The personnel spreadsheet on somebody’s laptop
Echipa HR 365 · reviewed 2026-09-09 · 5 min read
A personnel file saved locally is not an information security problem, it is a process problem: it was not downloaded out of bad intent, but because it was the only way to produce a report. As long as that remains the only way, the files will keep appearing, whatever policies you write.
Why they actually appear
| Situation | What should have existed | What happens |
|---|---|---|
| A report requested urgently | A report in the system | An export with every column, worked on in a spreadsheet |
| An analysis the system does not do | A reporting function | Export, manual calculation, file saved |
| Working from home, without access | Remote access | Copied onto a personal laptop |
| Preparing for a meeting | A screen shared in the meeting | A file emailed to every participant |
What the risk actually is
- The file stays on the laptop after the person changes role or leaves the company.
- It gets forwarded, with every column, because that is faster than stripping out what should not go.
- It is opened on a screen visible to someone else, in a shared office or a meeting.
- Nobody knows it exists, so it is neither updated nor deleted when the data changes.
- A lost or stolen laptop suddenly contains the whole company’s salaries.
The fourth point is the most underrated and produces a different kind of risk: an old file stays correct in form and false in content. Someone opens it a year later, believes it is current, and makes a decision on twelve-month-old data.
Four measures that need no budget
In order of effect
- 1 — Separate the sensitive columns from the rest. An export without salaries covers most reporting and is no longer dangerous.
- 2 — Build the frequent reports directly in the system. Every available report removes a category of exports.
- 3 — Put a date in the name of every export and set a deletion convention: exports older than a month get deleted.
- 4 — Search the shared drive once a quarter for the words “export”, “salaries”, “personnel”.
The first measure is the most effective and takes an hour. Most reporting does not need salaries — it asks for headcount, structure, tenure. A standard export without the sensitive columns covers nine requests out of ten and reduces the risk almost to zero.
The case of personal laptops
The hardest to control and the most often ignored. If somebody works from home on their own equipment, you cannot clean anything at their departure and you cannot verify anything during the engagement. The only levers are upstream: remote access that does not require downloading, and a clearly stated rule about what is not copied locally.
The rule works only if the alternative exists. “Do not download files onto your personal computer”, with no way of working remotely, is a prohibition people will break in order to do their job — and they will be right.
What do I do about the files that already exist?
Search the shared drive, make the list, and for each one decide: move it into the system, archive it with restricted access, or delete it. It takes a morning and does not recur at the same scale.
Is a cloud spreadsheet safer than a local one?
On access and versioning, yes — but the underlying problem remains: it is still a copy of the data, outside the system, with its own access rights granted ad hoc and never reviewed.
Where to start
Search the shared drive for “export” and “salaries”. What you find in five minutes is usually enough to make the discussion concrete.
Then ask why each one was made. The answer gives you the list of reports missing from the system — and that is the real repair.
How you hold the conversation with the team
The tone decides whether the practice changes or merely hides. A message that sounds like an accusation produces, predictably, files saved in harder-to-find places. What works is starting from the cause rather than from the behaviour.
| You do not say | You say |
|---|---|
| Stop downloading data onto computers | Which reports do you currently produce from exports? Let us build them in the system. |
| This is a policy violation | I want full exports to stop being necessary |
| Delete everything you hold locally | Let us make the list and decide together what moves and what goes |
The first column produces apparent compliance; the second produces the list of missing reports — which is exactly the information you need for the problem not to reappear in six months.
If a laptop is lost anyway
The first question is not “what was on it” but “who can know what was on it”. If the answer is “nobody”, that is the underlying problem — and it is solved beforehand, by keeping a record of exports, not on the day of the incident.
How often do I check the shared drive?
Quarterly is enough after the first clean-up. The first time takes a morning; the following ones under an hour, because the new volume is small if the missing reports have been added in the meantime.
What about the exports that are genuinely needed?
You keep them, with three conditions: only the necessary columns, a date in the name, and a location with restricted access — not the department’s shared folder.
Does password-protecting the file solve it?
It reduces the risk of loss, not the risk of circulation or of old data being read as current. A password is useful and does not replace the question of why the file was needed.
Reports in the system, with exports limited to the necessary columns
Frequent reporting happens directly, and an export can be limited to what is needed — so the file with every column is no longer the only route.
Free account, every module for 7 days, no card required.