Here is a certificate of destruction we have seen a version of many times: “1 x pallet, IT equipment, securely destroyed.”
It has a logo on it. It has a date. It looks reassuring in a folder.
It proves nothing. It does not say what was on the pallet, whose drives they were, how they were destroyed, or to what standard. If a laptop from that pallet surfaces on eBay with your payroll data on it, that certificate will not help you, and under UKGDPR you are still the data controller.
The gap between a certificate that reassures and a certificate that protects is entirely in the detail.
Wiping and shredding are different decisions
There are two legitimate ways to destroy data, and choosing between them is a commercial decision as much as a security one.
Overwriting, often called wiping, writes patterns across the whole drive so the original data cannot be recovered. Done properly and verified, the drive survives and retains resale value. This is the right answer for equipment with life left in it.
The critical word is verified. A wipe that is not verified is an assumption. Proper software confirms every sector was overwritten and produces a per-device report. Quick formats and factory resets do neither.
Physical destruction shreds the drive into fragments. Nothing is recoverable, and nothing is resaleable. This is the right answer for failed drives, for the most sensitive data, and where policy or a client contract demands it.
Two practical notes that catch people out:
Solid-state drives are not hard drives. SSDs store data across flash memory with wear levelling, so traditional overwriting does not reliably reach every cell. SSDs need either a verified cryptographic erase or physical destruction to a finer particle size than spinning disks.
Degaussing does not work on SSDs. Magnetic erasure destroys data on spinning platters. It does nothing to flash memory. A provider offering degaussing as a blanket answer has not asked what your drives are.
DIN 66399, and why the level matters
Physical destruction is measured against DIN 66399, published internationally as ISO/IEC 21964. It defines how small the fragments must be, and for data carriers, the levels run H-1 to H-7.
The number that matters is the maximum particle area:
- H-4, up to 2,000 mm², suits sensitive commercial data
- H-5, up to 320 mm², is the practical norm for most corporate data
- H-6, around 10 mm², for highly confidential material
- H-7, around 5 mm², for the strictest government and defence requirements
Most UK businesses are well served at H-5. The important thing is knowing which level you are actually buying, rather than chasing the highest number. On its own, “shredded” is meaningless. A drive broken into four large pieces has technically been shredded, and a determined forensic recovery would still get data off it.
Ask which level applies to your SSDs specifically. Some providers quote a level for spinning disks and process everything through the same machine.
ADISA, and what accreditation is worth
ADISA is the UK’s specialist standard for IT asset disposal. Unlike a certificate that covers a single process step, ADISA audits the whole chain: collection, transport, storage, sanitisation, destruction and downstream recycling, with unannounced audits.
For public sector, defence, financial services and healthcare, ADISA certification is frequently a procurement requirement. For everyone else, it is the cleanest available proxy for “this provider has been independently checked by people who know what to look for”.
Two other things to check alongside it:
- ISO 27001, which covers information security management across the business
- Upper tier waste carrier registration, because the same lorry is also moving controlled waste
What a real certificate of destruction contains
This is the checklist. Hold your provider’s certificate against it.
- Serial numbers or asset tags for every device, listed individually
- The method used, per device or per batch, wipe or shred, and the software or machine
- The standard achieved, including the DIN 66399 level for physical destruction
- The date the destruction was performed, not just the collection date
- The site where it was performed
- Your business named as the data controller
- A named signatory who is accountable for the statement
- Verification results for wiped drives, including any that failed and what happened to them
That last item separates the serious providers from the rest. In any batch, some drives fail to wipe. An honest report says so and confirms those drives were physically destroyed instead. A report where everything passes every time is a report nobody read.
On-site or off-site
On-site destruction uses a mobile unit in your car park. Drives are destroyed before they leave, and you can watch. It costs more, and it is the right answer for the most sensitive material.
Off-site destruction is more common and perfectly sound, provided the chain is controlled: sealed and numbered containers, GPS-tracked vehicles, CCTV at the facility, and destruction within a stated time of arrival.
If you go off-site, ask two questions. How long between collection and destruction? Anything over a few days means your drives sit in someone else’s warehouse. Can we witness a run? A provider confident in their process will say yes.
The equipment people forget
Data does not only live in laptops and servers.
- Multifunction printers and copiers hold internal drives that store every scan and print job. They are the single most overlooked item in any office clearance.
- Phones and tablets, including handsets sitting in a drawer since a staff member left
- Network hardware, where routers, firewalls and switches hold credentials and configuration
- USB sticks and external drives, which nobody logs
- CCTV recorders
- Point of sale terminals and card readers
- Smart building controllers and access control systems
Any of these leaving your site unrecorded is a gap in your asset register and a potential breach.
Frequently asked questions
What should a certificate of destruction include?
Individual serial numbers or asset tags for every device, the destruction method used, the standard achieved including the DIN 66399 level, the date and site of destruction, your business named as data controller, a named signatory, and verification results for any wiped drives. A certificate describing “one pallet of IT equipment” is not evidence of anything.
Is wiping a hard drive as secure as shredding it?
For most commercial data, a properly verified overwrite is secure and has the advantage of preserving resale value. Physical destruction is the right choice for failed drives, for highly sensitive data, and where a client contract or internal policy requires it. The deciding factor is verification: an unverified wipe is an assumption, not a control.
What DIN 66399 level does my business need?
H-5, with a maximum particle area of 320 mm², is the practical norm for most corporate data. H-4 suits ordinary sensitive commercial information, while H-6 and H-7 are for highly confidential and government material. Ask specifically which level applies to solid-state drives, as they often need a finer particle size than spinning disks.
Do I still have data protection responsibility after handing equipment to a recycler?
Yes. Under UKGDPR you remain the data controller until the data is verifiably destroyed. Your provider acts as a processor, which means you need a written agreement, evidence of their controls, and destruction records you can produce on demand. Handing over a laptop does not hand over the liability.
Does a copier need data destruction?
Almost always. Multifunction printers and copiers contain internal hard drives that retain images of documents scanned, printed and faxed, often going back years. They are the most commonly missed data-bearing device in office clearances and should be listed on your destruction certificate like any other asset.
The bottom line
Everything in data destruction comes down to one question: could you prove it?
Not “did we use a reputable company”, but could you put a document in front of a regulator that names the device, the method, the standard and the date. If your current certificate cannot do that, it is decoration.
Priority WEEE provides on-site and off-site data destruction for businesses nationally, with serial-level certificates, stated DIN 66399 levels and full verification reporting. Book a free waste review, and we will audit your current certificates against the checklist above.

