Call Us Now: 888.945.2611
Call Us Now: 888.945.2611
Aug 24, 2026
Most conversations about ITAD data destruction go wrong in the same place. Someone asks “do you shred or wipe,” as though those are the only two options and as though the right answer is the same for every device in the pile.
It isn’t. The method has to match the media, and getting that pairing wrong is how organizations end up with drives they believe are sanitized that are not. This guide covers the framework the industry actually works to, which methods suit which media, the SSD problem specifically, and what a certificate of destruction has to contain to be worth anything.
NIST Special Publication 800-88 is the reference standard for media sanitization, and it defines three categories. Almost every credible destruction policy is built on them.
Clear removes data from user-accessible locations using logical techniques, typically overwriting. It protects against recovery using standard tools and normal system functions. It is the lightest of the three.
Purge goes further, making recovery infeasible even using advanced laboratory techniques. Depending on the media, purging can be achieved logically through overwrite, block erase, or cryptographic erase, or physically through degaussing.
Destroy renders the media itself unusable. Shredding, pulverization, disintegration, incineration, and melting all fall into this category.
The important thing to understand is that these are outcomes, not products. A vendor telling you they “wipe to NIST standard” has not actually said which of the three they achieve, and the difference between Clear and Purge is the difference between protection against a technician and protection against a lab.
This is where most policies fall down. The same technique produces very different results depending on what it is applied to.
| Media type | Appropriate approach | What does not work |
|---|---|---|
| Magnetic hard drives (HDD) | Overwrite for Clear; degaussing or shredding for Purge or Destroy | Single-pass overwrite on a failed drive that cannot be written to |
| Solid state drives (SSD) | Cryptographic erase or the manufacturer’s dedicated sanitize command; shredding to appropriate particle size for Destroy | Degaussing, which does not erase flash memory |
| Magnetic tape | Degaussing, or physical destruction | Overwriting alone for high-sensitivity data |
| Mobile devices | Cryptographic erase via factory reset on encrypted devices; physical destruction for high sensitivity | Assuming a factory reset alone is sufficient on older or unencrypted devices |
| Optical media | Physical destruction | Any logical method |
| Failed or unreadable drives | Physical destruction | Every logical method, since the drive cannot be written to |
That last row is the one organizations most often overlook. A drive that has failed cannot be overwritten, which means the entire logical sanitization category is unavailable to it. Failed drives need to be tracked separately and physically destroyed, and they should appear as such on your reporting.
Our post on secure data wiping methods goes deeper into the logical techniques.
Solid state drives deserve their own section because the received wisdom about hard drives actively misleads people here.
Degaussing works by disrupting the magnetic field that stores data on magnetic media. SSDs do not store data magnetically. Running an SSD through a degausser does not erase it. It may damage the drive, which creates the appearance of destruction while leaving the flash memory chips intact and the data potentially recoverable. NIST 800-88 discourages degaussing non-magnetic media for exactly this reason.
Overwriting is also less reliable on SSDs than on HDDs, because wear levelling means the controller distributes writes across cells and an overwrite command may not reach every location holding your data.
The two approaches that do work are cryptographic erase, which destroys the encryption key so the encrypted data becomes unrecoverable, and the drive manufacturer’s dedicated sanitize command, which is built for flash. For Destroy-level assurance, SSDs must be shredded to a small enough particle size that individual memory chips are broken, which is a finer specification than is adequate for a platter-based hard drive.
If your vendor offers degaussing as a blanket service without asking what media you have, that is a meaningful signal about their process. Our post on whether to destroy an old hard drive covers the decision from the other direction.
On-site destruction means the media is destroyed at your premises before it leaves. It removes transport risk entirely and lets your staff witness the process. It generally costs more and can be constrained by volume and equipment access.
Off-site destruction means media is transported under chain of custody to a secure facility. It is more cost-effective at volume and gives access to better equipment and a fuller audit trail, but it introduces a transport window where custody documentation is doing the work.
A reasonable middle path for many organizations is on-site destruction for the highest-sensitivity subset and off-site processing for the rest.
Most data-destruction programmes do a good job of handling the obvious equipment, but the less obvious devices are where gaps usually appear. Common examples include:
Multifunction printers and copiers. Most office MFPs contain an internal hard drive that stores images of everything scanned, copied, and printed through them. They are routinely returned to a leasing company or sent for disposal with that drive intact and unsanitized. If your organization has ever scanned a personnel file or a contract, that image may still be on the device.
Network and infrastructure equipment. Routers, firewalls, and switches hold configuration data, credentials, and routing information. They rarely appear on a data-bearing asset list because nobody thinks of them as storage.
Servers pulled from racks. Drives are frequently removed and set aside during a decommission, then handled separately from the chassis and lost track of. The chassis gets logged, the drives do not.
Devices held in storage. Equipment retired months or years ago and stacked in a cupboard is the single most common source of untracked data-bearing assets. It predates the current policy, it is not on any register, and nobody is certain what is on it.
Personal and remote-worker devices. Hardware issued to staff who have since left, or sitting in home offices after a return-to-office transition, often never comes back into a controlled process at all.
A useful certificate is specific enough that an auditor could reconcile it against your asset register.
It should include:
The reconciliation step is the one people skip. Take the certificate and check it against the list of assets that left your site. Every serial should be accounted for, and anything that is not needs an explanation before you close the engagement out.
The consequences of getting this wrong are not abstract, and they differ depending on where and how you operate.
PIPEDA applies federally to private-sector organizations and includes mandatory breach reporting obligations where a breach creates a real risk of significant harm. Records of breaches must be maintained.
PHIPA governs personal health information in Ontario and imposes its own notification and reporting duties on health information custodians, which sets a higher bar for anyone disposing of clinical or patient-facing systems.
Quebec’s Law 25 has significantly strengthened privacy obligations for organizations operating in that province, including incident reporting requirements.
The common thread is that improperly sanitized media leaving your control is a reportable incident waiting to happen, and the documentation you hold at that point determines whether you can demonstrate you took reasonable steps.
For the wider risk picture, our post on why secure data destruction is important sets out the exposure in more detail, and our certifications page shows the standards we are independently audited against.
NIST Special Publication 800-88 is the widely used reference standard for media sanitization. It defines three categories: Clear, which removes data from user-accessible locations using logical methods; Purge, which makes recovery infeasible even with laboratory techniques; and Destroy, which renders the media itself unusable through shredding, pulverization, or similar.
Neither is universally better, and the right choice depends on the media and the sensitivity. Wiping preserves the asset for resale and recovers value, which suits functional drives holding routine data. Shredding provides Destroy-level assurance and is necessary for failed drives, optical media, and the highest-sensitivity material. Many programmes use both.
Serial numbers for each device, the method applied, the NIST 800-88 category achieved, the date, the facility or confirmation of on-site destruction, the name and signature of the person responsible, and a reference number linking to the chain of custody record. Reconcile it against the assets that left your site.
On-site removes transport risk and allows your staff to witness destruction, which suits the most sensitive material. Off-site is more cost-effective at volume and gives access to better equipment, with chain of custody documentation covering the transport window. Many organizations split their inventory between the two by sensitivity.
They have to be physically destroyed, because a drive that cannot be written to cannot be overwritten, which rules out every logical sanitization method. Failed drives should be identified at collection, tracked separately, and appear on your certificate of destruction as physically destroyed.
If you would like to review your current data destruction approach, our IT asset disposition team can walk through it with you. Request a quote or call 888-945-2611.