Secure data destruction & IT asset disposal
When kit leaves your data centre, the data on it is still your liability. This guide covers how data is actually destroyed — the methods, the drive-shredding particle sizes that genuinely matter (and why SSDs are different), and the standards and UK regulations that decide whether your disposal is defensible.
A Retired Drive Is a Breach Waiting to Happen
Decommissioning is the one stage of the lifecycle where the asset is worth little but the data on it is worth everything. A drive that leaves your estate intact — sold, recycled or simply skipped — is an uncontrolled copy of your data in someone else’s hands. Studies of second-hand drives routinely recover live personal and corporate data from kit that was “wiped.”
It’s a legal duty
UK GDPR Article 32 and the Data Protection Act 2018 require you to keep personal data secure until it is irretrievably destroyed — failure is a reportable breach with regulatory and financial consequences.
“Wiped” often isn’t
A quick format or delete leaves data fully recoverable. Even a single overwrite can be insufficient on some media, and SSDs hide data in spare cells a standard wipe never touches.
Disposal is regulated too
The WEEE Regulations govern how electronic equipment is recycled. Dumping kit isn’t just a data risk — it’s an environmental compliance failure.
The gap is the handover
Most exposure happens between your rack and the destruction: untracked transport, no asset register, no certificate. Without an unbroken chain of custody you can’t prove anything was destroyed at all.
Clear, Purge or Destroy
The reference framework is NIST SP 800-88 Rev.1, which defines three levels of sanitisation. Which you need depends on the sensitivity of the data and whether the drive will be reused or has reached end of life.
Logical wipe — drive reusable
Overwrite the addressable storage (e.g. a verified multi-pass erase). Fine for low/moderate-sensitivity data on a drive you intend to redeploy or resell. Must be verified, and doesn’t reach hidden/remapped areas.
Stronger — resists lab recovery
Cryptographic erase (destroy the encryption key) or degaussing. Degaussing works on magnetic HDDs only — it does nothing to an SSD. The right choice when you need high assurance but may still reuse or recycle the media.
Physical — end of life
Shredding, disintegration, pulverising, incineration or melting. The only route for the most sensitive data and for media that can’t be reliably purged (most SSDs). After this the device is unusable — which is the point.
NIST SP 800-88r2 (in draft) defers the detailed technique list to IEEE 2883-2022, the current sanitisation standard — and notably warns that shredding may not sufficiently sanitise modern SSDs unless the particle size meets the defined threshold. Which brings us to the part everyone gets wrong…
Shred Sizes — HDDs vs SSDs
Not all shredding is equal, and the single most common — and dangerous — mistake is shredding SSDs at hard-drive sizes. A hard drive stores data magnetically across large platters, so a coarse shred destroys it. An SSD stores data in tiny NAND flash chips; a fragment just a few millimetres across can hold an intact chip, and therefore recoverable data. SSDs must be shredded far finer.
Hard drives (HDD)
NSA/CSS requires magnetic hard drives to be shredded to particles ≤6mm for TOP SECRET media. Degaussing first is good practice.
SSDs & flash
NSA/CSS requires SSDs and flash media to be shredded to ≤2mm — verified under a microscope. A standard HDD shredder will not achieve this.
| Media | NSA/CSS (highest assurance) | DIN 66399 / ISO 21964 — by security level |
|---|---|---|
| Hard drive (H — magnetic) | ≤ 6 mm particle | H-3 ≤320 mm² · H-5 ≤10 mm² · H-7 ≤5 mm² |
| SSD / flash / chips (E — electronic) | ≤ 2 mm particle | E-3 ≤160 mm² · E-6 ≤1 mm² · E-7 ≤0.5 mm² |
DIN 66399 (now globally standardised as ISO/IEC 21964) runs from level 1 (low) to 7 (top secret) and uses separate classes for magnetic hard drives (H) and electronic/flash media (E) — precisely because the safe particle size differs by an order of magnitude. Higher level = smaller particle = lower reconstruction risk.
The types of physical destruction
Shredding
Mechanical cutting to a defined particle size. The workhorse — but the size must match the media (see above).
Disintegration / pulverising
Repeated cutting through a mesh to a very fine, uniform particle. How the smallest (≤2mm) SSD sizes are achieved.
Degaussing
A powerful magnetic field that erases magnetic media. Effective on HDDs and tape; useless on SSDs — flash isn’t magnetic.
Crushing / piercing
Deforms a drive so it won’t spin up. Lower assurance — data can survive on the platter or chips. Fine as a deterrent, not as certified destruction.
Standards & UK Regulations
“Securely destroyed” isn’t a feeling — it’s a set of standards you can point an auditor or regulator at. The ones that matter:
NIST SP 800-88 & IEEE 2883
The international reference for sanitisation methods (Clear / Purge / Destroy), with IEEE 2883-2022 now defining the approved techniques and particle-size thresholds.
DIN 66399 / ISO/IEC 21964
The destruction standard with the seven security levels and per-media particle sizes — what reputable shredding is specified against.
NSA/CSS EPL
The strictest physical-destruction benchmark (the ≤6mm / ≤2mm figures). Equipment is tested and listed by the NSA for classified media.
UK GDPR & DPA 2018
Article 32 mandates secure deletion of personal data. The legal duty that sits behind every destruction certificate.
WEEE Regulations
Govern environmentally compliant recycling of the electronic remains once data is destroyed.
ADISA & NCSC
In the UK: ADISA’s ICT Asset Recovery Standard 8.0 is an ICO-approved UK GDPR certification; NCSC’s CAS-S scheme covers destruction of classified government data. Also look for ISO 27001 and NAID AAA.
Chain of Custody, End to End
Certified destruction is only as good as the chain of custody around it. The defensible process is the same whether destruction happens on-site or at a facility:
Inventory
Every asset logged by serial number before it moves — so you know exactly what must be accounted for.
Secure transport
Tracked, sealed, GPS-monitored movement — or destroy on-site with witnesses and avoid transport risk entirely.
Destroy to standard
The right method and particle size for each media type (≤6mm HDD, ≤2mm SSD), to the level your data sensitivity requires.
Certificate per item
An item-by-item certificate of destruction tied to each serial number — your audit-proof evidence.
WEEE recycling
Compliant recycling of the destroyed remains, with environmental documentation.
Audit trail
Records retained (typically six years) so you can evidence compliance long after the kit is gone.
How Optronix Helps
Decommissioning is the final stage of the data centre lifecycle — the bookend to choosing and building a facility — and the one where a missed certificate becomes a breach. We run it as a controlled project, on-site or off, across the UK, Europe and worldwide.
Audit & inventory
We survey and serial-log the estate to be retired, so nothing is unaccounted for.
On-site or certified off-site destruction
Witnessed destruction in your facility, or via ADISA / ISO 27001-certified partners — to the right standard and particle size per media type.
Full chain of custody
Tracked handling and item-by-item certificates of destruction tied to every serial number.
WEEE recycling & reporting
Compliant recycling of the remains, with the documentation and audit trail your auditors will ask for.
Decommissioning a site, or just clearing kit?
Tell us what’s being retired and where, and we’ll handle secure destruction and compliant disposal end to end — with the certificates to prove it.
Sources & notes
- NIST SP 800-88 Rev.1, Guidelines for Media Sanitization (Clear / Purge / Destroy); IEEE 2883-2022
- DIN 66399, globally standardised as ISO/IEC 21964 — media classes and security levels 1–7 with particle-size limits
- NSA/CSS Evaluated Products List — ≤6mm (HDD) and ≤2mm (SSD/flash) particle sizes for the highest assurance
- UK GDPR Article 32 & Data Protection Act 2018; WEEE Regulations; ADISA ICT Asset Recovery Standard 8.0 (ICO-approved UK GDPR certification); NCSC CAS-S; ISO 27001; NAID AAA
General guidance, not legal advice. Standards evolve and obligations depend on your data, sector and jurisdiction — confirm current requirements with the relevant standard and, where needed, professional advice. Particle sizes cited are the high-assurance benchmarks; the level you need is driven by data sensitivity.