Compliance

GDPR and Data Destruction: What the Regulation Actually Requires

ReCircle Tech8 min read

The GDPR Compliance Gap in Hardware Disposal

Most organisations have robust controls around live data — access management, encryption, DLP tooling. Fewer have an equivalent programme for data on end-of-life hardware. This is the compliance gap that GDPR creates for enterprise IT teams.

The regulation doesn't list "shred the hard drives" as a requirement. What it does require is more demanding: a demonstrable, documented, and risk-appropriate approach to erasure that you can evidence to a regulator.

The Relevant Articles

Article 5(1)(e) — Storage Limitation

Personal data must be kept "in a form which permits identification of data subjects for no longer than is necessary." End-of-life hardware that still contains identifiable data — even in deleted files — fails this principle.

Article 17 — Right to Erasure

Where the legal basis for processing no longer applies, data must be erased. Retired hardware sitting in a storeroom doesn't meet this requirement. The obligation to erase is active, not passive.

Article 32 — Security of Processing

Controllers must implement "appropriate technical and organisational measures" to ensure a level of security appropriate to the risk. For hardware disposal, this means documented sanitisation processes, not a policy statement.

Recital 65

Provides guidance on the right to erasure and specifically notes that retention of data on storage media constitutes processing — meaning the obligations of the regulation apply throughout.

What "Demonstrable Compliance" Looks Like

The European Data Protection Board (EDPB) guidance and DPA enforcement decisions point consistently to the same evidence requirements:

  • Per-asset documentation — A certificate of data destruction that references the specific serial number of the device. Aggregate or batch certificates are insufficient for regulatory purposes.
  • Certified processes — Sanitisation should be performed to a recognised standard. NIST 800-88 (Rev. 1) and HMG Infosec Standard 5 (Enhanced) are the most widely accepted in European regulatory proceedings.
  • Chain of custody — Documentation showing where the device was at each stage from collection through final disposition.
  • Downstream controls — If your ITAD partner passes devices downstream, you need assurance that data destruction occurred before any transfer.

Physical Destruction vs. Overwriting

Neither method is universally "better" — the right choice depends on the media type and the risk profile of the data.

| Scenario | Recommended approach | |---|---| | Functional SSD / HDD, low-sensitivity data | Certified overwrite (NIST 800-88 Purge) | | Functional SSD / HDD, sensitive personal data | Cryptographic erase + overwrite | | Non-functional drives | Physical shredding (particle size ≤6mm for DIN 66399 H-5) | | Tape media | Degaussing + physical destruction | | Encrypted SSDs | Cryptographic erasure may be sufficient — confirm with your DPO |

Common Compliance Failures

In ITAD audits, we regularly encounter the same issues:

  1. Devices recycled without sanitisation — Particularly common with peripherals (printers, multifunction devices) that contain local storage.
  2. Reliance on OS-level deletion — Deleting files or reformatting a drive does not meet GDPR sanitisation requirements.
  3. No certificate for leased equipment — Returning leased hardware to the lessor without securing a destruction certificate leaves you holding the liability.
  4. Storeroom accumulation — Retired devices held on-site for months or years, with no formal disposition process, constitute an ongoing compliance exposure.

Building a Compliant Programme

The foundation of a compliant hardware disposal programme is policy, process, and evidence working together.

Start with a Data Asset Register that includes hardware with known or possible personal data storage. Map that against your retention schedules to identify devices that have exceeded their retention period. Then ensure your ITAD partner can provide serialised certificates within a defined SLA from device collection.

If you're uncertain whether your current programme would withstand regulatory scrutiny, contact our compliance team for a confidential review.

Speak With Our Team

Questions about your ITAD programme? Our compliance specialists are available for a confidential consultation.

Get in Touch

Category

Compliance
All Insights