• Expertenmeinungen

How to Assess Data Security When Buying Commercial Cleaning Robots

September 07, 2026

A commercial cleaning robot is a networked device. It maps the building it works in, and it reports each task to a cloud account. For an airport, a hospital group, a bank, or a public authority, that makes it part of the IT estate rather than only a line in the cleaning budget.

Assessing data security comes down to three checks: whether the manufacturer holds independently audited information security and privacy certification, whether it states where data is stored and how long it is kept, and whether the security measures it applies are named in a document rather than asserted in a meeting.

Gausium is certified to ISO/IEC 27001 and ISO/IEC 27701, and its privacy policy sets out server region selection, retention, and the measures applied to protect personal information. The sections below explain what each of the three checks involves, and how to apply them to any supplier under consideration.

What a Connected Cleaning Robot Collects

Before comparing certifications, it helps to agree internally on which data is in scope. A connected floor cleaning robot generates four kinds of data, and they carry different levels of sensitivity:

  • Spatial data — the map the robot builds and uses to localize itself, including room layouts, restricted zones, and route plans.
  • Sensor data — input from cameras, depth sensors, and LiDAR used to detect obstacles and people in real time.
  • Operational data — task records, coverage, runtime, water and consumable use, fault codes, and cleaning history, the material that appears in cleaning robot performance reporting.
  • Account data — the identities and contact details of the supervisors and operators who log in to the fleet platform.

Security reviews tend to concentrate on the second category. In practice the first and third are the ones a facility team is asked about later, because a floor plan of a restricted area and a timestamped record of when a corridor was unoccupied are both useful to someone who should not have them.

A short written answer covering all four categories — which data leaves the site, which stays on the machine, which is retained after a task ends — is enough to pass to a security officer without further translation.

How to Assess Data Security When Buying Commercial Cleaning Robots

Two Certifications Carry the Weight, and They Cover Different Things

Cleaning robot manufacturers reference a long list of marks. For data security, two international standards are usually decisive, and they are not interchangeable.

ISO/IEC 27001 certifies an information security management system. An independent auditor has examined how the organization identifies information risks, assigns ownership, applies controls, and reviews them over time.

ISO/IEC 27701 extends that system to privacy. It covers how the organization handles personal data in its roles as controller and as processor, which is the part that applies when operator accounts and building imagery sit on a manufacturer-run platform.

Certification

What it examines

What it tells a buyer

ISO/IEC 27001

The organization’s information security management system

Security is governed by an audited process rather than individual practice

ISO/IEC 27701

Privacy controls layered on top of that system

Personal data handling has been assessed by a third party

Product safety and radio marks

Product conformity for safety and electromagnetic compatibility

No statement about information security or privacy

Gausium holds both standards, certified by SGS. Its ISO/IEC 27701 certificate was the first award of that standard in the industry to carry UKAS accreditation, and the certification announcement names the issuing body and the accreditation in full. Accreditation carries more weight than it may appear to: UKAS is a national accreditation body that assesses certification bodies themselves, so an accredited certificate reflects a check on the auditor as well as on the organization audited.

How to Assess Data Security When Buying Commercial Cleaning Robots

The Two Editions of ISO/IEC 27701

ISO/IEC 27701 was first published in 2019 as an extension to ISO/IEC 27001. A revised edition, ISO/IEC 27701:2025, was published in October 2025 as a standalone privacy management standard.

Certificates across the market, including Gausium’s, were issued against the 2019 edition. Transition arrangements for a revised standard are set by accreditation bodies rather than by the standard itself, and the current requirements are published by the International Accreditation Forum, where the position on any given date can be confirmed.

What to Check on a Certificate

A standard number on a web page carries limited information. The certificate itself does most of the work, and five fields on it are worth reading:

  • The scope statement. It names the legal entities, sites, and services covered. A certificate that covers a manufacturing site but not the cloud platform a fleet reports to does not cover the relevant risk.
  • The certification body and its accreditor. Accredited certification means a national accreditation body has assessed the auditor, and it generally carries more weight in a tender framework than certification without accreditation.
  • The edition of the standard named. This indicates which transition arrangements, if any, apply.
  • Issue date, expiry date, and surveillance audits. Certification runs on a cycle, and annual surveillance is what keeps it current, so it is worth confirming the certificate in force today rather than an image saved from an earlier year.
  • The contracting entity. In Europe and North America, machines are often supplied through a distributor. Confirm whether the certified entity is also the entity that signs the contract and hosts the account.

Certificate numbers and scope statements are not always published on a manufacturer’s website, so their absence is not in itself a finding. Requesting the certificate directly, and passing it to whoever normally reviews supplier attestations, settles the question.

Where Data Is Stored, and How Long It Is Kept

Storage location is the item most likely to come back from a legal or compliance reviewer, particularly for public-sector and healthcare buyers in Europe.

Gausium’s privacy policy states that users can choose the cloud server area where their personal information is stored, based on their location. The policy is short enough to read in full, and it is the text to quote in an assessment. The provisioned region, and whether it can be changed later, are then worth confirming in the contract.

The same policy describes the retention period for personal information as running until the account is cancelled, and states that personal information is deleted after cancellation, except where a defined retention period is required by applicable laws and regulations.

On requests to access, correct, or delete personal information, it states that verified requests are processed within five working days, and that in special circumstances a response is provided within a maximum of thirty days or the period set by applicable law.

A privacy policy of this kind is written around the personal information handled through the account and the mobile app.

Storage location and retention for robot-generated data — floor maps, camera and sensor recordings, task history — is a separate question, and a written answer per data category is more useful than an inference drawn from a privacy policy. 

It is also worth asking what happens to each category at the end of a contract.

The Security Measures Behind the Platform

A named set of measures is more useful in an assessment than a general assurance, because each item can be checked against the buyer’s own policy.

Gausium’s privacy policy states that industry standard security measures are used to protect the personal information provided, and names firewall protection, encryption such as SSL, de-identification or anonymization, and access control measures. The policy text is the reference point, and that level of specificity is a reasonable expectation of any manufacturer.

Two follow-up questions turn a named list into usable evidence:

  • Which of these measures apply to the fleet management platform, as distinct from the mobile app?
  • Who holds administrative access to the account, and how is that access logged?

What Certification Does Not Cover

Three gaps recur in cleaning robot tenders.

Product marks are not security statements. A safety or radio-compliance mark confirms that a machine meets product conformity requirements. It does not address how data is stored, transmitted, or shared, and it does not substitute for an information security certificate. Where a mark is offered in this context, the standard it certifies and that standard’s scope are worth reading.

Certification covers the system, not every release. An audited management system supports secure development, but it does not certify each firmware version, which is why vulnerability handling belongs in the assessment separately.

Gausium publishes platform advisories on its cybersecurity notifications page, and how customers are informed when an advisory is issued is a fair question to put to any manufacturer.

Physical safety is a separate assessment track. Obstacle avoidance, emergency stop behavior, and safe operation around people are assessed against a different family of standards, covered in Gausium’s guide to commercial cleaning robot safety.

Keeping the two tracks separate in an evaluation matrix prevents one from absorbing the other.

Writing Data Security Into the Procurement Requirement

Data security often arrives late in cleaning robot procurement, after candidate models have been shortlisted on cleaning performance. Moving it forward costs very little and changes the shortlist, because the answers are documentary rather than technical and can be compared side by side.

Four clauses are usually enough:

  1. The supplier shall provide current ISO/IEC 27001 and ISO/IEC 27701 certificates, including scope statements naming the cloud platform used for fleet management, and shall state the edition of each standard.
  2. The supplier shall state the storage region for all account and operational data, and confirm whether the region is selectable.
  3. The supplier shall provide retention periods per data category, including map and sensor data, and a documented deletion process at contract termination.
  4. The supplier shall enter into a data processing agreement covering the jurisdiction in which the fleet operates.

Buyers working to these requirements can review the connected models in Gausium’s product range and raise the same four items with the sales team during the site assessment that covers floor types and cleaning area, which keeps security and cleaning performance on one timeline instead of two.

FAQ About Data Security in Commercial Cleaning Robots

Q1: Which Certification Matters Most for Cleaning Robot Data Security?

ISO/IEC 27001 is the baseline, because it certifies an audited information security management system. ISO/IEC 27701 adds privacy controls for personal data, and it is usually the standard that satisfies a data protection reviewer.

Q2: Does a CE or FCC Mark Cover Data Security?

No. Those marks address product safety and electromagnetic compatibility. They make no statement about data storage, transmission, or privacy, and are not evidence of information security.

Q3: How Does Gausium Protect Cleaning Robot Data?

Gausium is certified to ISO/IEC 27001 and ISO/IEC 27701, and its privacy policy names firewall protection, encryption such as SSL, de-identification or anonymization, and access control measures applied to the personal information provided.

Q4: Where Is Cleaning Robot Data Stored?

Gausium’s privacy policy states that users can choose the cloud server area where their personal information is stored, based on their location. Storage arrangements for robot-generated map and sensor data are confirmed during deployment planning.

Q5: How Are Data Access and Deletion Requests Handled?

Gausium’s privacy policy states that verified requests are processed within five working days, extending to a maximum of thirty days in special circumstances, and that data required to be retained by law is kept after account cancellation.

Q6: What Should a Procurement Requirement Cover?

Certification with scope statements and edition, the storage region and whether it is selectable, retention periods per data category including map and sensor data, and a data processing agreement for the relevant jurisdiction.

Sources

Where a statement above is attributed to a policy or an announcement, the source text below is the version to rely on.