What are data destruction certificates and when do you need them?

What are data destruction certificates and when do you need them?

 

An auditor or an insurer team asks for your data destruction certificate. You find it and send it over, but then you receive the follow-up question: which device does this cover, and how was it destroyed? The certificate you have just says, "data securely deleted." These days, that answer is too vague and no longer accepted.

Destruction certificates are turning up in tenders, cyber liability insurance renewals, ICO investigations, and supply chain due diligence questionnaires with increasing frequency. A destruction certificate only works as evidence if it can withstand exactly this kind of scrutiny. Most people don't find out what one should contain until the moment they're under pressure to produce it, by which point the device in question may have long gone.

‍

What a data destruction certificate is

A data destruction certificate is documentary evidence that personal data on a specific device has been destroyed to a recognised standard. It is not a receipt confirming a collection took place or a general statement that a supplier "handles data securely." It has to be tied to an individual device and describe what was done to it to remove the data. Anything less is a supplier's assurance, rather than evidence.

‍

What a data destruction certificate must contain to have evidential value

To function as evidence, a data destruction certificate needs five specific elements.

The device identifier such as a serial number or asset tag. The device type and batch descriptions aren’t enough information. "47 laptops collected on 14 March" identifies nothing.

‍

The method of destruction. Phrases like "securely wiped" that don't specify a method of destruction and can't be checked are too vague. There are four legitimate options to destroy data on a device:

●       Destroying the encryption key making the data unreadable. This process is called cryptographic erase.

●       Using multipass overwrite which replaces every bit of storage with new data which works well on traditional hard drives.

●       Scrambling the magnetic data on a hard drive using a strong magnetic field - a process called degaussing.

●       Physical shredding where the drive is ripped apart into small fragments.

‍

The standard or framework applied. Any device should be destroyed using a recognised framework that defines how the process should be carried out. In the UK, this is usually HMG IS5. The UK government sanitisation methodology on this process is now maintained through the National Cyber Security Centre's guidance on secure sanitisation and its CAS-S assurance scheme for commercial providers. However this isn’t an ICO-mandated standard. The ICO requires "appropriate technical and organisational measures," not a named framework, but referencing a recognised standard is how a provider demonstrates what "appropriate" means in practice.

‍

The name and credentials of the organisation carrying out the destruction.

The date that the data destruction took place.

‍

A certificate missing any of these five elements is not sufficient evidence, whatever else it says. This is what GDPR-compliant organisations should expect from a data destruction certificate.

‍

Batch certificates are weaker than device-level certificates

A certificate covering "100 laptops collected on [date]" cannot be matched against a specific asset. If a data incident review or a supplier questionnaire asks what happened to one machine, a batch certificate can't answer that question. It tells you devices were collected. It doesn't tell you what happened to any single one of them, or prove that the device now in question was among them at all.

Device-level certificates can answer that question. Each one covers a single device, identified by serial number, with its own record of method, standard, and date. This is the difference that determines whether your paperwork holds up when someone actually tests it, rather than simply files it away.

‍

When you will be asked for a data destruction certificate

Destruction certificates come up in more contexts than most people plan for. ICO investigations and audits look at whether disposal methods are used and documented, because UK GDPR Article 5(2) puts the burden of proof on the organisation, not the regulator. Supply chain due diligence questionnaires from enterprise clients increasingly ask for it directly. Cyber liability insurance renewals ask for it as evidence of risk management. ISO 27001 audits examine data destruction procedures and the documentation behind them as a matter of course.

In every one of these situations, a certificate without device-level identification gets challenged. This is exactly the kind of evidence the ICO expects an organisation to hold, alongside contracts and audit rights over the third parties doing the destruction, as part of demonstrating accountability under UK GDPR.

‍

What to check before appointing a provider

Your choice of IT disposal provider determines the quality of evidence you can produce later. Not all IT asset disposal (ITAD) companies issue device-level certificates as standard. Before appointing one, ask to see a sample certificate and check it against the five elements above. This single check, done before anything is collected, is worth more than any amount of paperwork chasing afterwards.

‍

What to do next

If you already have an archive of certificates and aren't sure they'd meet the standards needed, check them now rather than waiting for someone to ask. A certificate that only says data was "securely deleted," with no device identifier, method, or standard attached, won't hold up.

Talk to GAP about IT disposal services that provide device-level data destruction certificates as standard.

‍

Continue Reading
Keep in the Loop

Receive updates around WEEE Insights and Compliance

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.