🔒 Data Security 📄 Compliance Proof

What Is a Certificate of Data Destruction? And Why Your Business Needs One

When your business retires a computer or drive, wiping it is only half the job. You need to be able to prove the data was destroyed. This guide explains what a valid certificate must contain, when Australian law requires one, and how to check the certificate you are given is genuine.

ISO/IEC 27001:2022 Certified Sanitised to NIST 800-88 Certificate Issued Per Job

The Quick Answer

What is a certificate of data destruction?

A certificate of data destruction is a formal document that proves the data on specific devices was securely destroyed. It records exactly what was destroyed, how, when, to what standard, and by whom, so your business has auditable evidence that personal and confidential information was disposed of properly. It is the paper trail that turns "we wiped the drives" into something you can prove to a regulator, an auditor or a customer.

ITC

Written by the ITC Asset Management team. ITC is a Sydney-based IT asset disposition provider operating since 2018 from North Rocks, NSW, holding ISO/IEC 27001:2022, ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018 certifications. We issue a Certificate of Data Destruction and a Certificate of Recycling for every collection.

What is a certificate of data destruction?

A certificate of data destruction, sometimes called a certificate of destruction or a certificate of erasure, is documented proof that the data held on nominated storage media has been permanently destroyed or erased. It is issued by the provider that carried out the work, and it forms part of the chain-of-custody record for your retired equipment.

The certificate matters because a verbal assurance is not evidence. If a regulator, auditor or customer ever asks how you disposed of the data on an old device, the certificate is the record that answers the question. It links a specific device to a specific destruction method on a specific date, so there is no gap between the equipment leaving your office and the data being destroyed.

What a Valid Certificate Must Contain

A certificate that is missing the device serial numbers or the method used is weak evidence, however official it looks. Look for all of these.

Anatomy of a valid certificate of data destruction CERTIFICATE OF DATA DESTRUCTION Unique reference number Device make, model and serial number Destruction method used Standard applied, such as NIST 800-88 Verification result Date of destruction Operator and witness where relevant Authorised signature ISO 27001 issuer

Why does your business need one?

A certificate of data destruction does three jobs. It proves you took your obligations seriously, it protects you if something goes wrong, and it closes the loop on your asset register.

Evidence of due diligence

It shows you did not simply throw old devices away, but had the data destroyed to a recognised standard.

Audit and compliance

Auditors and regulators expect documented proof, not assurances. The certificate is the artifact they look for.

Liability protection

If a device is ever questioned, the certificate demonstrates the data was destroyed before disposal, which is your defence.

A complete asset trail

Reconciling certificates against your asset register confirms every retired device is accounted for, with none left unexplained.

Is a certificate of data destruction legally required in Australia?

Australian law does not name the certificate itself, but it does require you to destroy personal information you no longer need, and the certificate is how you prove you did. Under Australian Privacy Principle 11.2 of the Privacy Act 1988, an organisation must take reasonable steps to destroy or de-identify personal information once it is no longer needed and is not required to be kept by law.

Privacy Act 1988

APP 11.2

The obligation to destroy or de-identify personal information you no longer need. A certificate is your evidence that you met it.

Notifiable Data Breaches

The NDB scheme

If data on an improperly disposed device is exposed, it can become a notifiable breach reported to the Office of the Australian Information Commissioner and the affected individuals.

Financial services

APRA CPS 234

APRA-regulated entities in banking, insurance and superannuation must maintain information security across the full information lifecycle, including secure disposal.

The Stakes Are Real

Serious or repeated breaches of the Privacy Act 1988 can attract penalties of $50M or more, according to the Office of the Australian Information Commissioner. A certificate of data destruction is a small piece of paperwork that sits directly against that risk.

The methods, and what NIST 800-88 means

There are three broad ways to destroy data, and the right one depends on the device. Software erasure overwrites a working drive so it can be reused. Degaussing wipes traditional magnetic hard drives and tapes, but does not work on solid-state drives. Physical destruction shreds or crushes the media, which suits faulty drives, solid-state media, or anything covered by a strict destruction policy.

NIST 800-88 is the widely used international guideline for media sanitisation. It defines three levels, and a good certificate names which level was applied.

NIST 800-88 levels: Clear, Purge, Destroy CLEAR Resists simple recovery. Standard software overwrite. PURGE Resists lab recovery. Drive-level overwrite, crypto erase or degauss. DESTROY Media unusable and unrecoverable. Shredding, crushing, pulverising. increasing assurance

For business data, sanitising to the Purge level or physically destroying the media gives strong assurance. ITC sanitises data-bearing drives to the NIST 800-88 standard using Blancco software, or physically destroys them where that is required.

Certificate of Data Destruction vs Certificate of Recycling

These are two different documents that answer two different questions. A complete IT asset disposal job produces both.

Data security

Certificate of Data Destruction

Proves the data on your devices was destroyed. This is what meets your privacy and security obligations.

Environmental

Certificate of Recycling

Proves the physical hardware was recycled responsibly, in line with AS/NZS 5377. This is what meets your environmental and waste obligations.

When you engage a provider, ask for both. If you only receive one, you have proof of half the job.

How do you verify a certificate is valid?

A certificate is only as good as what you can check against it. Do not just file it. Take a few minutes to confirm it holds up.

Reconcile the serial numbers

Match each device on the certificate against your own asset register, item by item, so nothing is unaccounted for.

Check the method and standard

Confirm the certificate names the destruction method and the standard it meets, and that they match what you asked for.

Confirm the verification result

For software erasure, a proper certificate records that the erasure was verified, not just started.

Verify the issuer

Confirm the provider holds relevant certifications, such as ISO/IEC 27001 for information security, and that the certificate carries a unique number and a signature.

How ITC Issues Certificates

ITC issues a Certificate of Data Destruction and a Certificate of Recycling for every collection. Data-bearing drives are sanitised to the NIST 800-88 standard using Blancco software, or physically destroyed, backed by ISO/IEC 27001 information security certification and a documented chain of custody to our North Rocks facility. Explore our secure data destruction and hard drive shredding services.

Why It Matters

The obligation is legal, and the proof is the certificate. Penalty figure from a named public source; certification and process facts from ITC.

$50M
Or more, in penalties for serious or repeated breaches under the Privacy Act 1988
Source: OAIC
4
ISO certifications held by ITC, including ISO/IEC 27001 for information security
Source: ITC Asset Management
2
Certificates issued for every job: data destruction and recycling
Source: ITC Asset Management

Frequently Asked Questions

Common questions about certificates of data destruction.

Australian law does not name the certificate itself, but Australian Privacy Principle 11.2 of the Privacy Act 1988 requires organisations to destroy or de-identify personal information they no longer need. The certificate is how you prove you met that obligation, and it supports the Notifiable Data Breaches scheme and APRA CPS 234 for regulated entities.

It should include a unique reference number, device details for each item including serial numbers, the destruction method and the standard it meets such as NIST 800-88, the verification result for software erasure, the date, the operator and any witness, the provider's identity and certifications, and a signature.

A Certificate of Data Destruction proves the data on your devices was destroyed. A Certificate of Recycling proves the physical hardware was recycled responsibly. A complete IT asset disposal job produces both, one for your data-security records and one for your environmental records.

Yes, but the method matters. Solid-state drives cannot be degaussed, so they are handled by software erasure to a drive-level standard or by physical destruction. A proper certificate names the method used for each device, so you can confirm the right approach was applied to your SSDs.

Reconcile the device serial numbers on the certificate against your own asset register item by item, confirm the method and standard match what you asked for, check for a unique reference number and a signature, and verify the issuer holds relevant certifications such as ISO/IEC 27001. A certificate that cannot be matched to your assets is weak evidence.

Need certified data destruction for your business? Contact our team or call 1300 048 226.

Secure Data Destruction You Can Prove

ITC securely destroys data on business devices across Sydney and NSW, sanitised to the NIST 800-88 standard or physically destroyed, with a Certificate of Data Destruction and a Certificate of Recycling for every job.

Book Your Free Collection

Request a callback