Destroying the data is the part everyone thinks about. Accounting for every device on the way to destruction is the part that fails. Chain of custody is the documented, unbroken record of where each asset was and who was responsible for it, from collection to destruction. It is what turns a disposal into evidence, and its absence is where data goes missing.
Chain of custody is the documented, unbroken record of every asset from the moment it is collected to the moment it is destroyed, showing where it was, who was responsible for it, and what happened to it at each step. It exists to close the single most dangerous gap in disposal: the window between a device leaving your control and its data being destroyed. Destroying the data properly counts for little if a drive could have gone missing in transit with no record of it, because you can no longer prove what happened to the information it held. A proper chain of custody logs each asset at collection, tracks it through transport and processing, records its destruction, and reconciles the whole set back to what was collected, so there is never a moment where a data-bearing device is unaccounted for. It is the backbone of trustworthy IT asset disposal.
Most people picture data destruction as the shredder or the wipe, the decisive act at the end. But the risk in disposal is rarely the destruction itself, which a competent provider performs to standard. The risk is everything before it: the collection, the loading, the transport, the handling at the facility. That is the stretch where a device can be dropped, diverted or simply lost, and it is exactly the stretch chain of custody is designed to make accountable. This guide explains what a real chain of custody includes, where the risk sits, and how to tell a documented process from a casual pickup.
A proper chain of custody is unbroken because each link hands off to the next with a record. Break one link and the chain is worthless.
Each step is logged and hands off to the next, so no device is ever unaccounted for, and the whole set reconciles back to what was collected.
If any link is undocumented, the chain is broken, and you can no longer prove what happened to a device in that gap.
Each asset is recorded and accounted for at the point it is picked up, so responsibility for the equipment and its data transfers under a documented, traceable handover rather than an informal one.
The assets move under controlled conditions, tracked from your site to the processing facility, so there is no window in which a device is off the record.
At the facility each device is handled under a documented, certified process, its destruction method recorded against the individual asset rather than the batch.
Each device is wiped or destroyed to a recognised standard, and a certificate is issued for it, closing the chain at the individual-asset level.
The whole set is reconciled back to what was collected, so the number that arrived matches the number destroyed. That reconciliation is the proof the chain was never broken.
Not at the shredder. In the handover and the transit, where a device is most easily lost and least often watched.
It is worth being precise about where disposal goes wrong, because it is not where most people assume. A competent provider destroys data to standard; that stage is reliable. The exposure is the stretch before it. A device is carried out of the building, loaded onto a vehicle, driven across the city, unloaded, and staged at a facility before it is processed, and every one of those movements is a chance for a drive to be dropped, taken, or simply miscounted. An informal pickup, however convenient, treats that whole stretch as invisible: the equipment is handed over and nobody can say, afterwards, exactly what happened to each item along the way. Chain of custody exists to make that stretch accountable, so that if a question is ever asked about a specific device, the answer is a record rather than a shrug.
This is also why a certificate on its own is not the whole story. A certificate proves a device was destroyed; a chain of custody proves it was the right device, tracked the whole way, with none lost in between. The two work together: the chain accounts for every asset from collection to destruction, and the certificate documents the destruction of each. A disposal that produces certificates but cannot show an unbroken chain has evidence of destruction without evidence that nothing went astray first, which for a regulated business is only half the assurance it needs.
Australian privacy law requires reasonable steps to protect personal information, and for financial institutions APRA CPS 234 requires you to assess and manage third parties handling your information assets. A documented chain of custody is precisely the evidence those obligations call for: it shows the asset was controlled and accounted for throughout, not just destroyed at the end. It is the difference between demonstrating a control and hoping one held.
The two can look identical on collection day. They differ entirely in what you can prove afterwards.
The trap is that on the day, the two feel the same: a van arrives, the equipment leaves, the office is clear. The difference only appears later, when someone asks what happened to a particular drive, or an auditor wants to see that the disposal was controlled. At that point the documented process produces a record and the casual pickup produces nothing. For anything beyond a single personal device, and certainly for any business handling customer or regulated data, the itemised, reconciled chain of custody is what separates a disposal you can stand behind from one you simply have to trust.
A single unaccounted-for device undoes an otherwise perfect disposal. Chain of custody is how you close the gap. Figures from a named source.
The logic of chain of custody is unforgiving in the best way: a disposal is only as trustworthy as its weakest link, and one untracked device is a broken chain. That is why the reconciliation at the end matters so much. When the number of devices that arrived for destruction matches the number collected from your site, you have positive proof that nothing went astray in between, and when a discrepancy appears, it is caught and explained rather than discovered later as a breach. Against a maximum privacy penalty of $50M or more, the modest discipline of logging and reconciling every asset is obviously worth it. The test of a disposal provider is simple: can they show you, device by device, that what left your building is what was destroyed. If they can, the chain held; if they cannot, there was never really a chain at all.
The questions businesses ask most about the audit trail behind secure disposal.
A certificate proves a device was destroyed, but not that it was tracked the whole way there. Chain of custody proves the asset was accounted for from collection to destruction, with nothing lost in between. The two work together: the chain shows nothing went astray, and the certificate documents the destruction. A disposal with certificates but no chain has evidence of destruction without evidence the right devices reached it.
In the handover and transit. A competent provider destroys data reliably; the exposure is the stretch before that, when a device is carried out, loaded, transported and staged. Every movement is a chance for a drive to be dropped, taken or miscounted. Chain of custody makes that stretch accountable, so a device is never off the record between your control and its destruction.
Each asset logged at collection, tracking through transport and processing, the destruction method recorded against each individual device, a certificate per device, and a final reconciliation matching the count destroyed to the count collected. Together these let you show, for any specific device, where it was and what happened to it at every step.
Because it is the evidence their obligations call for. Australian privacy law requires reasonable steps to protect personal information, and APRA CPS 234 requires financial institutions to assess and manage third parties handling their information assets. A documented chain of custody demonstrates the asset was controlled and accounted for throughout, which is exactly what proving a control, rather than asserting one, requires.
Ask whether the provider can show you, device by device, that what left your building is what was destroyed. A documented process logs each asset, tracks it, records its destruction individually, and reconciles the final count. A casual pickup offers a blanket assurance and no itemised record. On collection day they can look identical; the difference is what you can prove afterwards.
It matters whenever the devices held data you are accountable for, regardless of quantity. Even a handful of drives holding customer or regulated data warrant an itemised, tracked collection, because a single lost device is a potential breach. For a large disposal the reconciliation is essential; for a small one it is still the difference between being able to prove the data was handled and merely hoping it was.
See how ITC tracks every asset from collection to destruction under a documented chain of custody, with per-device certificates and a reconciled report, so you can show exactly what happened to each device.
Destroy it properly
Knowing the right method is only half of it. The other half is being able to prove what happened to each serial number. ITC works to the NIST 800-88 standard under ISO/IEC 27001:2022, records chain of custody from your desk to the shredder, and issues a Certificate of Data Destruction listing the devices processed.