---
title: "Meet NIS2, DORA & GDPR Compliance | Firevault"
url: https://fire-vault.com/compliance/uk-gdpr-physical-disconnection
description: "Navigate complex data regulations with our dedicated compliance hub. We detail how offline storage helps meet NIS2, DORA, and GDPR obligations. Explore."
lang: en-GB
---

Whitepaper, UK GDPR, Article 32

# Physical Disconnection And UK GDPR

Technical whitepaper: why physical disconnection at Layer 1 is a stronger technical measure under UK GDPR Article 32 than logical isolation, and how to evidence it to the ICO, insurers and your board.

- Offline by default
- Identity locked access
- Hardware encrypted

Framework matrix: https://fire-vault.com/compliance/frameworks

Image: Security analyst reviewing an isolated workstation with disconnected cables (https://fire-vault.com/assets/hero-square-analyst-DI5B7V_E.jpg)

Art. 32

UK GDPR security of processing, including timely restore

£17.5m

Maximum UK GDPR fine, or 4% of global turnover if higher

Layer 1

Where Offline Secure Storage® disconnects, below the network

01 The requirement

## Article 32 Asks For Measures Appropriate To The Risk

UK GDPR Article 32 requires appropriate technical and organisational measures, including the ability to ensure ongoing confidentiality, integrity and availability, and the ability to restore availability and access to personal data in a timely manner after an incident. Article 5(1)(f) adds the integrity and confidentiality principle. The ICO expects controllers to consider the state of the art. Logical isolation reduces exposure, but a copy that remains addressable on a network remains within reach of a compromised credential. This paper is a technical argument, not legal advice.

This is a mapping, not a certification claim. Firevault holds Cyber Essentials Plus. Everything else on this page is stated as alignment: Offline Secure Storage® produces evidence you can point at in your own submission, assessment or audit.

- Art. 32 — UK GDPR security of processing, including timely restore. Source: ICO, A guide to data security (https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/)
- £17.5m — Maximum UK GDPR fine, or 4% of global turnover if higher. Source: ICO (https://ico.org.uk/for-organisations/law-enforcement/guide-to-le-processing/penalties/)

02 What is tested

## Physical Versus Logical, The Technical Argument

Each line below is something an assessor, regulator or underwriter can ask you to evidence.

Logical isolation (VLANs, firewalls, object lock) is enforced by software that can be misconfigured or bypassed

An immutable bucket is still reachable over an API with valid credentials

Physical disconnection removes the network path entirely while offline

Availability after an incident depends on a copy the attacker could not reach

Confidentiality improves when exfiltration has no route to the data

Evidence of the disconnected state is simpler to prove than a policy configuration

03 Consequences

## Where Logical Isolation Leaves Residual Risk

What happens when the control is missing, and the record cannot be produced.

### Always Addressable

Anything with an IP address can be scanned, targeted and eventually reached.

### Credential Compromise

Stolen administrator or cloud console credentials can change retention, delete or exfiltrate.

### Configuration Drift

Firewall rules and bucket policies change over time, often without the data owner knowing.

### Exfiltration Path

A logically isolated copy can still be copied out, creating a reportable personal data breach.

04 The architecture

## Physical Disconnection As A Technical Measure

Offline Secure Storage® holds personal data on dedicated hardware in the customer's chosen jurisdiction, physically disconnected between identity-verified windows.

### Integrity And Confidentiality

With no network interface while offline, there is no remote path to alter, encrypt or exfiltrate the copy.

### Timely Restore (Art. 32(1)(c))

Scheduled restore windows return a clean copy after ransomware, supporting availability duties.

### Hardware Encryption At Rest

Data is encrypted on dedicated hardware, with identity factors held by the customer.

### Jurisdiction Chosen By You

Bunkers across Europe including the UK, so international transfer questions are answered by design.

### Regular Testing (Art. 32(1)(d))

Recurring verification windows test and evaluate the effectiveness of the measure.

### Accountability Evidence

Every connection, identity check and restore is logged to support Article 5(2) accountability.

“A policy can be changed by whoever holds the keys. A cable that is not connected cannot. That is why physical disconnection is the stronger measure.”

Mark Fermor, CTO, CMO & Founder, Firevault

05 What sits offline

## Personal Data Best Held Offline

The records most often moved into Offline Secure Storage® for this framework.

HR and payroll records

Client and patient records

Legal case files

Customer databases

CCTV and identity documents

Backups of production systems

### Alongside, not instead of

Physical disconnection complements encryption, access control and immutable backups. It provides the copy of last resort.

### Aligned with NCSC

The NCSC advises keeping at least one backup offline. Physical disconnection turns that advice into a provable state.

### Easier breach assessment

If the offline copy had no network path during an incident, it is simpler to show it was not affected.

### Not legal advice

Controllers remain responsible for their own risk assessment. Firevault supplies the architecture and the evidence.

UK GDPR and Offline Secure Storage: https://fire-vault.com/compliance/gdpr

Layer 1 vs logical air gap: https://fire-vault.com/learn/physical-vs-logical-air-gap

NCSC ransomware-resistant backups: https://fire-vault.com/compliance/ncsc-ransomware-resistant-backups

All compliance frameworks: https://fire-vault.com/compliance

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-aWtKNSv7.jpg)

Image: David Bailey (https://fire-vault.com/assets/david-bailey-Dgqj8eaE.jpg)

Image: Kenny Phipps (https://fire-vault.com/assets/kenny-phipps-Dy-CtCjw.jpg)

Online Now

Get started

## Tell us which framework you are being tested against.

We will map Offline Secure Storage® to the outcomes your assessor is checking, and give you the wording and evidence to submit.

From £360 a month including VAT. 36-month commitment. First payment at checkout.

From £360/mo VAT included 36-month plan

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/compliance/uk-gdpr-physical-disconnection#webpage",
    "url": "https://fire-vault.com/compliance/uk-gdpr-physical-disconnection",
    "name": "Meet NIS2, DORA & GDPR Compliance",
    "description": "Navigate complex data regulations with our dedicated compliance hub. We detail how offline storage helps meet NIS2, DORA, and GDPR obligations. Explore.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/compliance/uk-gdpr-physical-disconnection#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/compliance/uk-gdpr-physical-disconnection#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Compliance",
        "item": "https://fire-vault.com/compliance"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Meet NIS2, DORA & GDPR Compliance",
        "item": "https://fire-vault.com/compliance/uk-gdpr-physical-disconnection"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  }
]
```