Is it safe to give your laptop to a repair shop?
Usually, but not verifiably. Most technicians do their job and nothing else. The risk is documented rather than theoretical: a 2022 University of Guelph field study found technicians accessed customer data at six of sixteen shops tested with a simple battery replacement, and in 2021 Apple settled with a customer after contractors at a repair facility posted her private photographs. The real problem is not that abuse is common: it is that you cannot tell the difference afterwards. A shop that behaved perfectly and a shop that copied your files return an identical laptop. So the sensible approach is to reduce what is reachable, and to keep a record of the service window.
What the studies found
The University of Guelph study is the most useful evidence available, because it was a field test rather than a survey. Researchers took devices with a trivial fault to sixteen service providers and examined what happened. Technicians at six shops accessed personal data that had nothing to do with the repair. In several cases they attempted to copy it.
Other incidents are documented individually. Apple's 2021 settlement followed contractors posting a customer's private photos. Investigations by CNA in Singapore and reporting from Kerala and Kolkata have documented similar patterns. We keep the full sourced set on our case files page.
How to think about the risk sensibly
Per visit, the odds are in your favour. Across a lifetime of repairs, across a family, across a company's fleet of laptops, the arithmetic changes. And the consequences are asymmetric: a repair that goes fine costs you nothing, while a single copied folder of personal photographs or financial documents cannot be undone.
That asymmetry is the argument for a record, not for avoiding repair shops. You are not trying to catch anyone. You are trying to make the question answerable.
Black Box exists for the gap between 'probably fine' and 'verifiably fine'. It is a free Windows recorder: arm Repair Mode before the handover and every file access, USB connection, login and process start during the service window is sealed into a tamper evident report. Most of the time that report will show a technician logging in, opening a diagnostic folder, and nothing else: which is a genuinely useful result, because it means you know rather than assume. If it shows something else, you have a record made at the time rather than a suspicion formed afterwards.
