Getting rid of data is a control, not an afterthought. Data you no longer hold cannot be breached, cannot be subpoenaed and does not need protecting — which makes disposal one of the cheapest risk reductions available to a small business. It only works if it is done properly and you can prove it was.
Sanitisation versus destruction
These are different things and the distinction matters. Sanitisation renders data unrecoverable while leaving the media usable — so the laptop can be resold, redeployed or donated. Destruction physically ruins the media, which is the only honest option for drives that have failed, since a drive that will not respond cannot be verified as erased.
A factory reset is not sanitisation. Formatting a drive is not sanitisation. Dragging files to the bin is not anything at all. We follow the media sanitisation guidance in the ASD's Information Security Manual and match the method to the media.
Method by media type
| Media | Method | Evidence you receive |
|---|---|---|
| Self-encrypting SSD / NVMe | Cryptographic erase (destroy the key), then verify the drive reports sanitised | Certificate with serial number and verification output |
| Standard SSD / NVMe | Firmware secure erase (ATA / NVMe sanitize), verified by sampling | Certificate with serial number and method used |
| Hard disk drive | Verified multi-pass overwrite, or physical destruction if the drive will not accept it | Certificate with serial number; destruction photos on request |
| Failed or unreadable drive | Physical destruction — shred or punch. No sanitisation claim is possible on media that will not respond | Certificate stating physical destruction, with photos |
| Laptops, desktops, servers | Drive sanitised or removed and destroyed; BIOS and firmware passwords cleared; asset de-enrolled from management | Certificate per device, listing make, model and serial |
| Phones and tablets | Factory reset after remote wipe and de-enrolment from MDM and the vendor account (Apple / Google / Samsung) | Certificate confirming de-enrolment, so the device is not left activation-locked |
| Magnetic tape | Degauss, then shred | Certificate listing tape identifiers |
| Optical media | Shred to unreadable fragments | Certificate with count and batch reference |
| Paper records | Cross-cut shred | Certificate with batch reference and weight |
Chain of custody
Every asset is logged at collection with its make, model and serial number, sealed in numbered transit containers, and reconciled against that manifest before any work starts. Nothing gets sanitised or destroyed that is not on the manifest, and nothing leaves the manifest without an outcome recorded against it. You get the reconciled manifest with your certificates, so the count you handed over matches the count you have evidence for.
Your certificate of destruction
One certificate per asset, not one per pickup. Each certificate records:
- Make, model and serial number of the asset.
- The sanitisation or destruction method applied, and the standard or ISM guidance it follows.
- The date, the operator, and the witness.
- The verification result, where the media supports verification.
- A reference back to the collection manifest.
That certificate is your evidence — for your own records, your auditor, your insurer, or a customer asking what happened to their data when you replaced your servers.
What we do not claim
oowl is not NAID AAA certified, not ISO 27001 certified, and holds no accreditation for destruction services. Our certificates are a record of work we performed and can evidence; they are not a certification issued under an accreditation scheme. If your contract or industry regulator requires a certified destruction provider, say so early and we will tell you plainly that you need one, and help you scope the requirement.
Not sure where you stand?
The security check is free and takes 30 minutes. You will leave it knowing your three biggest gaps.
Book a free security check