purposes and is not legal advice. UK GDPR has been amended in part by the Data (Use and Access) Act 2025. Organisations should check current ICO guidance and seek independent advice on their specific obligations.

New Guide

Paper Run Sheets & Data Compliance

This plain English guide explains the UK GDPR risks hiding in paper run sheets, helping trustees and transport managers understand what the law demands in 2026 and how to keep their transport schemes compliant.

Send this to a friend