🏛 NSW Government📜 State Records Act

NSW Government Records and IT Disposal

For a NSW public sector agency, disposing of IT is not just a data-security task; it intersects with records law. State records can only be disposed of in an authorised way, and the drives being retired may hold them. This guide explains how the State Records Act shapes government IT disposal, and how to destroy the data on retired equipment compliantly, without breaching either records or privacy obligations.

Records-Aware Disposal Certificate for Every Device

The Quick Answer

How does records law affect NSW government IT disposal?

Under the State Records Act 1998 (NSW), public sector records may only be disposed of in accordance with an authorised process, such as an approved retention and disposal authority, not simply because the hardware is being retired. When a NSW agency disposes of IT, the drives and devices may hold State records, so the records position has to be settled first, and then the data destroyed securely to a recognised standard, with evidence. The reason this is two obligations at once is that a government hard drive can hold both a State record that records law governs and personal or sensitive information that privacy obligations govern. Retiring the hardware does not release the agency from either. The compliant path is to ensure the records on a device are appropriately retained, transferred or authorised for destruction under records rules, and then to render the data unrecoverable and certify it. This is a core part of accountable government IT disposal. For the general step-by-step process, see our government IT equipment disposal guide; this piece focuses on the records-law dimension.

Most guidance on government IT disposal focuses on data security, and rightly so. But a NSW public sector agency carries an extra layer that private organisations do not: its information is often a State record, and State records sit under a legal framework that controls how and when they can be destroyed. That means a government drive cannot always simply be wiped and recycled the moment it is retired; the records on it have to be accounted for first. This guide is about that intersection of records law and IT disposal.

Two Obligations on One Hard Drive

A retired government device can hold a State record and personal information at the same time. Records law and privacy obligations both apply, and disposal has to satisfy both.

The first obligation comes from records law. The State Records Act 1998 (NSW) establishes that public sector records must be managed through their life and can only be disposed of in an authorised way, typically under a retention and disposal authority that sets how long particular records are kept and when they may be destroyed. The key point for IT disposal is that destroying the hardware is not, by itself, an authorised disposal of the records it contains. If a drive holds State records that are still required, wiping or shredding that drive without settling the records position could destroy records the agency was obliged to keep. So the records have to be dealt with, retained, migrated, transferred to the state archives where required, or confirmed as authorised for destruction, before the media is destroyed.

The second obligation comes from information protection. NSW public sector agencies are also expected to handle personal information securely, including its secure disposal, so a government drive that holds personal or sensitive information cannot be passed on with that data intact. This is the familiar data-destruction obligation: the information has to be rendered unrecoverable, not merely deleted. The two obligations meet on the same hard drive. Records law asks whether the records may be destroyed yet; information protection asks that, once they may be, the data is destroyed securely and evidenced. A compliant government disposal answers both in the right order.

Settle the records position before you destroy the drive

The mistake unique to government is treating an IT refresh as authority to destroy whatever is on the hardware. It is not. Confirm the records on a device are retained, transferred or authorised for destruction under records rules first, then render the data unrecoverable and certify it. Order matters.

Disposing of Government IT Compliantly

Five steps keep a NSW agency on the right side of both records law and secure disposal when retiring IT.

1

Identify what records the devices hold

Before disposal, understand what State records and personal information live on the drives being retired, so the records position can be settled and nothing that must be kept is destroyed by default.

2

Settle the records under an authority

Ensure the records are retained, migrated or transferred as required, or confirmed as authorised for destruction under the applicable retention and disposal authority, so that destroying the media is a lawful disposal of the records, not an accidental one.

3

Render the data unrecoverable

Once the records position allows it, securely erase the media to a recognised standard such as NIST 800-88, or physically destroy drives that cannot be reliably wiped, so government data cannot be reconstructed.

4

Maintain chain of custody

Move retired devices under a documented chain of custody from the agency to destruction, giving an unbroken, auditable record of where government data went at each step.

5

Retain certificates and records of disposal

Keep a certificate for each device recording what was destroyed and to what standard, alongside the records-disposal documentation. Government disposal must be demonstrable, so the evidence completes the process.

Use a provider that understands both sides

The secure destruction and chain of custody are well suited to a specialist provider, working alongside the agency's records team who settle the records position. A provider that renders data unrecoverable to standard, maintains custody and certifies each device gives the agency the disposal evidence it needs. Talk to our team about compliant government IT disposal.

The Order That Keeps You Compliant

Records first, destruction second. Getting the sequence wrong is how an agency destroys a record it had to keep, or keeps data it should have destroyed.

Two obligations, one correct sequence 1. Records law Are these records authorised for disposal, or must they be kept? 2. Secure destruction Render the data unrecoverable to a recognised standard 3. Evidence Certificate per device, chain of custody, plus records-disposal docs Destroying the drive before settling the records position risks destroying a record the agency had to keep.

Why Government Disposal Carries Extra Weight

A public sector agency answers to records law, information protection and public accountability at once. Disposal has to satisfy all three. Figures from named sources.

Authorised
Is the only lawful way to dispose of State records under the State Records Act 1998 (NSW)
Source: State Records Act 1998
532
Data breaches notified to the OAIC in Jan to Jun 2025; the public sector features among reporting entities
Source: OAIC NDB Report
Both
Records law and secure destruction apply to the same government drive, in that order
The principle

Government information carries a weight that private data does not, because it belongs, in a sense, to the public, and because a State record can have enduring value that outlives the hardware it happens to sit on. That is why records law controls its disposal, and why a government IT refresh cannot be treated as licence to destroy whatever is on the drives. At the same time, government systems hold large volumes of citizens' personal information, and a careless disposal exposes exactly the data the public trusts agencies to protect. Handling both obligations in the right order, settling the records position under the applicable authority, then rendering the data unrecoverable to a recognised standard and evidencing it, is how a NSW agency retires IT without either destroying a record it was bound to keep or leaking data it was bound to protect. For any agency managing public sector IT, disposal is a records event and a security event at the same time, and it has to be run as both.

NSW Government Records & IT Disposal: FAQ

The questions public sector teams ask most about disposing of IT that holds government records.

Not without first settling the records position. Under the State Records Act 1998 (NSW), State records can only be disposed of in an authorised way, so if a drive holds records that must still be kept, destroying it could be an unlawful disposal of those records. The compliant approach is to confirm the records are retained, transferred or authorised for destruction, and then wipe or destroy the drive securely and certify it.

It applies to the records, whatever medium they sit on, including the data on hard drives, servers and backups. A record does not stop being a State record because it lives on a drive that is being retired. So the records on the media are subject to records law, which is why the records position has to be settled before the hardware is destroyed, rather than assuming the physical disposal takes care of it.

That is a records-management decision for the agency, guided by the applicable retention and disposal authority, which sets how long particular records are kept and when they may be destroyed. A data destruction provider does not make that call; it acts once the agency's records team has confirmed the position, then renders the data unrecoverable and certifies it. The two roles are distinct and both are needed.

NSW public sector agencies are expected to handle personal information securely, including disposing of it securely when it is no longer needed. So beyond records law, a government drive holding personal information must have that data rendered unrecoverable, not merely deleted, before the device leaves the agency's control. In practice the secure destruction step covers both the records and the personal information once disposal is authorised.

The secure-destruction steps are the same; the difference is the records-law layer on top. A private business generally decides for itself when data is no longer needed. A public sector agency must dispose of State records only as authorised, so it has an extra gate to clear before destruction. For the general disposal process, our government IT equipment disposal guide covers the steps; this piece adds the records dimension specific to the public sector.

Both the records-disposal documentation and the data-destruction evidence: a certificate for each device recording what was destroyed and to what standard, under a documented chain of custody. Together these show that the records were disposed of as authorised and that the data was securely destroyed. Because government disposal has to be demonstrable and auditable, keeping both sets of records is what completes a compliant disposal.

Retiring public sector IT? Contact our team or call 1300 048 226.

Retire Government IT Without Breaching Records Law

See how ITC works alongside your records team to dispose of government IT compliantly: secure destruction to a recognised standard once disposal is authorised, chain of custody, and a certificate for every device.

Evidence for your auditor

Disposal that stands up to a compliance review

Regulators do not ask whether you recycled the hardware. They ask what happened to the data on it, who handled it, and where the record is. ITC holds ISO/IEC 27001:2022 for information security alongside ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018, and issues serialised documentation on every job so the answer is already written down.

Talk to a compliance specialist View certifications

Book Your Free Collection

Request a callback