What Does GDPR Compliant Data Disposal Mean for Businesses?

GDPR compliant data disposal means removing personal data securely when a business no longer has a valid reason to retain it. The disposal method should prevent unauthorised access before, during and after the process, while creating enough evidence to show that the organisation followed an appropriate procedure.

It does not simply mean putting an old computer into an electrical recycling collection or dragging files into a recycle bin.

Businesses need to understand what information they hold, how long it should be retained, where copies are stored and what must happen when the retention period ends. They must then select a deletion or destruction method that reflects the sensitivity of the information, the storage technology and the risk of recovery.

The Information Commissioner’s Office states that personal data should not be kept for longer than it is needed. Organisations should establish retention periods, review the information they hold and erase or anonymise personal data when it is no longer required.

Secure disposal is therefore not an isolated task completed at the end of a device’s life. It is part of the organisation’s wider data governance, information security and asset-management responsibilities.

What makes data disposal GDPR compliant?

The UK GDPR does not prescribe one destruction machine, particle size or disposal company that every business must use.

Instead, organisations are expected to use technical and organisational measures that are appropriate to their circumstances and the risks created by their processing activities. The ICO explains that the correct security measures will depend on the organisation, the processing involved and the risks it presents.

In practice, a compliant disposal process should address several connected issues:

  • Why the data is being disposed of
  • Whether disposal has been authorised
  • Where every relevant copy is stored
  • What type of media contains the information
  • How sensitive the information is
  • Whether the media will be reused or destroyed
  • Who will carry out the work
  • How assets will be protected before processing
  • What evidence will be retained afterwards

A business should be able to explain why its selected method was suitable. It should not rely on an assumption that a device is safe because it is old, damaged or no longer recognised by a computer.

When should a business dispose of personal data?

Personal data should generally be deleted, anonymised or destroyed when the organisation no longer needs it for the purpose for which it was collected, subject to any legal, contractual or operational reason requiring continued retention.

The storage limitation principle requires personal data to be kept in an identifiable form for no longer than necessary. The UK GDPR does not set one universal retention period because appropriate timescales depend on the purpose and context of the information.

For example, a business may need to retain certain financial, employment or contractual records for a defined period. Other information, such as duplicate exports, temporary working files or outdated customer lists, may no longer serve a valid purpose much sooner.

The important point is that the decision should be controlled rather than accidental.

Retention schedules support consistent disposal

A retention schedule defines how long different categories of records should be kept and what should happen when the retention period expires.

It can cover information such as:

  • Customer and supplier records
  • Employee information
  • Financial documents
  • Contracts and correspondence
  • Security logs
  • CCTV or access records where applicable
  • Project documentation
  • Marketing information
  • Backup data
  • Archived email
  • Information held on retired equipment

The schedule should identify who is responsible for reviewing and approving disposal. Automatic deletion may be appropriate for some systems, while other records may require a manual review before destruction.

The ICO recommends documenting retention periods and regularly reviewing information so that data is erased or anonymised when it is no longer needed.

Disposal should be suspended when information must be preserved

A scheduled destruction date does not always mean that a record should be destroyed immediately.

Information may need to be retained because of ongoing litigation, a regulatory investigation, a contractual dispute, an insurance matter or another formal preservation requirement.

The organisation’s procedure should allow authorised personnel to place relevant information on hold. This helps prevent routine destruction from removing records that are still required.

Once the preservation requirement ends, the information can return to the normal retention and disposal process.

Is deleting a file enough?

Usually not, particularly when a storage device is being sold, recycled, returned, redeployed or removed from the organisation’s control.

Ordinary file deletion often removes the system’s reference to the information without immediately overwriting the underlying data. Formatting a drive can create a similar problem, depending on the method used.

The ICO distinguishes normal deletion from data destruction. It describes data destruction as removing information so that it cannot be restored, including by professional recovery specialists. Suitable approaches may include secure removal software, physical destruction or the use of a specialist destruction company.

A device that appears empty may therefore still contain recoverable information.

Recycle bins, archives and backups must also be considered

Personal data may exist in more places than the original file location.

Copies may remain in:

  • Desktop recycle bins
  • Email deleted-item folders
  • Shared-drive archives
  • Cloud synchronisation folders
  • System backups
  • Local downloads
  • Portable storage devices
  • Temporary folders
  • Old database exports
  • Staff laptops or mobile devices

The ICO’s disposal guidance advises organisations to consider electronic records in archives, recycle bins and backups as part of the destruction process.

This does not always mean that every backup copy must be manually extracted and deleted immediately. Some backups are designed to expire through controlled rotation periods. However, the organisation should understand where the data remains, how long it will persist and what prevents it from being restored into active use incorrectly.

What is the difference between data deletion, sanitisation and destruction?

These terms are sometimes used interchangeably, but they can describe different outcomes.

Data deletion

Deletion removes information from normal use or makes it unavailable through the standard system interface.

This may be sufficient for routine housekeeping within an active system, but it may not prevent technical recovery from the storage medium.

Media sanitisation

Sanitisation treats data on storage media so that retrieval and reconstruction are reduced to an acceptable level.

Some sanitisation methods allow the storage device to be reused. Others are destructive and make the device unusable. The NCSC advises that organisations should sanitise decommissioned assets according to the type of media and the required security outcome.

Examples may include validated overwriting, cryptographic erasure, degaussing or physical destruction. The correct option depends on the storage technology and whether reuse is intended.

Physical destruction

Physical destruction damages the data-bearing components so that recovering the information is no longer feasible at the relevant threat level.

Methods can include:

  • Hard drive shredding
  • Hard drive crushing
  • Magnetic degaussing followed by destruction
  • Solid-state media shredding
  • SSD crushing
  • Specialist destruction of memory chips
  • Destruction of optical or magnetic media

Physical damage must target the components that store the information. Damaging a connector, casing or controller does not necessarily destroy the underlying data.

How should different storage devices be disposed of?

The disposal method should match the device’s storage technology.

A business may own numerous devices that contain information, even where data storage is not their primary purpose. The NCSC recommends maintaining a policy for the reuse, repair, disposal and destruction of storage media and data-bearing equipment, including devices such as printers and photocopiers.

Magnetic hard disk drives

Traditional hard drives store data magnetically on internal platters.

They may be sanitised using a validated overwrite process when they remain functional and are intended for reuse. Where reuse is inappropriate, they can be degaussed using suitably powerful equipment or physically destroyed.

Degaussing is only effective when the magnetic field is appropriate for the media being processed. It normally renders the hard drive unusable.

Physical shredding or crushing may be used instead of, or after, degaussing depending on the organisation’s risk assessment.

Solid-state drives

SSDs store information in flash memory chips and cannot be reliably erased through degaussing.

They may support secure erasure or cryptographic sanitisation when functioning correctly, but the process must be suitable for the specific drive and capable of verification.

Where physical destruction is required, the memory-bearing chips must be sufficiently damaged. A specialist SSD crusher or solid-state media shredder may be necessary.

USB drives and memory cards

USB sticks, SD cards and microSD cards also use flash memory.

Their small size can create handling risks because they are easy to misplace, conceal or mix with general waste. They require controlled collection and destruction equipment capable of processing small flash components.

Backup tapes

Magnetic backup tapes may contain extensive historic information from multiple systems.

They can often be degaussed, but the equipment must be suitable for the tape’s magnetic properties. The organisation must also reconcile individual tapes or cartridges against its backup inventory.

Mobile phones, tablets and embedded devices

Mobile devices can store personal data in internal memory, removable cards, applications and synchronised accounts.

A factory reset may be part of the process, but the organisation should follow current device-specific guidance and verify that the intended security outcome has been achieved. Failed or high-risk devices may require physical destruction of their storage components.

Printers, photocopiers and network equipment

Office equipment can contain hard drives, flash memory, cached documents, configuration records and login credentials.

These devices should be included in the asset-disposal policy rather than treated as ordinary office machinery. Network devices may also hold certificates or credentials that should be revoked before disposal.

Does GDPR require businesses to destroy old IT equipment?

The UK GDPR does not require every old device to be physically destroyed.

A functioning device may be reused, sold, donated or recycled if the personal data has first been securely sanitised and the organisation can justify its approach.

Physical destruction may be appropriate when:

  • The device has failed and cannot be sanitised through software
  • Secure erasure cannot be verified
  • The media contains particularly sensitive information
  • Internal policy prohibits reuse
  • Contractual requirements specify destruction
  • The device uses unsupported or unfamiliar technology
  • The cost of reliable sanitisation exceeds its reuse value
  • The risk of recovery is unacceptable

The NCSC recognises both reusable and destructive forms of sanitisation. The organisation should choose the method that reduces retrieval risk to an acceptable level for the data involved.

Responsible recycling can follow once the data security requirement has been satisfied.

What should happen before devices are destroyed?

A compliant process starts before the destruction equipment is used.

Identify all data-bearing assets

The business should maintain an inventory of devices that may contain information.

This may include:

  • Desktop computers
  • Laptops
  • Servers
  • Storage arrays
  • External hard drives
  • SSDs
  • Mobile phones
  • Tablets
  • USB drives
  • Backup tapes
  • Printers and photocopiers
  • Network appliances
  • Access-control equipment
  • Specialist operational machinery with embedded storage

The NCSC’s Cyber Assessment Framework describes cataloguing and tracking data-bearing devices as part of an achieved approach to media and equipment sanitisation.

Confirm that the data is no longer required

The disposal request should be authorised by someone with suitable responsibility.

This prevents useful or legally required records from being destroyed accidentally. It also reduces the risk of an employee disposing of equipment without checking whether business information needs to be migrated or preserved.

Back up information that must be retained

Required business information should be transferred to an approved system before the original asset is sanitised.

The business should verify that the migration or backup has been completed successfully. Once destruction occurs, recovery should not be possible.

Secure assets awaiting processing

Devices awaiting destruction still contain data and should be protected accordingly.

They should be stored in a locked location with access restricted to authorised staff. The ICO recommends maintaining records of hardware awaiting destruction, including the devices and their locations.

Leaving retired drives in an open cupboard or unattended recycling area can create an avoidable security weakness.

Can a business use a third-party disposal company?

Yes, but appointing a supplier does not remove the business’s responsibility for protecting the personal data.

The ICO advises organisations using a third party to erase data, dispose of equipment or recycle IT assets to ensure that the work is carried out adequately. It warns that the original organisation may remain responsible if personal data is later recovered from its old equipment.

The supplier should therefore be assessed before assets are transferred.

What should supplier due diligence cover?

The business should investigate:

  • The supplier’s destruction methods
  • Which media types it can process
  • Whether services are completed on-site or off-site
  • How assets are collected and transported
  • Employee screening and training
  • Secure vehicle and container arrangements
  • Processing-site security
  • Asset-tracking capabilities
  • How exceptions are handled
  • Certification and reporting
  • Downstream recycling arrangements
  • Insurance and contractual responsibilities
  • Procedures for reporting loss or security incidents

The level of investigation should reflect the sensitivity and volume of the data.

A low-cost waste collector should not be assumed to provide secure data destruction simply because it accepts electrical equipment.

Contracts should define the required controls

The agreement should make clear:

  • What assets will be processed
  • The approved destruction methods
  • The required timescale
  • Whether subcontractors may be used
  • How the chain of custody will be maintained
  • What evidence will be supplied
  • How incidents will be reported
  • What happens to residual materials
  • Whether the organisation has audit or inspection rights

Clear contractual expectations help the business demonstrate that security was considered before disposal.

What is a chain of custody?

The chain of custody records how data-bearing assets move from the organisation’s control through collection, transport, storage and final destruction.

A strong chain of custody may record:

  1. The asset or serial number.
  2. The person authorising disposal.
  3. The date and location of handover.
  4. The person or company receiving the asset.
  5. The container or collection reference.
  6. The transport and processing location.
  7. The destruction method and date.
  8. The final outcome and certificate reference.

On-site destruction can shorten the chain because intact media remains at the business’s premises until it is processed.

For off-site destruction, secure containers, authorised collection personnel and documented transfer points become particularly important.

Any discrepancy should be investigated. For example, an asset listed for disposal but absent from the final report should not simply be marked as destroyed without evidence.

Does a certificate of destruction prove GDPR compliance?

A certificate of destruction is useful evidence, but it does not prove complete compliance on its own.

Its value depends on the accuracy and reliability of the process behind it.

A certificate may record:

  • The client organisation
  • The destruction provider
  • The date and location
  • The media category
  • The quantity processed
  • The destruction method
  • Asset or serial numbers
  • An authorised signature
  • A service or project reference

This can support internal audits, client assurance and regulatory enquiries.

However, a certificate cannot show that the business followed an appropriate retention policy, authorised the disposal correctly or selected a suitable supplier unless those controls are documented elsewhere.

It also offers limited assurance if it only states that a mixed quantity of IT equipment was recycled without identifying whether the data-bearing media was sanitised.

A defensible disposal record normally combines the certificate with asset lists, chain-of-custody records, internal approval and supplier information.

What are common GDPR data-disposal mistakes?

Many disposal failures arise from gaps in routine processes rather than sophisticated attacks.

Treating recycling as data destruction

Electrical recycling and data destruction are related but separate activities.

Recycling manages the physical materials. Data destruction addresses the information stored on the device. A device should not enter an uncontrolled recycling route while recoverable personal data remains present.

Assuming broken devices contain no data

A hard drive may fail because of its controller, motor or read mechanism while the platter data remains intact.

An SSD may stop responding while its flash memory chips still contain information. Failed devices should therefore be treated as data-bearing assets.

Using one method for every media type

Degaussing can be effective for suitable magnetic media but not for flash storage.

A hard drive crusher may not provide sufficient destruction for small SSD memory chips. Media should be identified and assigned an appropriate process.

Failing to track equipment

A certificate stating that 100 drives were destroyed is less useful when the asset register listed 103 devices.

Individual or controlled batch tracking helps identify missing assets, rejected items and processing exceptions.

Keeping data indefinitely

Secure disposal cannot work properly without retention decisions.

Keeping unnecessary information increases the volume of data exposed in a security incident and makes disposal projects harder to control. The ICO emphasises that businesses should not retain personal information for longer than it is needed.

Trusting a supplier without verification

The organisation should not assume that a provider’s use of words such as “secure”, “GDPR” or “certified” proves that its process is suitable.

It should review the actual controls, methods and documentation.

Frequently Asked Questions

Is GDPR compliant data disposal only relevant to large organisations?

No. Any organisation processing personal data should dispose of it securely when it is no longer needed. The scale of the process may vary, but the underlying responsibility applies to businesses of all sizes.

Can an old computer be donated after its data is erased?

Yes, provided the organisation uses an appropriate sanitisation method and has sufficient assurance that personal data cannot be recovered. The result should be documented before the device leaves organisational control.

Are damaged hard drives exempt from secure disposal?

No. A damaged or non-functioning drive may still contain recoverable data. It should remain securely controlled and be sanitised or physically destroyed using a suitable method.

Does GDPR specify a required shredding particle size?

The UK GDPR does not set one universal particle size for every organisation and media type. The selected destruction level should be appropriate to the data sensitivity, storage technology and recovery risk.

Must every device be recorded by serial number?

Not necessarily, but individual serial-number tracking provides stronger evidence. Controlled batch records may be suitable in some circumstances if the organisation can demonstrate what the batch contained and how it was managed.

Can deleted information remain in backups?

Yes. Copies can remain in backup systems until their normal retention or rotation period expires. Businesses should document how backup copies are controlled and ensure that deleted information is not restored into active use without justification.

Is physical destruction always better than secure wiping?

No. Secure wiping can allow functioning media to be reused and may be appropriate when the process is reliable and verified. Physical destruction is more suitable when reuse is not permitted, the device has failed or the recovery risk remains unacceptable.

What should a business retain after a destruction project?

Useful evidence can include the authorised asset list, collection or handover records, chain-of-custody documentation, destruction reports, serial-number schedules, certificates and relevant recycling records.

GDPR compliant data disposal means having a controlled, risk-based process for removing personal information that the organisation no longer needs.

The process begins with retention decisions and accurate asset records. It continues through secure storage, suitable media sanitisation, controlled supplier management and reliable destruction evidence.

Businesses should not assume that ordinary deletion, factory resetting or recycling automatically removes the risk. The selected approach must reflect the storage device and the sensitivity of the data. Magnetic hard drives, SSDs, tapes, mobile devices and embedded storage may all require different treatment.

Where a specialist supplier is used, the organisation should understand the entire process rather than relying solely on a certificate or a general promise of GDPR compliance.

Varese Secure supports organisations requiring controlled, traceable and certified disposal of data-bearing assets. To discuss an appropriate destruction process for hard drives, SSDs, tapes or mixed IT equipment, contact the team.

Contact Varese Secure Ltd
Phone: 01489 854 131
Email: sales@varese-secure.co.uk
Find out more: https://varese-secure.co.uk/

Facebook | Twitter | LinkedIn