Guides
Data recovery and privacy after a repair, following ICO guidance for UK consumers
How UK consumers can keep control of personal data through a device repair, from secure wipe and backup to ICO complaints and breach reports.
What to take away
- A repairer holds your personal data, it does not own it, and UK GDPR still applies to a phone left on a counter.
- Most repairs, including screens, charging ports and batteries, need no access to your files at all.
- Back up, sign out of accounts, pull the SIM and memory card, then wipe only if the fault can still be tested.
- A subject access request is free and the repairer normally has one month to answer it.
- If data is exposed, report to the ICO yourself; the ICO regulates, it does not recover files or pay compensation.
Your data rights when you hand over a device
Handing a laptop to a repairer does not transfer the data on it. Under the UK GDPR and the Data Protection Act 2018, personal data is anything relating to an identified or identifiable living person. That covers photos, messages, contacts, saved passwords and a serial number tied to you.
The repairer becomes a controller or processor of that data. It needs a lawful reason to open it, must keep it secure, and must delete it when the job ends. A screen swap, a charging port fix or a battery replacement normally needs none of your files.
Ask what the shop will do with your data, and get the answer in writing. A text or email is enough. If nobody can explain the process, treat that as the warning sign it is.
Postal repairs raise the stakes. The device leaves your hands for days and passes through more than one pair of them. Ask where it is stored overnight and who can reach it.
Your rights are access, correction, erasure, restriction, portability and objection. You can also complain to the Information Commissioner's Office. Those rights bind a two-person repair shop exactly as they bind a bank.
The For the public | ICO hub explains those rights in plain terms, and it is the page to read before you agree to anything.
Keep a handover record: date, repairer, fault, and what you agreed about data. That note is what you rely on if the repair goes wrong.
How the ICO framework applies to a repair bench
The ICO writes for organisations, but the same text tells you whether a repairer is behaving. The test is accountability: a business must be able to show how it protects your data.
In practice that means limiting access to what the job needs, training staff, and having a written wipe process. It also means keeping a record of what was processed. A technician who copies your photos to a personal laptop to test the camera has created a data protection problem.
Ask the questions the framework implies. Where is the device kept overnight? Who has access? Is the wipe a secure erase or a factory reset? Is a backup kept, and for how long? Vague answers are the risk.
The ICO's UK GDPR guidance and resources sets out these principles:
- Lawfulness
- Fairness
- Transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity
- Confidentiality
Route changes the risk. A high street shop fixes the device in front of you. A mail-in service sends it to a central workshop. A manufacturer scheme may route it overseas. Each one puts your data in different hands.
If you are weighing those routes, smartphone repair routes compared sets out price, turnaround and privacy for the common UK options. A cheaper mail-in job can mean the device travels further, which is a choice worth making deliberately rather than by default.
Preparing a device for handover
- Back up what you cannot lose, using the platform tool or an encrypted drive you control, and open the backup once to prove it works.
- Sign out of Apple, Google, Microsoft and banking apps, and remove stored payment cards.
- Take out the SIM and any memory card; contacts, messages and photos often sit there.
- Wipe the device only if the fault can still be demonstrated afterwards.
- Write down what you removed, when, and where the backup lives.
If the handover process is unfamiliar, prepare device for repair walks through it without losing the files you need. The goal is a device that is clean but still shows the fault.
Some jobs need the device left exactly as it is. Data recovery is the obvious one, because wiping destroys the thing you are paying to retrieve. Choose a specialist with a written data handling policy and ask what happens to the recovered files afterwards.
A repair intake checklist records identity, fault, backup and authorisation in one place. Both sides then have evidence of what was agreed.
- Back up photos, messages, contacts and documents
- Sign out of Apple, Google, Microsoft and banking apps
- Remove SIM and memory cards
- Decide whether the passcode is shared, and with whom
- Ask for the data handling policy in writing
- Record the handover date, fault and agreed price
- Confirm what happens to your data after the repair
If a repairer wants your passcode for a screen replacement, ask what test requires it. Some do, many do not. Change the passcode once the device is back.
When data is mishandled
Mishandling covers a wide range. Photos surface on a technician's social feed. An account is accessed. The device returns with a stranger's files on it. Or the shop simply will not say what happened to your data.
Write to the repairer first. State what happened, which data is involved, and what you want. Ask directly whether the data was accessed, copied, shared or lost. Keep it factual and keep a copy.
If the business belongs to a trade body or accredited scheme, raise it there as well. The Chartered Trading Standards Institute and the Office for Product Safety and Standards both work on consumer protection, though neither handles data protection complaints.
For data protection, the regulator is the ICO. The Make a complaint | ICO route is free, and the ICO can require the organisation to explain itself.
Compensation for damage or distress is a separate track from an ICO complaint. Keep bank statements and correspondence that show the loss, and take advice from Citizens Advice or a solicitor.
If the repairer goes quiet, check whether it still trades. Company status is public at Companies House, and a dissolved business is hard to pursue.
Do not delete your own evidence. Keep messages, receipts, photographs of the device and screenshots of anything exposed. If data appeared online, note the URL and the date before it disappears.
Subject access requests and your other rights
A subject access request, or SAR, is how you ask an organisation for a copy of your personal data. You can send one to a repairer. It is free in most cases, and the reply is normally due within one month.
No special form is needed. Say who you are, what data you want, and how you would like it delivered. The repairer may ask for ID, which is reasonable.
After a repair, a SAR shows what notes were kept, whether your data was shared, and what happened to it. A refusal without a valid reason is itself something you can complain about.
The ICO's Subject access requests (also known as SARs or right of access) | ICO covers time limits, fees, exemptions and complaints. It is written for organisations, and it tells you what to expect.
Other rights apply too. You can have inaccurate data corrected, data erased when it is no longer needed, and processing restricted while a dispute runs. None of these is absolute.
Marketing data is easier to stop. If a repairer relies on consent, you can withdraw it. If it claims a legitimate interest, you can still object, and it must show why its interest outweighs yours.
Send the request dated, keep the sent copy, and use tracked post if you write. The clock starts when the organisation receives it.
Reporting a breach
A personal data breach is a security incident causing accidental or unlawful loss, alteration, disclosure of, or access to personal data. A repairer exposing your files is a breach.
Organisations must report certain breaches to the ICO within 72 hours of becoming aware. They must also tell affected people when the breach is likely to mean a high risk to their rights. The ICO's Report a breach | ICO page sets out the duty.
You can report a breach yourself and do not have to wait for the repairer. Report online with the business name, what happened, and which data was involved.
The ICO assesses the report. It may ask the organisation for more information, issue advice, or take regulatory action. It does not usually award compensation, which is a matter for a court or a settlement.
Reporting also builds a pattern. Several reports about one business let the ICO act on the pattern rather than a single incident.
If financial data is involved, tell your bank at once. If identity documents are involved, consider a fraud alert with a credit reference agency. Both sit alongside an ICO report, not instead of it.
Keep your report and any reference number. If you later claim compensation, it shows you acted promptly.
Data recovery: access against security
Recovery is the hard case. A specialist often needs the device in its current state, personal data included, because wiping destroys the evidence you are trying to save.
You still hold your rights. Choose the repairer carefully and agree the terms in writing. Ask what will be copied, where it is stored, who can see it, when it is deleted, and whether the work happens in the UK.
A good specialist will say what is recoverable, what is not, and what happens to the files afterwards. Vagueness on all three is the signal to walk away.
If the device is a work laptop or phone, tell your employer before anyone touches it. Workplace data may fall under the employer's own policies, and the employer may need to handle the breach or the recovery.
Shared family devices raise the same point. A tablet can hold photos and documents belonging to several people, and each of them has rights over their own data.
If the fault is not yet pinned down, our repair diagnosis guide separates hardware faults from software ones before any repair that touches storage.
If the quote moves after diagnosis, treat that as a separate dispute. Vague diagnoses and shifting bills are common, and repair quote problems covers how to challenge them without losing sight of the data question.
Decide the end of life early. A device beyond repair goes through a licensed WEEE route, not the bin. The UK WEEE Regulations cover waste electrical and electronic equipment, and proper disposal cuts the chance of data lingering on discarded hardware.
Common questions
Does a repairer own my data once I hand over the device?
No. You stay the data subject and the repairer holds the data only to do the job. It needs a lawful reason, must keep it secure, and must delete it when it is no longer needed.
Can I refuse to give my passcode?
Yes, unless the repair genuinely requires it, and many do not. Ask what test needs it and what will happen to the data. If you agree, change the passcode after collection.
How long does a subject access request take?
Usually one month from the day the repairer receives it. Complex requests can be extended by two months, and the organisation may ask for ID before it replies.
What counts as a personal data breach after a repair?
Any security incident involving your data, including unauthorised access, loss or disclosure. A technician copying photos, or a device lost in transit, both count.


