Compliance Guide

Secure data destruction & IT asset disposal

When kit leaves your data centre, the data on it is still your liability. This guide covers how data is actually destroyed — the methods, the drive-shredding particle sizes that genuinely matter (and why SSDs are different), and the standards and UK regulations that decide whether your disposal is defensible.

General guidance, not legal advice. Standards and figures are referenced from NIST, DIN/ISO, NSA/CSS and UK regulators; see notes at the end.
≤2mm
NSA shred size for SSDs — three times finer than the ≤6mm for hard drives
7
Security levels in DIN 66399 / ISO/IEC 21964, by media type and data sensitivity
Art. 32
UK GDPR duty to securely destroy personal data — backed by DPA 2018
ADISA
ICT Asset Recovery Standard 8.0 — an ICO-approved UK GDPR certification
6yrs
How long to keep destruction certificates and the chain-of-custody trail
01 | The Risk

A Retired Drive Is a Breach Waiting to Happen

Decommissioning is the one stage of the lifecycle where the asset is worth little but the data on it is worth everything. A drive that leaves your estate intact — sold, recycled or simply skipped — is an uncontrolled copy of your data in someone else’s hands. Studies of second-hand drives routinely recover live personal and corporate data from kit that was “wiped.”

It’s a legal duty

UK GDPR Article 32 and the Data Protection Act 2018 require you to keep personal data secure until it is irretrievably destroyed — failure is a reportable breach with regulatory and financial consequences.

“Wiped” often isn’t

A quick format or delete leaves data fully recoverable. Even a single overwrite can be insufficient on some media, and SSDs hide data in spare cells a standard wipe never touches.

Disposal is regulated too

The WEEE Regulations govern how electronic equipment is recycled. Dumping kit isn’t just a data risk — it’s an environmental compliance failure.

The gap is the handover

Most exposure happens between your rack and the destruction: untracked transport, no asset register, no certificate. Without an unbroken chain of custody you can’t prove anything was destroyed at all.

02 | The Methods

Clear, Purge or Destroy

The reference framework is NIST SP 800-88 Rev.1, which defines three levels of sanitisation. Which you need depends on the sensitivity of the data and whether the drive will be reused or has reached end of life.

Clear

Logical wipe — drive reusable

Overwrite the addressable storage (e.g. a verified multi-pass erase). Fine for low/moderate-sensitivity data on a drive you intend to redeploy or resell. Must be verified, and doesn’t reach hidden/remapped areas.

Purge

Stronger — resists lab recovery

Cryptographic erase (destroy the encryption key) or degaussing. Degaussing works on magnetic HDDs only — it does nothing to an SSD. The right choice when you need high assurance but may still reuse or recycle the media.

Destroy

Physical — end of life

Shredding, disintegration, pulverising, incineration or melting. The only route for the most sensitive data and for media that can’t be reliably purged (most SSDs). After this the device is unusable — which is the point.

NIST SP 800-88r2 (in draft) defers the detailed technique list to IEEE 2883-2022, the current sanitisation standard — and notably warns that shredding may not sufficiently sanitise modern SSDs unless the particle size meets the defined threshold. Which brings us to the part everyone gets wrong…

03 | The Detail That Matters

Shred Sizes — HDDs vs SSDs

Not all shredding is equal, and the single most common — and dangerous — mistake is shredding SSDs at hard-drive sizes. A hard drive stores data magnetically across large platters, so a coarse shred destroys it. An SSD stores data in tiny NAND flash chips; a fragment just a few millimetres across can hold an intact chip, and therefore recoverable data. SSDs must be shredded far finer.

≤6mm

Hard drives (HDD)

NSA/CSS requires magnetic hard drives to be shredded to particles ≤6mm for TOP SECRET media. Degaussing first is good practice.

≤2mm

SSDs & flash

NSA/CSS requires SSDs and flash media to be shredded to ≤2mm — verified under a microscope. A standard HDD shredder will not achieve this.

MediaNSA/CSS (highest assurance)DIN 66399 / ISO 21964 — by security level
Hard drive (H — magnetic)≤ 6 mm particleH-3 ≤320 mm² · H-5 ≤10 mm² · H-7 ≤5 mm²
SSD / flash / chips (E — electronic)≤ 2 mm particleE-3 ≤160 mm² · E-6 ≤1 mm² · E-7 ≤0.5 mm²

DIN 66399 (now globally standardised as ISO/IEC 21964) runs from level 1 (low) to 7 (top secret) and uses separate classes for magnetic hard drives (H) and electronic/flash media (E) — precisely because the safe particle size differs by an order of magnitude. Higher level = smaller particle = lower reconstruction risk.

The types of physical destruction

Shredding

Mechanical cutting to a defined particle size. The workhorse — but the size must match the media (see above).

Disintegration / pulverising

Repeated cutting through a mesh to a very fine, uniform particle. How the smallest (≤2mm) SSD sizes are achieved.

Degaussing

A powerful magnetic field that erases magnetic media. Effective on HDDs and tape; useless on SSDs — flash isn’t magnetic.

Crushing / piercing

Deforms a drive so it won’t spin up. Lower assurance — data can survive on the platter or chips. Fine as a deterrent, not as certified destruction.

04 | The Rulebook

Standards & UK Regulations

“Securely destroyed” isn’t a feeling — it’s a set of standards you can point an auditor or regulator at. The ones that matter:

NIST SP 800-88 & IEEE 2883

The international reference for sanitisation methods (Clear / Purge / Destroy), with IEEE 2883-2022 now defining the approved techniques and particle-size thresholds.

DIN 66399 / ISO/IEC 21964

The destruction standard with the seven security levels and per-media particle sizes — what reputable shredding is specified against.

NSA/CSS EPL

The strictest physical-destruction benchmark (the ≤6mm / ≤2mm figures). Equipment is tested and listed by the NSA for classified media.

UK GDPR & DPA 2018

Article 32 mandates secure deletion of personal data. The legal duty that sits behind every destruction certificate.

WEEE Regulations

Govern environmentally compliant recycling of the electronic remains once data is destroyed.

ADISA & NCSC

In the UK: ADISA’s ICT Asset Recovery Standard 8.0 is an ICO-approved UK GDPR certification; NCSC’s CAS-S scheme covers destruction of classified government data. Also look for ISO 27001 and NAID AAA.

05 | Doing It Right

Chain of Custody, End to End

Certified destruction is only as good as the chain of custody around it. The defensible process is the same whether destruction happens on-site or at a facility:

Inventory

Every asset logged by serial number before it moves — so you know exactly what must be accounted for.

Secure transport

Tracked, sealed, GPS-monitored movement — or destroy on-site with witnesses and avoid transport risk entirely.

Destroy to standard

The right method and particle size for each media type (≤6mm HDD, ≤2mm SSD), to the level your data sensitivity requires.

Certificate per item

An item-by-item certificate of destruction tied to each serial number — your audit-proof evidence.

WEEE recycling

Compliant recycling of the destroyed remains, with environmental documentation.

Audit trail

Records retained (typically six years) so you can evidence compliance long after the kit is gone.

06 | The Bridge

How Optronix Helps

Decommissioning is the final stage of the data centre lifecycle — the bookend to choosing and building a facility — and the one where a missed certificate becomes a breach. We run it as a controlled project, on-site or off, across the UK, Europe and worldwide.

Audit & inventory

We survey and serial-log the estate to be retired, so nothing is unaccounted for.

On-site or certified off-site destruction

Witnessed destruction in your facility, or via ADISA / ISO 27001-certified partners — to the right standard and particle size per media type.

Full chain of custody

Tracked handling and item-by-item certificates of destruction tied to every serial number.

WEEE recycling & reporting

Compliant recycling of the remains, with the documentation and audit trail your auditors will ask for.

Decommissioning a site, or just clearing kit?

Tell us what’s being retired and where, and we’ll handle secure destruction and compliant disposal end to end — with the certificates to prove it.

Talk to our team

Sources & notes

  • NIST SP 800-88 Rev.1, Guidelines for Media Sanitization (Clear / Purge / Destroy); IEEE 2883-2022
  • DIN 66399, globally standardised as ISO/IEC 21964 — media classes and security levels 1–7 with particle-size limits
  • NSA/CSS Evaluated Products List — ≤6mm (HDD) and ≤2mm (SSD/flash) particle sizes for the highest assurance
  • UK GDPR Article 32 & Data Protection Act 2018; WEEE Regulations; ADISA ICT Asset Recovery Standard 8.0 (ICO-approved UK GDPR certification); NCSC CAS-S; ISO 27001; NAID AAA