Disposal and Data Sanitisation
The end of the lifecycle carries the largest data risk and the least attention. What to require of a disposal supplier and what evidence to keep.
Procedure · 734 words
A retired device holds everything it ever held. Disposal is a data protection activity that happens to involve hardware.
The requirements
Data destruction, verified, before the device leaves your control or by a supplier under contract.
A record of what was destroyed, when, how, and by whom.
Compliance with waste electronics regulations, which apply in most jurisdictions and place obligations on the producer of the waste.
A certificate from the disposal supplier, retained.
Register update to disposed status, with the certificate referenced.
Sanitisation methods
Cryptographic erasure. Where the drive was encrypted from first use, destroying the key renders the data unrecoverable. Fast, effective, and it depends entirely on encryption having been enabled from the start.
Overwriting, for drives that support it, following a recognised standard.
Firmware secure erase, built into modern solid-state drives and effective when implemented correctly.
Physical destruction, for drives that cannot be verified or that held the most sensitive data. Shredding, with a certificate.
Not sufficient: deleting files, formatting, or reinstalling the operating system.
The encryption point
Worth stating separately because it changes the entire disposal problem.
Full-disk encryption enabled from deployment means disposal is a key-destruction exercise rather than a wiping exercise.
It also protects lost and stolen devices, which is the more likely event.
Enable it by policy on every device, from first boot, and record enrolment in the register. This is the highest-return security control in hardware asset management and it makes the disposal process both cheaper and more defensible.
Choosing a disposal supplier
Certification to a recognised standard for data destruction and for waste handling.
Chain of custody, documented, from collection to destruction.
Certificates per asset, with serial numbers, not a single certificate for a pallet.
Insurance.
Audit rights, even if never exercised.
A written contract, which many organisations do not have with the company taking their old laptops away.
Ask for a sample certificate before signing. A supplier who issues per-serial certificates is operating differently from one who issues a weight-based receipt.
Resale and donation
Attractive and it does not reduce the sanitisation requirement.
Sanitise before transfer, to the same standard as disposal.
Remove asset tags and organisational markings.
Deregister from management platforms, which is frequently forgotten and leaves a device permanently locked to your organisation or, worse, still enrolled.
Record the recipient where the device continues to exist.
The evidence file
Per disposal batch, retained for the required period:
Asset list with serial numbers.
Collection record and chain of custody.
Destruction certificates.
Waste transfer documentation.
Register updates.
This file is what a data protection enquiry asks for, and assembling it retrospectively from a supplier who no longer has the records is not possible.
The devices that never reach disposal
The larger practical problem in most organisations.
Laptops in drawers. Old phones in a cupboard. Devices from leavers that were never returned.
These hold data and are not in any disposal process.
Run an amnesty: a collection point, a stated period, no questions. Organisations doing this for the first time recover a surprising quantity of equipment, and the recovery is a data risk reduction rather than an asset recovery exercise.
The amnesty collection
Most organisations hold more retired equipment than they think, in drawers and cupboards and at former employees' homes.
Announce a collection window with a stated purpose: data protection, not asset recovery.
No questions and no consequences for anything handed in, including devices nobody can account for.
Collection points in every office, and prepaid packaging for remote staff.
Include personal devices that hold company data, with an offer to wipe rather than to keep.
Publish the outcome: how much was collected and what happened to it.
Expect a surprising volume the first time. Every device recovered is a data exposure closed, which is the argument to make internally rather than the value of the hardware.
Verifying a disposal supplier
Most organisations have no written contract with the company taking their old equipment away.
Ask for a sample certificate before signing. Per-serial certificates indicate a different operation from a weight-based receipt.
Ask how chain of custody is documented from collection to destruction.
Ask what happens to devices they cannot sanitise.
Ask whether they subcontract, and to whom.
Ask for their certifications and check them, rather than accepting the logo.
Visit if the volume justifies it.
Then contract: scope, standards, certificates per asset, insurance, audit rights, and what happens if a device is lost in transit.