The importance of certified destruction of hard drives and data carriers

In a world where digital data plays a crucial role, data destruction is an indispensable part of modern business operations. Data carriers such as hard drives, USB sticks, and mobile phones often contain sensitive information, ranging from personal data to trade secrets. The risk of data breaches from improperly disposing of data-bearing equipment is therefore considerable.

The relevance of certified data destruction is reinforced by legislation such as the General Data Protection Regulation (GDPR). Organisations are legally required to process and destroy personal data securely. Trade secrets, intellectual property, and strategic data must also not fall into the wrong hands, as this can have serious consequences for business continuity.

What is certified destruction of data carriers?

Certified data destruction is the controlled process by which data carriers such as hard drives, SSDs, tapes, and USB sticks are completely and irrecoverably wiped or physically destroyed. It goes beyond simply deleting files or formatting devices, since data can often still be recovered.

Different methods of data destruction

There are various ways to securely destroy data carriers, each with its own advantages and applications. Below are the two most common methods of data destruction: physical and software-based destruction.

Physical data destruction is a direct and irreversible way to completely destroy data carriers. The data carrier is physically destroyed, making it impossible to recover data. Industrial shredders specially designed for shredding data carriers are used for this. This method is highly suitable for data carriers that are defective, decommissioned, or no longer usable.

Software-based data destruction involves overwriting data on a data carrier with certified software. This can be done in multiple layers, whereby the original data is completely wiped and overwritten according to standardised processes.

Certifications and standards

Physical destruction: Certification according to DIN 66399

DIN 66399 is an international standard that provides guidelines for the secure destruction of data carriers. This standard includes various security levels, depending on the sensitivity of the data and the type of carrier. Certification according to DIN 66399 guarantees that physical data destruction meets strict standards, making data unrecoverable. Companies can use this to demonstrate compliance with regulations such as the GDPR.

Software-based and firmware-based data destruction: Protocols in accordance with international certification & guidelines

There are several certifications that guarantee the secure and irreversible destruction of data via software:

Certus Software:
– Common Criteria (certified product)
– BSI (accredited)
– NCSC (certified product)
– NATA (accredited)
– ADISA (Product Claim test)

NIST 800-88 Clear, Purge:
– Guidelines and protocols for the safest, certified data erasure.
– Suitable for all data carriers, including firmware-based wiping.

DoD 5220.22-M:
– Multiple overwrite cycles for magnetic data carriers, not suitable for Solid State Drives (SSDs) or Fusion Drives, which require a firmware-based wiping protocol.

CESG CPA:
– A British standard for secure data destruction.

GDPR Compliance:
– Guarantees that the destruction of personal data meets the requirements of the GDPR.

Why is certified destruction of data carriers important?

When it comes to removing data, many companies still rely on standard methods, such as using the ‘delete’ button, formatting, or even physically damaging hard drives. Although these actions may seem sufficient, they’re often inadequate and offer no guarantee that data has actually been irrecoverably removed.

Why standard methods aren’t sufficient:

  • Delete and format: Deleting or formatting a hard drive only removes the references to the data, but the files themselves remain physically present and can easily be recovered with recovery software.
  • Physically breaking: Drilling holes in or hitting a hard drive may seem effective, but data can often still be read out using specialised tools. SSDs and tapes are even more vulnerable to this flawed approach.

Risks of insecure data removal

Consequences of non-compliance with data destruction regulations

Failing to comply with regulations for secure data destruction can have serious consequences for organisations. The main risks are outlined below:

  • Heavy fines: Under the GDPR, data breaches caused by careless destruction can result in heavy fines.
  • Reputational damage: A data breach caused by poorly destroyed data can seriously damage the trust of customers, partners, and employees.
  • Legal action: In the event of privacy law violations, affected individuals or organisations can take legal action, potentially resulting in damage claims.
  • Business continuity: Sensitive business information, such as strategic plans or customer data, could fall into the wrong hands, leading to competitive disadvantages or cybercrime, such as identity theft and fraud.
  • Non-compliance with sector rules: Specific sectors, such as finance and healthcare, impose strict requirements on data destruction. Failing to comply with these rules can result in additional sanctions or exclusion from markets.


Why is compliance crucial?
By complying with data destruction regulations, such as the GDPR or NIST standards, organisations can not only prevent fines and reputational damage, but also build a stronger image as a reliable and secure partner. Certified data destruction plays an essential role in this.

Advantages of certified data destruction

The advantages of certified data destruction are:

  1. Certainty
    Certification provides guaranteed certainty that all data has been permanently and irrecoverably destroyed. The techniques used, such as overwriting or physical shredding, make recovery impossible, even with advanced tools. This eliminates any risk of data breaches from leftover data.
  2. Liability
    By using certified data destruction, companies can demonstrate that they have met legal obligations such as the GDPR. A certificate of destruction provides legal proof that data has been correctly destroyed. This protects organisations against liability in the event of data breaches, since they can show they acted with due care when disposing of data carriers. This prevents heavy fines, legal action, and reputational damage.
  3. Audit trail
    A certified process provides a complete audit trail, in which every step in the data destruction is documented. This includes:
    • Serial numbers of the destroyed devices.
    • Date, time, and location of destruction.
    • Methods and certification standards used.


This documentation is essential for internal and external audits to prove that data destruction took place in a secure and compliant manner. It gives organisations control over their data management and provides peace of mind in the event of inspections or disputes.

Certified data destruction therefore offers not only security, but also transparency, legal protection, and a fully auditable process.

The certified data destruction process

Step by step:

1. Taking stock of the number of data carriers and/or data-holding equipment.

2. Collecting the data carriers or data-holding equipment.

3. Securing the data carriers/data-holding equipment in a secure depot.

4. Data destruction takes place according to the customer’s wishes (shredding or wiping).


Documentation:
For data carriers that are wiped, the customer receives a full (Certus) report. Among other things, this report shows:
– Serial number of the data carrier that was wiped.
– Data/size of the data carrier.
– The method by which the data carrier was wiped.
– Time of wiping.
– Whether the wipe was successful.

For data carriers that are shredded, the customer receives a Certificate of Destruction (COD). This report contains the following details:
– Serial number of the data carrier.
– Data/size of the data carrier.
– Person who registered and shredded the data carrier.
– Date of registration and shredding.

Verification:
Verifying data destruction is a crucial part of the process to demonstrate that sensitive data has been irreversibly removed. This provides organisations not only with certainty, but also proof of compliance with laws and regulations, such as the GDPR.

Holland Recycling offers organisations certified data destruction according to the mechanical method of DIN 66399, protection class 3. In addition, we’re a certified and authorised partner of Certus Software for securely wiping hard drives and other data carriers.

We destroy a wide range of devices, including hard drives, tapes, and mobile phones. Depending on your needs, we can physically shred these data carriers or wipe them using software. All our processes are fully certified and carefully documented.

Would you like more information or a no-obligation proposal? Feel free to contact us. We’re happy to think along with you about a secure and compliant solution for your data destruction.