UP NEXT
Cleaning Robots That Charge Automatically: Which Models and What a Dock Covers02 września, 2026
07 września, 2026
A commercial cleaning robot is a networked device. It maps the building it works in, and it reports each task to a cloud account. For an airport, a hospital group, a bank, or a public authority, that makes it part of the IT estate rather than only a line in the cleaning budget.
Assessing data security comes down to three checks: whether the manufacturer holds independently audited information security and privacy certification, whether it states where data is stored and how long it is kept, and whether the security measures it applies are named in a document rather than asserted in a meeting.
Gausium is certified to ISO/IEC 27001 and ISO/IEC 27701, and its privacy policy sets out server region selection, retention, and the measures applied to protect personal information. The sections below explain what each of the three checks involves, and how to apply them to any supplier under consideration.
Before comparing certifications, it helps to agree internally on which data is in scope. A connected floor cleaning robot generates four kinds of data, and they carry different levels of sensitivity:
Security reviews tend to concentrate on the second category. In practice the first and third are the ones a facility team is asked about later, because a floor plan of a restricted area and a timestamped record of when a corridor was unoccupied are both useful to someone who should not have them.
A short written answer covering all four categories — which data leaves the site, which stays on the machine, which is retained after a task ends — is enough to pass to a security officer without further translation.

Cleaning robot manufacturers reference a long list of marks. For data security, two international standards are usually decisive, and they are not interchangeable.
ISO/IEC 27001 certifies an information security management system. An independent auditor has examined how the organization identifies information risks, assigns ownership, applies controls, and reviews them over time.
ISO/IEC 27701 extends that system to privacy. It covers how the organization handles personal data in its roles as controller and as processor, which is the part that applies when operator accounts and building imagery sit on a manufacturer-run platform.
|
Certification |
What it examines |
What it tells a buyer |
|
The organization’s information security management system |
Security is governed by an audited process rather than individual practice |
|
|
Privacy controls layered on top of that system |
Personal data handling has been assessed by a third party |
|
|
Product safety and radio marks |
Product conformity for safety and electromagnetic compatibility |
No statement about information security or privacy |
Gausium holds both standards, certified by SGS. Its ISO/IEC 27701 certificate was the first award of that standard in the industry to carry UKAS accreditation, and the certification announcement names the issuing body and the accreditation in full. Accreditation carries more weight than it may appear to: UKAS is a national accreditation body that assesses certification bodies themselves, so an accredited certificate reflects a check on the auditor as well as on the organization audited.

ISO/IEC 27701 was first published in 2019 as an extension to ISO/IEC 27001. A revised edition, ISO/IEC 27701:2025, was published in October 2025 as a standalone privacy management standard.
Certificates across the market, including Gausium’s, were issued against the 2019 edition. Transition arrangements for a revised standard are set by accreditation bodies rather than by the standard itself, and the current requirements are published by the International Accreditation Forum, where the position on any given date can be confirmed.
A standard number on a web page carries limited information. The certificate itself does most of the work, and five fields on it are worth reading:
Certificate numbers and scope statements are not always published on a manufacturer’s website, so their absence is not in itself a finding. Requesting the certificate directly, and passing it to whoever normally reviews supplier attestations, settles the question.
Storage location is the item most likely to come back from a legal or compliance reviewer, particularly for public-sector and healthcare buyers in Europe.
Gausium’s privacy policy states that users can choose the cloud server area where their personal information is stored, based on their location. The policy is short enough to read in full, and it is the text to quote in an assessment. The provisioned region, and whether it can be changed later, are then worth confirming in the contract.
The same policy describes the retention period for personal information as running until the account is cancelled, and states that personal information is deleted after cancellation, except where a defined retention period is required by applicable laws and regulations.
On requests to access, correct, or delete personal information, it states that verified requests are processed within five working days, and that in special circumstances a response is provided within a maximum of thirty days or the period set by applicable law.
A privacy policy of this kind is written around the personal information handled through the account and the mobile app.
Storage location and retention for robot-generated data — floor maps, camera and sensor recordings, task history — is a separate question, and a written answer per data category is more useful than an inference drawn from a privacy policy.
It is also worth asking what happens to each category at the end of a contract.
A named set of measures is more useful in an assessment than a general assurance, because each item can be checked against the buyer’s own policy.
Gausium’s privacy policy states that industry standard security measures are used to protect the personal information provided, and names firewall protection, encryption such as SSL, de-identification or anonymization, and access control measures. The policy text is the reference point, and that level of specificity is a reasonable expectation of any manufacturer.
Two follow-up questions turn a named list into usable evidence:
Three gaps recur in cleaning robot tenders.
Product marks are not security statements. A safety or radio-compliance mark confirms that a machine meets product conformity requirements. It does not address how data is stored, transmitted, or shared, and it does not substitute for an information security certificate. Where a mark is offered in this context, the standard it certifies and that standard’s scope are worth reading.
Certification covers the system, not every release. An audited management system supports secure development, but it does not certify each firmware version, which is why vulnerability handling belongs in the assessment separately.
Gausium publishes platform advisories on its cybersecurity notifications page, and how customers are informed when an advisory is issued is a fair question to put to any manufacturer.
Physical safety is a separate assessment track. Obstacle avoidance, emergency stop behavior, and safe operation around people are assessed against a different family of standards, covered in Gausium’s guide to commercial cleaning robot safety.
Keeping the two tracks separate in an evaluation matrix prevents one from absorbing the other.
Data security often arrives late in cleaning robot procurement, after candidate models have been shortlisted on cleaning performance. Moving it forward costs very little and changes the shortlist, because the answers are documentary rather than technical and can be compared side by side.
Four clauses are usually enough:
Buyers working to these requirements can review the connected models in Gausium’s product range and raise the same four items with the sales team during the site assessment that covers floor types and cleaning area, which keeps security and cleaning performance on one timeline instead of two.
ISO/IEC 27001 is the baseline, because it certifies an audited information security management system. ISO/IEC 27701 adds privacy controls for personal data, and it is usually the standard that satisfies a data protection reviewer.
No. Those marks address product safety and electromagnetic compatibility. They make no statement about data storage, transmission, or privacy, and are not evidence of information security.
Gausium is certified to ISO/IEC 27001 and ISO/IEC 27701, and its privacy policy names firewall protection, encryption such as SSL, de-identification or anonymization, and access control measures applied to the personal information provided.
Gausium’s privacy policy states that users can choose the cloud server area where their personal information is stored, based on their location. Storage arrangements for robot-generated map and sensor data are confirmed during deployment planning.
Gausium’s privacy policy states that verified requests are processed within five working days, extending to a maximum of thirty days in special circumstances, and that data required to be retained by law is kept after account cancellation.
Certification with scope statements and edition, the storage region and whether it is selectable, retention periods per data category including map and sensor data, and a data processing agreement for the relevant jurisdiction.
Where a statement above is attributed to a policy or an announcement, the source text below is the version to rely on.
UP NEXT
Cleaning Robots That Charge Automatically: Which Models and What a Dock Covers02 września, 2026
Step 1/2
Please select the type of business you’d like to have with Gausium.
Choose one item from the list
Step 2/2
Thanks for sharing your preference. Please fill out the form below, and we’ll get in touch shortly.
By clicking “Submit”, I authorize Gausium to contact me. Privacy Policy.
Thank you for filling out the form
By clicking “Submit”, I authorize Gausium to contact me. Privacy Policy.