Blog

ITAD Data Destruction: NIST 800-88, Erasure vs Shredding, and Certificates of Destruction

Tricia Oldfield

Aug 24, 2026

ITAD Data Destruction - eCycle Solutions

Most conversations about ITAD data destruction go wrong in the same place. Someone asks “do you shred or wipe,” as though those are the only two options and as though the right answer is the same for every device in the pile.

It isn’t. The method has to match the media, and getting that pairing wrong is how organizations end up with drives they believe are sanitized that are not. This guide covers the framework the industry actually works to, which methods suit which media, the SSD problem specifically, and what a certificate of destruction has to contain to be worth anything.

The Framework: NIST 800-88

NIST Special Publication 800-88 is the reference standard for media sanitization, and it defines three categories. Almost every credible destruction policy is built on them.

Clear removes data from user-accessible locations using logical techniques, typically overwriting. It protects against recovery using standard tools and normal system functions. It is the lightest of the three.

Purge goes further, making recovery infeasible even using advanced laboratory techniques. Depending on the media, purging can be achieved logically through overwrite, block erase, or cryptographic erase, or physically through degaussing.

Destroy renders the media itself unusable. Shredding, pulverization, disintegration, incineration, and melting all fall into this category.

The important thing to understand is that these are outcomes, not products. A vendor telling you they “wipe to NIST standard” has not actually said which of the three they achieve, and the difference between Clear and Purge is the difference between protection against a technician and protection against a lab.

Matching the Method to the Media

This is where most policies fall down. The same technique produces very different results depending on what it is applied to.

Media type Appropriate approach What does not work
Magnetic hard drives (HDD) Overwrite for Clear; degaussing or shredding for Purge or Destroy Single-pass overwrite on a failed drive that cannot be written to
Solid state drives (SSD) Cryptographic erase or the manufacturer’s dedicated sanitize command; shredding to appropriate particle size for Destroy Degaussing, which does not erase flash memory
Magnetic tape Degaussing, or physical destruction Overwriting alone for high-sensitivity data
Mobile devices Cryptographic erase via factory reset on encrypted devices; physical destruction for high sensitivity Assuming a factory reset alone is sufficient on older or unencrypted devices
Optical media Physical destruction Any logical method
Failed or unreadable drives Physical destruction Every logical method, since the drive cannot be written to

 
That last row is the one organizations most often overlook. A drive that has failed cannot be overwritten, which means the entire logical sanitization category is unavailable to it. Failed drives need to be tracked separately and physically destroyed, and they should appear as such on your reporting.

Our post on secure data wiping methods goes deeper into the logical techniques.

The SSD Problem

Solid state drives deserve their own section because the received wisdom about hard drives actively misleads people here.

Degaussing works by disrupting the magnetic field that stores data on magnetic media. SSDs do not store data magnetically. Running an SSD through a degausser does not erase it. It may damage the drive, which creates the appearance of destruction while leaving the flash memory chips intact and the data potentially recoverable. NIST 800-88 discourages degaussing non-magnetic media for exactly this reason.

Overwriting is also less reliable on SSDs than on HDDs, because wear levelling means the controller distributes writes across cells and an overwrite command may not reach every location holding your data.

The two approaches that do work are cryptographic erase, which destroys the encryption key so the encrypted data becomes unrecoverable, and the drive manufacturer’s dedicated sanitize command, which is built for flash. For Destroy-level assurance, SSDs must be shredded to a small enough particle size that individual memory chips are broken, which is a finer specification than is adequate for a platter-based hard drive.

If your vendor offers degaussing as a blanket service without asking what media you have, that is a meaningful signal about their process. Our post on whether to destroy an old hard drive covers the decision from the other direction.

On-Site or Off-Site

On-site destruction means the media is destroyed at your premises before it leaves. It removes transport risk entirely and lets your staff witness the process. It generally costs more and can be constrained by volume and equipment access.

Off-site destruction means media is transported under chain of custody to a secure facility. It is more cost-effective at volume and gives access to better equipment and a fuller audit trail, but it introduces a transport window where custody documentation is doing the work.

A reasonable middle path for many organizations is on-site destruction for the highest-sensitivity subset and off-site processing for the rest.

Where Destruction Programmes Actually Break Down

Most data-destruction programmes do a good job of handling the obvious equipment, but the less obvious devices are where gaps usually appear. Common examples include:

Multifunction printers and copiers. Most office MFPs contain an internal hard drive that stores images of everything scanned, copied, and printed through them. They are routinely returned to a leasing company or sent for disposal with that drive intact and unsanitized. If your organization has ever scanned a personnel file or a contract, that image may still be on the device.

Network and infrastructure equipment. Routers, firewalls, and switches hold configuration data, credentials, and routing information. They rarely appear on a data-bearing asset list because nobody thinks of them as storage.

Servers pulled from racks. Drives are frequently removed and set aside during a decommission, then handled separately from the chassis and lost track of. The chassis gets logged, the drives do not.

Devices held in storage. Equipment retired months or years ago and stacked in a cupboard is the single most common source of untracked data-bearing assets. It predates the current policy, it is not on any register, and nobody is certain what is on it.

Personal and remote-worker devices. Hardware issued to staff who have since left, or sitting in home offices after a return-to-office transition, often never comes back into a controlled process at all.

What a Certificate of Destruction Must Contain

A useful certificate is specific enough that an auditor could reconcile it against your asset register.

It should include:

  1. Serial numbers for every device, not a count or a weight
  2. The sanitization method applied to each device or clearly defined group
  3. The NIST 800-88 category achieved, meaning Clear, Purge, or Destroy
  4. The date the destruction was performed
  5. The facility where it took place, or confirmation it was on-site
  6. The name and signature of the person who performed or witnessed it
  7. A reference number tying back to the collection and chain of custody record

The reconciliation step is the one people skip. Take the certificate and check it against the list of assets that left your site. Every serial should be accounted for, and anything that is not needs an explanation before you close the engagement out. 

Why This Matters Under Canadian Privacy Law

The consequences of getting this wrong are not abstract, and they differ depending on where and how you operate.

PIPEDA applies federally to private-sector organizations and includes mandatory breach reporting obligations where a breach creates a real risk of significant harm. Records of breaches must be maintained.

PHIPA governs personal health information in Ontario and imposes its own notification and reporting duties on health information custodians, which sets a higher bar for anyone disposing of clinical or patient-facing systems.

Quebec’s Law 25 has significantly strengthened privacy obligations for organizations operating in that province, including incident reporting requirements.

The common thread is that improperly sanitized media leaving your control is a reportable incident waiting to happen, and the documentation you hold at that point determines whether you can demonstrate you took reasonable steps. 

For the wider risk picture, our post on why secure data destruction is important sets out the exposure in more detail, and our certifications page shows the standards we are independently audited against.

Frequently Asked Questions

NIST Special Publication 800-88 is the widely used reference standard for media sanitization. It defines three categories: Clear, which removes data from user-accessible locations using logical methods; Purge, which makes recovery infeasible even with laboratory techniques; and Destroy, which renders the media itself unusable through shredding, pulverization, or similar.

 

Neither is universally better, and the right choice depends on the media and the sensitivity. Wiping preserves the asset for resale and recovers value, which suits functional drives holding routine data. Shredding provides Destroy-level assurance and is necessary for failed drives, optical media, and the highest-sensitivity material. Many programmes use both.

 

Serial numbers for each device, the method applied, the NIST 800-88 category achieved, the date, the facility or confirmation of on-site destruction, the name and signature of the person responsible, and a reference number linking to the chain of custody record. Reconcile it against the assets that left your site.

 

On-site removes transport risk and allows your staff to witness destruction, which suits the most sensitive material. Off-site is more cost-effective at volume and gives access to better equipment, with chain of custody documentation covering the transport window. Many organizations split their inventory between the two by sensitivity.

 

They have to be physically destroyed, because a drive that cannot be written to cannot be overwritten, which rules out every logical sanitization method. Failed drives should be identified at collection, tracked separately, and appear on your certificate of destruction as physically destroyed.

 

 
If you would like to review your current data destruction approach, our IT asset disposition team can walk through it with you. Request a quote or call 888-945-2611.

About Tricia Oldfield

Tricia Oldfield is a senior operations and sustainability leader at eCycle Solutions, Canada’s trusted partner for IT asset disposition, certified data destruction, and electronics recycling. With years of experience helping Canadian enterprises, healthcare organizations, and public institutions navigate end-of-life hardware responsibly, Tricia brings a practical, compliance-first perspective to every engagement. She writes to help IT directors, CFOs, and privacy officers make smarter decisions about technology retirement — protecting their organizations, their data, and the environment at the same time.

ecyclesolutions.com

Recycle Icon - eCycle Solutions

Schedule Pickup

eCycle Your Technology – Contact Us Today

    testimonials

    See what people have to say about eCycle Solutions

    eCycle Solutions is my most recommended and is a highly reputed electronics solutions company. Their team is highly efficient and supportive! My experience with them was so great that I will consider them in the future for sure! Highly recommended!

    It is so important to properly recycle your electronics and ensure they do not end up in a landfill. eCycle Solutions is my number one choice! They ensure your electronics are recycled properly. Highly recommended!

    eCycle Solutions is Canada’s best electronic recycler. Great team, polite and friendly customer service. Thank you eCycle Solutions for doing a wonderful job. Highly recommended!