The personnel spreadsheet on somebody’s laptop

Echipa HR 365 · reviewed 2026-09-09 · 5 min read

A personnel file saved locally is not an information security problem, it is a process problem: it was not downloaded out of bad intent, but because it was the only way to produce a report. As long as that remains the only way, the files will keep appearing, whatever policies you write.

Why they actually appear

The situation and how you end up with a local file
SituationWhat should have existedWhat happens
A report requested urgentlyA report in the systemAn export with every column, worked on in a spreadsheet
An analysis the system does not doA reporting functionExport, manual calculation, file saved
Working from home, without accessRemote accessCopied onto a personal laptop
Preparing for a meetingA screen shared in the meetingA file emailed to every participant

What the risk actually is

The fourth point is the most underrated and produces a different kind of risk: an old file stays correct in form and false in content. Someone opens it a year later, believes it is current, and makes a decision on twelve-month-old data.

Four measures that need no budget

In order of effect

  1. 1 — Separate the sensitive columns from the rest. An export without salaries covers most reporting and is no longer dangerous.
  2. 2 — Build the frequent reports directly in the system. Every available report removes a category of exports.
  3. 3 — Put a date in the name of every export and set a deletion convention: exports older than a month get deleted.
  4. 4 — Search the shared drive once a quarter for the words “export”, “salaries”, “personnel”.

The first measure is the most effective and takes an hour. Most reporting does not need salaries — it asks for headcount, structure, tenure. A standard export without the sensitive columns covers nine requests out of ten and reduces the risk almost to zero.

The case of personal laptops

The hardest to control and the most often ignored. If somebody works from home on their own equipment, you cannot clean anything at their departure and you cannot verify anything during the engagement. The only levers are upstream: remote access that does not require downloading, and a clearly stated rule about what is not copied locally.

The rule works only if the alternative exists. “Do not download files onto your personal computer”, with no way of working remotely, is a prohibition people will break in order to do their job — and they will be right.

What do I do about the files that already exist?

Search the shared drive, make the list, and for each one decide: move it into the system, archive it with restricted access, or delete it. It takes a morning and does not recur at the same scale.

Is a cloud spreadsheet safer than a local one?

On access and versioning, yes — but the underlying problem remains: it is still a copy of the data, outside the system, with its own access rights granted ad hoc and never reviewed.

Where to start

Search the shared drive for “export” and “salaries”. What you find in five minutes is usually enough to make the discussion concrete.

Then ask why each one was made. The answer gives you the list of reports missing from the system — and that is the real repair.

How you hold the conversation with the team

The tone decides whether the practice changes or merely hides. A message that sounds like an accusation produces, predictably, files saved in harder-to-find places. What works is starting from the cause rather than from the behaviour.

How you phrase it
You do not sayYou say
Stop downloading data onto computersWhich reports do you currently produce from exports? Let us build them in the system.
This is a policy violationI want full exports to stop being necessary
Delete everything you hold locallyLet us make the list and decide together what moves and what goes

The first column produces apparent compliance; the second produces the list of missing reports — which is exactly the information you need for the problem not to reappear in six months.

If a laptop is lost anyway

The first question is not “what was on it” but “who can know what was on it”. If the answer is “nobody”, that is the underlying problem — and it is solved beforehand, by keeping a record of exports, not on the day of the incident.

How often do I check the shared drive?

Quarterly is enough after the first clean-up. The first time takes a morning; the following ones under an hour, because the new volume is small if the missing reports have been added in the meantime.

What about the exports that are genuinely needed?

You keep them, with three conditions: only the necessary columns, a date in the name, and a location with restricted access — not the department’s shared folder.

Does password-protecting the file solve it?

It reduces the risk of loss, not the risk of circulation or of old data being read as current. A password is useful and does not replace the question of why the file was needed.

Reports in the system, with exports limited to the necessary columns

Frequent reporting happens directly, and an export can be limited to what is needed — so the file with every column is no longer the only route.

See the reports

Free account, every module for 7 days, no card required.