Every data breach story starts somewhere glamorous in the imagination: hackers, phishing, ransomware crews in distant time zones. Almost nobody imagines the actual scene of a great many incidents: a pallet of old computers on a loading dock, sold or scrapped with the drives still in, each one a filing cabinet that nobody remembered was full.
Second-hand drives bought online and found holding medical records, payroll, and customer databases are a research genre of their own; the studies repeat every few years and the findings never improve. The pattern underneath is always the same: someone believed the data had been dealt with, and the belief was doing all the work.
Our policy on this is short enough to print on a mug, and we state it plainly: hard drives are destroyed. Period. They are physically shredded, and here is the reasoning, the regulation, and the process behind that full stop.
Why Wiping Keeps Failing In The Real World
Software wiping, done perfectly, on the right drive, verified afterwards, is a legitimate technique. The trouble is that phrase doing an enormous amount of lifting.
Deleting and formatting are not wiping at all. Deletion removes the signpost, not the town; formatting redraws the map. Free recovery tools reverse both, which is why the drives in those research studies gave up their secrets so easily.
Real wiping fails at scale, through people. A proper wipe takes time per drive, multiplied across a refresh project’s hundreds. Somewhere in that stack: the drive that errored mid-wipe and got re-shelved, the machine powered off early, the one that never joined the queue because it was in a drawer, the SSD whose wear-levelling quietly kept blocks the software never touched. Human error is all too prevalent in exactly this workflow, and a 99% success rate across five hundred drives is five unwiped filing cabinets in the wild.
Failed and dead drives cannot be wiped at all. The drive that will not spin up will still surrender its platters to a determined recovery lab. Software cannot address what will not boot; shredders do not care.
Physical shredding replaces a per-drive promise with a per-drive fact. A shredded drive is not “probably fine”. It is confetti, and confetti has no recovery mode.
What The Regulator Actually Expects
UK GDPR never names shredders, but its logic walks straight to them. Personal data must be protected through its whole life, disposal included; the accountability principle demands you can evidence what you did; and a lost drive is a reportable breach with the burden on you to show the data was irrecoverable.
Assemble those and the disposal standard writes itself: storage media leaving your control must be demonstrably beyond recovery, with a paper trail. “We wiped them, mostly, we think” fails the demonstrably test the moment anyone asks hard questions, and tribunals, insurers, and ICO caseworkers ask hard questions professionally.
This is what the certificate of destruction exists for: the formal record of which media were destroyed, by serial number where required, when, and how. One certificate per collection, filed with the asset register, and the disposal chapter of any future audit takes thirty seconds. Our guide to WEEE paperwork covers the wider file; the destruction certificate is its sharpest page.
And the scope is wider than the server room realises: drives hide in photocopiers and MFPs (a famous blind spot), tills, laptops in drawers, NAS boxes under desks, phones, tablets, USB sticks in the great stationery diaspora. A destruction policy that only counts the drives IT remembers is a policy with a hole in it, which is why collections scope media across the whole estate, not just the obvious towers.
Destruction And Value Are Not Enemies
The objection we hear most: “but the computers are worth something.” They are, and shredding the drives does not spend that value.
The best-practice combination, and the one our IT asset management customers run as routine: drives out and shredded, certificated; everything else assessed for reuse. Chassis, screens, RAM, good laptops and desktops are refurbished and resold, with revenue flowing back to fund the refresh, as our asset disposal guide explains. The data risk and the resale value were never in the same component; separating them costs one screwdriver pass per machine.
And the shredded drives themselves join the recovery chain rather than a hole in the ground. The fragments are processed for material recovery: steel and aluminium, copper, board metals, and the rare earth magnets, that neodymium again, heading back to smelting and manufacturing. Our what-is-inside-your-electronics guide maps the whole chain. Destruction feeds recycling. Done properly, it is the front end of the recovery chain.
For equipment with residual sensitivity beyond drives, branded prototypes, returned stock, seized counterfeits, the same certificated logic extends into full product destruction, which has its own guide on this blog.
The Process, From Your Loading Dock
What a destruction engagement actually involves, start to file:
- Scope the media. Free assessment: how many machines, which categories of hidden media, loose drive stocks, what needs serial-level recording, and whether the estate splits into reuse and destruction lanes.
- Secure the chain. Collections on confirmed dates, tracked vehicles, locked containment for media in transit where required. Mainland UK up to Glasgow and Edinburgh, 5 to 7 working days typical, next-day when a clear-out will not wait.
- Shred. Physical destruction of every drive and data device in scope. No wiping lane, no judgement calls, no drive quietly re-shelved.
- Certificate and report. Destruction certificates, serials where specified, plus asset reports for the reuse lane, into your file against the day someone official asks.
The cost conversation usually ends pleasantly: destruction rides alongside WEEE collection and asset recovery, reuse value offsets the project, and the certificate costs nothing extra because it is simply how the job closes.
Frequently Asked Questions About Data Destruction
Is deleting or formatting enough before disposal?
No. Both are reversible with free tools. Even professional wiping depends on flawless per-drive execution, which is where real-world projects leak.
What does GDPR require at disposal?
Data irretrievable once media leaves your control, and evidence of it: documented, certificated destruction.
What is a certificate of destruction?
The formal record, media, serials where required, method, date, that closes disposal in any audit. File it with the asset register.
What happens to shredded drives?
Material recovery: steel, copper, board metals, and neodymium magnets return to manufacturing. Confetti, then commodities.
Can we still resell the computers?
Yes: drives shredded, everything else refurbished and resold through asset management. The value and the risk live in different components.
Where and how fast do you collect?
Mainland UK from Bedford to Glasgow and Edinburgh, typically 5 to 7 working days, next-day available, tracked vehicles, licence CBDU292438.
End Every Drive’s Story Properly
Every drive your business has ever owned is somewhere right now. The only question audits ever ask is whether you know where, and can prove it stopped being readable.
Priority WEEE shreds drives as policy, certificates every destruction, and recovers the value in everything around them. Call 0800 078 9580 or request a free review at priorityweee.co.uk, and turn “we think they were wiped” into a folder of full stops.
