🔒 Data Security Guide 🇦🇺 Australian Rules

How to Securely Wipe Data From an Old Laptop Before You Recycle It

Deleting your files or running a factory reset does not always remove your data. This guide shows you how to securely wipe a laptop before recycling, why the method depends on whether you have an SSD or a hard drive, and when a factory reset is enough versus when you need certified destruction.

ISO/IEC 27001:2022 Certified NIST 800-88 Data Sanitisation Blancco Certified Erasure

The Quick Answer

How do I securely wipe a laptop before recycling?

Back up anything you want to keep, sign out of and de-authorise your accounts, turn on full-disk encryption, then run a secure erase. On an encrypted laptop, a factory reset that removes files is effective because the data is already scrambled. For a hard drive with sensitive or business data, use a full overwrite or the drive's built-in Secure Erase. If the laptop is broken, or holds customer or company data, the safest option is physical destruction with a certificate.

An old laptop is not just hardware waiting to be recycled. It is a storage device that has quietly held your logins, banking details, tax records, work files, photos, and saved passwords for years. Handing it on, whether to a recycler, a buyer, or a charity, without properly clearing it is one of the most common and most avoidable data risks in Australia. The good news is that wiping a laptop correctly is straightforward once you understand what actually removes data and what only appears to.

This guide covers the whole process end to end: what to do before you wipe, the exact steps for Windows, Mac, and Chromebook, why an SSD and a hard drive need different treatment, and how to decide between a do-it-yourself wipe and certified destruction. It is written for Australian readers, so it reflects the guidance of the Australian Cyber Security Centre and your obligations under the Privacy Act 1988, not overseas rules.

ITC

Written by the ITC Asset Management team. ITC is a Sydney-based IT asset disposition provider operating since 2018, holding ISO/IEC 27001:2022 certification and sanitising data to the NIST 800-88 standard with Blancco certified erasure. We wipe and destroy data-bearing devices for Australian businesses every week, so this guide reflects how the methods perform in practice.

Why Deleting Files or a Factory Reset Is Not Always Enough

When you delete a file or empty the recycle bin, the file does not actually leave the drive. The operating system simply marks that space as available to be reused, and removes the pointer that told it where the file lived. Until something else happens to overwrite that exact location, the original data sits there intact, fully recoverable with free software that anyone can download. The same is true of a quick format, which rewrites the index of where files are, not the files themselves.

This is not a theoretical risk. A widely cited study by Blancco Technology Group and Kroll Ontrack bought used drives from online marketplaces and found that 42% of them still contained residual data, including scans of passports, financial records, and company documents, despite the sellers believing the drives had been wiped. The sellers had deleted files or run a basic reset, and assumed that was the end of it.

A factory reset is better than a simple delete, but on its own it is not a guarantee either. Whether a reset truly removes your data depends on two things: whether the drive was encrypted, and what type of drive it is. That is why the single most powerful step you can take, and the one most guides skip, is to turn on full-disk encryption before you wipe. Once a drive is encrypted, the data on it is meaningless without the key. When you then reset the laptop and the key is discarded, even data that physically remains on the drive is scrambled beyond use. This approach, known as a cryptographic erase, is recognised in the NIST 800-88 sanitisation standard and is the backbone of a safe consumer wipe.

What actually happens to your data Delete or quick format Data still present index removed only Recoverable Reset without encryption Fragments may remain depends on drive type Sometimes recoverable Encrypt then secure erase Data overwritten or key destroyed Not recoverable
File deletion and a basic reset leave data behind. Encrypting the drive first, then erasing, is what makes a consumer wipe reliable.

Why This Matters: The Numbers

The scale of the risk, and the reason data on an old laptop is worth taking seriously. Figures from named public sources.

42%
Of second-hand drives sold online still held residual data despite owners believing they were wiped
Source: Blancco Technology Group and Kroll Ontrack study
$50M+
Maximum penalty for a serious or repeated interference with privacy under the Privacy Act 1988
Source: OAIC, Privacy Act s 13G
588,000 t
E-waste generated in Australia in 2023, up 38 percent in a decade, much of it data-bearing
Source: Australian Bureau of Statistics, Waste Account Australia 2024

Step by Step: How to Securely Wipe a Laptop Before Recycling

Follow these steps in order. The first three apply to every laptop; step four is where the method branches by operating system and drive type.

01

Back up anything you want to keep

Copy your files, photos, and documents to an external drive or a cloud service such as OneDrive, iCloud, or Google Drive. Export your browser bookmarks and saved passwords, and note down any software licence keys. Once the wipe is done, this data cannot be brought back, so take your time here. A wipe is only safe if you are certain you no longer need what is on the device.

02

Sign out and de-authorise your accounts

This step is easy to forget and causes the most grief later. Sign out of your Microsoft or Apple account and remove the device from that account online, so it is no longer tied to you. De-authorise software that is licensed to the machine, such as Adobe, Microsoft 365, iTunes, and any games launchers or password managers. On a Mac, sign out of iCloud and turn off Find My and Activation Lock, or the next owner will be locked out entirely.

03

Turn on full-disk encryption

This is the step that makes everything after it reliable. On Windows, enable BitLocker (Device encryption on Home editions). On a Mac, turn on FileVault. On a Chromebook, encryption is on by default. Encryption scrambles the entire drive so that, even if fragments survive the wipe, they are useless without the key. Let encryption finish before you move on.

04

Run the secure wipe for your system

Windows 10 or 11: Settings, then System, then Recovery, then Reset this PC, choose Remove everything, and select Clean the drive rather than just removing files. Mac: use Erase All Content and Settings on macOS Monterey or later, which performs a cryptographic erase, or use Disk Utility to erase on older machines. Chromebook: use Powerwash. Expect the process to take anywhere from twenty minutes to a few hours depending on the drive.

05

Clear firmware passwords and security features

Remove any BIOS or UEFI password, disable Windows Hello or fingerprint sign-in, and reset the TPM if prompted. On a Mac, make sure a firmware password is removed. These do not hold your personal data, but they will stop the machine being reused if you leave them locked, which defeats the purpose of recycling for reuse.

06

Remove SIM cards, SD cards, and extra storage

Take out any SIM or memory card, and remember that some laptops have a second drive or an M.2 slot you may have forgotten about. If you plan to keep the drive rather than recycle it inside the laptop, remove it now and store or destroy it separately. Wiping the main drive does nothing for a second drive you overlooked.

A note for businesses and anyone holding customer data

The steps above are the right approach for a personal laptop. If the machine held company or customer information, a self-service wipe leaves you with no proof it was done. For business equipment, use a certified process that sanitises to the NIST 800-88 standard and issues a serialised Certificate of Destruction, which is what your auditors and the Privacy Act expect. See certified data destruction, or our guide on how to choose a responsible e-waste recycler.

SSD or Hard Drive? Why the Method Matters

This is the part that most consumer guides get wrong or gloss over, and it is the difference between a wipe that works and one that only looks like it did. The way data is stored on a traditional hard drive (HDD) and a solid state drive (SSD) is completely different, and so is the way you have to erase it.

A hard drive stores data on spinning magnetic platters at fixed locations. Because the location is fixed, you can reliably erase it by overwriting every sector with new data. A single full overwrite makes the old data unrecoverable in practice, which is why tools that overwrite the whole disk are effective on an HDD.

A solid state drive works differently. To spread wear evenly and extend its life, an SSD constantly moves data around its memory cells using a process called wear levelling, and it keeps spare hidden capacity that the operating system cannot even see. This means a normal overwrite cannot be trusted to reach every copy of your data, because the drive may have written it somewhere the overwrite never touches. Overwriting an SSD also wears it out for no good reason. The correct methods for an SSD are the drive's own built-in ATA Secure Erase or NVMe Format command, which tells the drive itself to purge every cell, or a cryptographic erase, where the drive was encrypted and you simply destroy the key. This is exactly why encrypting first, as in step three, matters so much on a modern laptop.

Erasing an HDD versus an SSD Hard drive (HDD) Fixed locations on platters A full overwrite works Solid state drive (SSD) Wear levelling and hidden cells Overwrite is not reliable Use Secure Erase or crypto-erase
On an SSD, wear levelling can leave copies of your data in cells a normal overwrite never reaches. The drive's own Secure Erase command, or a cryptographic erase, is the reliable method.
MethodWorks on HDDWorks on SSDNotes
Delete files / empty binNoNoOnly removes the index. Data remains and is easily recovered.
Quick formatNoNoRewrites the file table, not the data itself.
Factory reset (unencrypted)PartialPartialBetter than delete, but fragments can survive. Not a guarantee on its own.
Factory reset (encrypted)YesYesReliable, because the data is already scrambled and the key is discarded.
Full overwrite (single pass)YesNot reliableCorrect for a hard drive. Misses hidden cells on an SSD and wears it out.
ATA Secure Erase / NVMe FormatYesYesThe drive purges its own cells. The right built-in method for an SSD.
Cryptographic eraseYesYesDestroy the encryption key so remaining data is meaningless.
Physical destruction / shreddingYesYesThe only option for a broken drive, and the standard for high-sensitivity data.

Wipe It Yourself, or Use a Certified Service?

The right choice comes down to one question: how sensitive is the data, and do you need to prove it was destroyed?

For a personal laptop that held your own photos, emails, and browsing, the do-it-yourself route above is perfectly adequate. Encrypt, run a proper secure erase, and you can recycle with confidence. Where the calculation changes is when the laptop held information that belongs to other people, such as customer records, patient details, financial data, or company intellectual property, or when the laptop is broken and cannot be wiped at all.

In those cases two things matter that a self-service wipe cannot provide: certainty and proof. A certified data destruction service sanitises the drive to the internationally recognised NIST 800-88 standard, using either verified erasure with software such as Blancco or physical shredding, and then issues a serialised Certificate of Destruction that records exactly which device was destroyed and how. That certificate is what an auditor, an insurer, or a regulator will ask for, and it is the practical answer to the Privacy Act obligation to take reasonable steps to destroy personal information you no longer need.

Which path is right for your laptop? Does it hold other people's data? No, personal Yes, business Encrypt, then secure erase yourself Recycle with confidence Certified destruction to NIST 800-88 Get a certificate Broken or will not boot? Physical destruction is the safe route
A simple rule: personal data, wipe it yourself; other people's data or a broken device, use certified destruction and keep the certificate.

How to verify a wipe actually worked

After a do-it-yourself wipe, you can sanity-check it by trying to run a free file-recovery tool against the drive. If it finds nothing, your wipe held. A certified service goes further and produces a verification report per drive, so the proof is documented rather than assumed. If you are recycling in volume, that documented verification is the difference between hoping and knowing.

What the Australian Rules and Guidance Say

Wiping a device is not only good hygiene. For a business it is a legal duty, and the official guidance is clear on the method.

🛡 Guidance and law

  • Australian Cyber Security Centre, advises backing up, signing out, and resetting, and physically destroying storage that cannot be wiped
  • Privacy Act 1988, APP 11.2, requires reasonable steps to destroy or de-identify personal information no longer needed
  • OAIC penalties, up to $50 million or more for a serious or repeated privacy breach
  • NIST 800-88, the international standard for media sanitisation, covering Clear, Purge, and Destroy
  • AS/NZS 5377, the standard the hardware is recycled in line with once the data is gone

What it means for you

  • Individuals, encrypt and secure-erase before recycling, and you have taken sensible, sufficient care
  • Businesses, deletion is not a defence; you need verified sanitisation and a record of it
  • Broken devices, if it cannot be wiped, it must be physically destroyed, not simply binned
  • Documentation, a Certificate of Destruction is the evidence that you met your obligation
  • Recycling, once data is destroyed, the materials should be recovered responsibly, not sent to landfill

After the Wipe: Recycling the Laptop Responsibly

Once the data is gone, the laptop itself still deserves a proper end. A laptop is full of recoverable materials, including aluminium, copper, and small amounts of gold, alongside a battery that must never go in a general waste or recycling bin because of the fire risk. Sending a wiped laptop to landfill wastes those materials and is exactly the outcome responsible recycling exists to prevent.

For a single household laptop, your council e-waste drop-off or a retailer take-back program will handle it. For business quantities, or for any device where you want the data destruction and the recycling handled together with documentation, a certified provider collects the equipment, destroys the data, recycles the hardware in line with the AS/NZS 5377 standard, and gives you certificates for both. If you are working out where to take it, our guide to where to drop off electronic waste in Sydney lists the options, and our how to recycle electronics in Australia guide covers the full process.

The short version

Back up, sign out, encrypt, and secure-erase. Match the method to your drive: overwrite is fine for a hard drive, but an SSD needs its own Secure Erase or a cryptographic erase. If the data belongs to other people or the laptop is broken, use certified destruction and keep the certificate. Then recycle the hardware so nothing goes to landfill.

Frequently Asked Questions

Common questions about wiping a laptop before recycling, selling, or donating it in Australia.

Only if the drive was encrypted first. On an encrypted laptop, a factory reset that removes files is effective because the data is already scrambled and the key is discarded. On an unencrypted laptop, a reset is better than deleting files but can leave recoverable fragments, so turn on BitLocker or FileVault before you reset.

No. Deleting a file only removes the pointer to it and marks the space as reusable. The data stays on the drive until it is overwritten and can be recovered with free software. A study by Blancco and Kroll Ontrack found 42 percent of used drives sold online still held recoverable data because owners had only deleted files or run a basic reset.

A hard drive can be reliably erased with a single full overwrite because data sits at fixed locations. An SSD moves data around using wear levelling and keeps hidden spare cells, so an overwrite is not reliable. For an SSD, use the drive's built-in ATA Secure Erase or NVMe Format command, or encrypt the drive and perform a cryptographic erase.

It means encrypting the whole drive and then destroying the encryption key. Any data physically left on the drive is scrambled and useless without the key. It is fast, it is recognised in the NIST 800-88 standard, and it is the reason encrypting before you reset a modern laptop is so effective.

If the laptop is broken and cannot boot, you cannot run a software wipe, so the data on the drive is still intact. The safe option is physical destruction: remove the drive and have it shredded, or use a certified destruction service that shreds the media and issues a certificate. Do not simply bin a broken laptop with the drive inside.

For a personal laptop, no. For a business, yes in practice. If the device held customer or company data, a serialised Certificate of Destruction is your evidence that you met the Privacy Act obligation to destroy personal information, and it is what auditors and insurers ask for. See our certificate of data destruction guide.

You do not have to if you have securely wiped it. Removing and keeping or destroying the drive separately is an extra layer of certainty some people prefer, especially for sensitive data. If you do leave the drive in, make sure it is the one you wiped, and check the laptop does not have a second drive you missed.

Yes, once you have encrypted, secure-erased, and signed out of and de-authorised your accounts. The account step matters as much as the wipe: if you leave Find My or Activation Lock on a Mac, the new owner is locked out, and if you leave your Microsoft account linked, the device still shows as yours.

A cryptographic erase or a modern Secure Erase is quick, often under half an hour. A full overwrite of a large hard drive can take several hours. Encrypting the drive beforehand also takes time on the first run, so allow a few hours overall if you are starting from an unencrypted machine.

Under the Privacy Act 1988, Australian businesses must take reasonable steps to destroy or de-identify personal information they no longer need. In practice that means verified sanitisation to a recognised standard such as NIST 800-88, a record of destruction, and responsible recycling of the hardware. For fleets, a certified provider like ITC handles collection, destruction, documentation, and recycling together.

Need certified data destruction with certificates for your business laptops? Contact our team or call 1300 048 226.

Certified Data Destruction, Done Properly

For business laptops and drives, ITC sanitises to the NIST 800-88 standard with Blancco certified erasure or witnessed shredding, issues serialised certificates, and recycles the hardware responsibly with full documentation.

Book Your Free Collection

Request a callback