TL;DR:
- Shadow IT is when employees use personal or unapproved apps — personal Gmail, Dropbox, WhatsApp, Notion — to do work. Most small businesses have it; most don’t know how much
- The risks are real: client data sitting in an employee’s personal Dropbox after they leave, GDPR violations from using uncertified processors, no audit trail if something goes wrong
- The fix isn’t a blanket ban — it’s understanding why the shadow apps exist and providing approved alternatives that are actually better
Here’s a scenario that plays out constantly in UK small businesses. A new member of staff finds that the shared drive is slow and disorganised, so they start keeping their working files in their personal Dropbox. A salesperson discovers that the company email system doesn’t work well on mobile, so they forward client emails to their personal Gmail. A project manager starts a WhatsApp group with the team because the approved tool requires too many clicks.
Each of these feels like a reasonable workaround. Each one is also shadow IT — and each creates a data security and compliance problem that can surface badly if the business suffers a breach, an employment dispute, or an ICO inquiry.
What Shadow IT Actually Includes
Shadow IT is any software, service, or tool used for work purposes that hasn’t been approved by whoever manages the organisation’s systems. In a small business, that often means there’s no formal list of approved tools at all — which means everything is technically shadow IT.
The most common categories:
Cloud storage and file sharing — personal Dropbox, Google Drive, iCloud. Staff use these because they’re fast, work on all devices, and already installed. Business data ends up outside any company-controlled environment.
Messaging and communication — personal WhatsApp groups for team coordination, personal Gmail for client contact, social media DMs for supplier conversations. No archive, no audit trail, no access control when someone leaves.
Productivity tools — personal Notion workspaces, Trello boards, Airtable bases, personal ChatGPT accounts. Work planning and client data get entered into services the business has no contract with and no visibility into.
AI tools — the most rapidly growing shadow IT category. Employees use personal Claude, ChatGPT, or Gemini accounts to draft documents, summarise client data, and process internal information. The business’s data is being sent to third-party AI providers with no data processing agreement in place.
SaaS browser extensions — tools that integrate with browsers to automate tasks, enhance productivity, or access email. Many extensions have significant data access permissions and aren’t vetted by anyone.
Why This Is a Real Problem
GDPR compliance. Under UK GDPR, your business is responsible for any personal data you process, including when it’s processed by a third party on your behalf (called a data processor). If an employee sends client data to a personal AI tool, or stores it in their personal Dropbox, you have no data processing agreement with that provider. You’re also likely in breach of your privacy notice, which tells customers how their data is handled.
The ICO has investigated small businesses for exactly this kind of informal data sharing. You don’t need to be a large organisation to receive a reprimand or fine.
Data loss when staff leave. When an employee with business data in their personal accounts leaves — amicably or not — that data leaves with them. You have no way to remotely wipe a personal Dropbox, revoke access to a personal Gmail, or retrieve files from a personal device. If that data includes client lists, financial information, or intellectual property, the consequences can be severe.
No visibility if something goes wrong. If a client’s data is mishandled and there’s a complaint or ICO investigation, you need to be able to demonstrate what happened to that data. Shadow IT by definition sits outside your audit trail. You cannot reconstruct what was accessed, shared, or processed if it happened in an employee’s personal accounts.
Security gaps. Personal accounts typically don’t have the same security controls as business accounts. Multi-factor authentication may not be enabled. Password hygiene may be poor. If an employee’s personal Gmail is compromised, any client data stored there is now in the hands of whoever compromised it.
How to Find Out What Shadow IT Exists
Start by asking, not auditing. Tell your team you’re trying to understand what tools are actually being used so you can provide better alternatives — and mean it. A survey or informal conversation will surface more than monitoring software, and it won’t damage trust.
Common questions to ask:
- What apps do you use to do your job that aren’t listed on the company systems?
- Is there anything you use your personal accounts for because the work tools don’t do it well enough?
- Do you use any AI tools for work tasks? Which ones?
You’ll likely find that shadow IT exists because the approved tools are inadequate. Slow VPN, poor mobile experience, missing features, awkward login requirements — people work around friction. The shadow IT is usually a symptom of a gap in the approved toolset.
Technical discovery. If you have a managed firewall or a DNS filtering tool (like Cloudflare Gateway, which has a free tier), you can see which domains are being accessed on the company network. This won’t catch personal mobile data usage, but it shows you what’s happening in the office.
Fixing the Problem
Start with the highest-risk categories. You can’t address everything at once. Prioritise shadow IT that involves client data or personal data covered by GDPR. Personal AI tools processing client information and personal cloud storage holding client files are the first things to address.
Provide better alternatives. If you ban personal Dropbox without providing a working, convenient alternative, the workaround will continue — just less visibly. Microsoft 365 and Google Workspace both include cloud storage, communication tools, and collaboration features. If your business is already paying for these, ensure the tools are properly configured and staff know how to use them.
Address the AI tools question directly. Many employees are using AI tools because they’re genuinely useful and the business hasn’t provided an approved option. Evaluate an enterprise-grade AI tool — Microsoft Copilot (included in some M365 plans), Google Workspace’s AI features, or a standalone tool with a proper data processing agreement — and make it the default.
Create a simple approved tools list. You don’t need a complex IT policy. A single-page list of approved tools for common tasks (file sharing, communication, AI assistance, note-taking) removes ambiguity. When staff know there’s an approved option, they’re less likely to reach for a personal one.
Set expectations for data handling when staff leave. Include in employment contracts and offboarding procedures a clear requirement to transfer and delete any work data held in personal accounts. This is easier to enforce if it’s established policy rather than an afterthought when someone resigns.
Review connected apps on business accounts. Many shadow IT problems come not from entirely separate apps, but from personal tools that have been granted access to business accounts — a personal productivity tool that someone connected to the company Google account, for example. Audit OAuth permissions on your Google Workspace or Microsoft 365 admin console quarterly and revoke access for anything not explicitly approved. (There’s a separate guide on this: OAuth third-party app permissions audit for small businesses.)
The GDPR Documentation Piece
If an ICO investigation or client complaint requires you to demonstrate your data handling practices, you’ll need to show a Record of Processing Activities (ROPA) — a list of what personal data you process, for what purpose, and under what legal basis. Shadow IT makes it impossible to maintain an accurate ROPA.
Bringing shadow IT into the open doesn’t just reduce security risk — it makes your data protection documentation meaningful. Once you know what tools are being used and why, you can either bring them into your approved framework (sign a data processing agreement with the provider, update your ROPA) or migrate to alternatives that are already covered.
The ICO provides free guidance and template documentation for small businesses on its website. Getting your ROPA in order is a manageable task for most small businesses once the shadow tools are understood.
The Right Frame
Shadow IT isn’t a discipline problem — it’s a tooling problem. Employees use personal apps because those apps solve a real problem that the approved tools don’t. The productive response is to acknowledge this, understand what the tools are being used for, and provide approved alternatives that are as convenient.
The goal isn’t perfect visibility into every tool employees use. It’s ensuring that data covered by GDPR — client records, employee data, financial information — stays within environments you control and have appropriate agreements with. Everything else is secondary.