Article 32 covers more than IT
Article 32 of the UK GDPR requires controllers and processors to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, expressly including the ability to ensure the ongoing confidentiality of processing systems and services. Article 5(1)(f) makes integrity and confidentiality a core processing principle.
The ICO's security guidance has always treated physical security as part of the Article 32 assessment alongside cyber measures. The question a controller must be able to answer is not whether it bought security products, but whether the measures match the risk to the specific personal data it processes — including data that exists as conversation.
When overheard speech is a data breach
Disciplinary hearings, occupational health conversations, safeguarding discussions, and HR casework all involve personal data — often special category data — communicated verbally in rooms assumed to be private. A covert listening or recording device in such a room means unauthorised disclosure of personal data: a personal data breach as defined in Article 4(12).
That triggers the breach machinery. Article 33 requires notification to the ICO without undue delay and where feasible within 72 hours of awareness, unless the breach is unlikely to result in a risk to individuals. Article 34 may require informing the affected individuals. The discovery of a device in an HR meeting room is very hard to argue out of either obligation, because you usually cannot establish how long it was live.
Proportionate measures, defensible records
Nothing in the UK GDPR obliges every organisation to run technical sweeps. Article 32 is risk-based: the state of the art, the costs of implementation, and the nature and scope of processing all weigh in. For organisations that routinely process sensitive personal data in defined rooms — HR suites, clinical consulting rooms, legal offices — a periodic inspection of those spaces is a proportionate measure that is cheap relative to the risk it addresses.
As with every Article 32 measure, the record matters as much as the measure. A documented technical surveillance risk assessment, a short list of protected rooms, an inspection cadence and dated findings give you an answer to the regulator's first question after any incident: what did you do to prevent this, and can you show it?