When your business retires a computer or drive, wiping it is only half the job. You need to be able to prove the data was destroyed. This guide explains what a valid certificate must contain, when Australian law requires one, and how to check the certificate you are given is genuine.
A certificate of data destruction is a formal document that proves the data on specific devices was securely destroyed. It records exactly what was destroyed, how, when, to what standard, and by whom, so your business has auditable evidence that personal and confidential information was disposed of properly. It is the paper trail that turns "we wiped the drives" into something you can prove to a regulator, an auditor or a customer.
Written by the ITC Asset Management team. ITC is a Sydney-based IT asset disposition provider operating since 2018 from North Rocks, NSW, holding ISO/IEC 27001:2022, ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018 certifications. We issue a Certificate of Data Destruction and a Certificate of Recycling for every collection.
A certificate of data destruction, sometimes called a certificate of destruction or a certificate of erasure, is documented proof that the data held on nominated storage media has been permanently destroyed or erased. It is issued by the provider that carried out the work, and it forms part of the chain-of-custody record for your retired equipment.
The certificate matters because a verbal assurance is not evidence. If a regulator, auditor or customer ever asks how you disposed of the data on an old device, the certificate is the record that answers the question. It links a specific device to a specific destruction method on a specific date, so there is no gap between the equipment leaving your office and the data being destroyed.
A certificate that is missing the device serial numbers or the method used is weak evidence, however official it looks. Look for all of these.
A certificate of data destruction does three jobs. It proves you took your obligations seriously, it protects you if something goes wrong, and it closes the loop on your asset register.
It shows you did not simply throw old devices away, but had the data destroyed to a recognised standard.
Auditors and regulators expect documented proof, not assurances. The certificate is the artifact they look for.
If a device is ever questioned, the certificate demonstrates the data was destroyed before disposal, which is your defence.
Reconciling certificates against your asset register confirms every retired device is accounted for, with none left unexplained.
Australian law does not name the certificate itself, but it does require you to destroy personal information you no longer need, and the certificate is how you prove you did. Under Australian Privacy Principle 11.2 of the Privacy Act 1988, an organisation must take reasonable steps to destroy or de-identify personal information once it is no longer needed and is not required to be kept by law.
The obligation to destroy or de-identify personal information you no longer need. A certificate is your evidence that you met it.
If data on an improperly disposed device is exposed, it can become a notifiable breach reported to the Office of the Australian Information Commissioner and the affected individuals.
APRA-regulated entities in banking, insurance and superannuation must maintain information security across the full information lifecycle, including secure disposal.
Serious or repeated breaches of the Privacy Act 1988 can attract penalties of $50M or more, according to the Office of the Australian Information Commissioner. A certificate of data destruction is a small piece of paperwork that sits directly against that risk.
There are three broad ways to destroy data, and the right one depends on the device. Software erasure overwrites a working drive so it can be reused. Degaussing wipes traditional magnetic hard drives and tapes, but does not work on solid-state drives. Physical destruction shreds or crushes the media, which suits faulty drives, solid-state media, or anything covered by a strict destruction policy.
NIST 800-88 is the widely used international guideline for media sanitisation. It defines three levels, and a good certificate names which level was applied.
For business data, sanitising to the Purge level or physically destroying the media gives strong assurance. ITC sanitises data-bearing drives to the NIST 800-88 standard using Blancco software, or physically destroys them where that is required.
These are two different documents that answer two different questions. A complete IT asset disposal job produces both.
Proves the data on your devices was destroyed. This is what meets your privacy and security obligations.
Proves the physical hardware was recycled responsibly, in line with AS/NZS 5377. This is what meets your environmental and waste obligations.
When you engage a provider, ask for both. If you only receive one, you have proof of half the job.
A certificate is only as good as what you can check against it. Do not just file it. Take a few minutes to confirm it holds up.
Match each device on the certificate against your own asset register, item by item, so nothing is unaccounted for.
Confirm the certificate names the destruction method and the standard it meets, and that they match what you asked for.
For software erasure, a proper certificate records that the erasure was verified, not just started.
Confirm the provider holds relevant certifications, such as ISO/IEC 27001 for information security, and that the certificate carries a unique number and a signature.
ITC issues a Certificate of Data Destruction and a Certificate of Recycling for every collection. Data-bearing drives are sanitised to the NIST 800-88 standard using Blancco software, or physically destroyed, backed by ISO/IEC 27001 information security certification and a documented chain of custody to our North Rocks facility. Explore our secure data destruction and hard drive shredding services.
The obligation is legal, and the proof is the certificate. Penalty figure from a named public source; certification and process facts from ITC.
Common questions about certificates of data destruction.
Australian law does not name the certificate itself, but Australian Privacy Principle 11.2 of the Privacy Act 1988 requires organisations to destroy or de-identify personal information they no longer need. The certificate is how you prove you met that obligation, and it supports the Notifiable Data Breaches scheme and APRA CPS 234 for regulated entities.
It should include a unique reference number, device details for each item including serial numbers, the destruction method and the standard it meets such as NIST 800-88, the verification result for software erasure, the date, the operator and any witness, the provider's identity and certifications, and a signature.
A Certificate of Data Destruction proves the data on your devices was destroyed. A Certificate of Recycling proves the physical hardware was recycled responsibly. A complete IT asset disposal job produces both, one for your data-security records and one for your environmental records.
Yes, but the method matters. Solid-state drives cannot be degaussed, so they are handled by software erasure to a drive-level standard or by physical destruction. A proper certificate names the method used for each device, so you can confirm the right approach was applied to your SSDs.
Reconcile the device serial numbers on the certificate against your own asset register item by item, confirm the method and standard match what you asked for, check for a unique reference number and a signature, and verify the issuer holds relevant certifications such as ISO/IEC 27001. A certificate that cannot be matched to your assets is weak evidence.
ITC securely destroys data on business devices across Sydney and NSW, sanitised to the NIST 800-88 standard or physically destroyed, with a Certificate of Data Destruction and a Certificate of Recycling for every job.