The photocopier is the most overlooked data risk in the office, because almost nobody thinks of it as a computer. Most copiers and multifunction devices contain an internal hard drive that stores an image of everything they scan, print and fax. This guide explains what is on that drive, why lease returns are the danger, and how to destroy the data before the machine leaves the building.
You destroy it by securely wiping or physically destroying the copier's internal hard drive before the machine is retired or returned, and getting a certificate to confirm it. A factory reset or the built-in "clear" function is often not enough on its own. Most photocopiers and multifunction printers made in the last two decades contain a hard drive that stores an image of the documents they process, so a retired or returned copier can leave the building carrying a copy of a great deal of sensitive material. The safe approach is to treat the copier exactly like any other data-bearing device: identify the drive, wipe it to a recognised standard or remove and physically destroy it, and issue a certificate. That is part of what a certified data destruction service handles.
This is one of the clearest gaps in how businesses handle data at disposal. Enormous care goes into wiping laptops and shredding paper, while the copier, which has quietly retained an image of every document it touched, is handed back to a finance company at lease end with no thought given to the drive inside it. The result is that a device holding years of sensitive material walks out the door as a routine equipment return. This guide is about closing that gap.
A modern multifunction device is a computer with a hard drive. It has to store what it processes, and often it keeps it.
To scan, copy, print and fax at speed, a multifunction device needs to hold documents in memory and on storage while it works, and most units do this on an internal hard drive. Depending on the model and its settings, that drive can retain an image of the documents it has processed, sometimes for a long time, building up a store of whatever has passed through the machine. In an ordinary office that might include contracts, invoices, payroll, and identity documents. In a professional setting it is far more sensitive: a law firm's affidavits and briefs, a medical practice's patient records, a bank's account and identity documents. The copier does not distinguish; it stores images of whatever it is asked to handle.
The risk became well enough known that regulators have written about it. The United States Federal Trade Commission published guidance for businesses on exactly this issue, noting that digital copiers store images of documents on an internal hard drive and that the data should be protected and cleared before a machine is returned or resold. You can read the FTC copier data security guide for the background. The principle applies just as much in Australia, where the same personal information sits under the Privacy Act.
Most copiers are leased, not owned, and the moment they go back is exactly when the data risk is highest and the attention lowest.
The majority of office copiers are leased, and at the end of the lease the machine is collected by the finance company or the supplier and moved on, refurbished and re-leased, or sold second-hand. In the ordinary course of business this is treated as a logistics event: the old machine goes back, the new one arrives. The internal hard drive, and the images it holds, goes back with it, into a supply chain the business no longer controls. Unlike a retired laptop, which an IT team knows to wipe, the copier is handled by facilities or administration as a piece of office equipment, and the drive inside it is invisible to everyone in the process. That is what makes lease returns the classic copier data breach: not malice, just a device with a hard drive treated as if it did not have one.
The fix is to build a step into the return. Before a copier is handed back, its drive is either securely wiped to a recognised standard or removed and physically destroyed, and a certificate is issued. Some lease agreements allow the business to retain and destroy the drive itself; others require the drive to be wiped in place. Either way, the point is that the data is dealt with before the machine leaves, not left to a supply chain that has no obligation to your clients. A certified provider can handle this as part of a normal on-site or collected destruction, timed to the return.
Some machines have a built-in data-clearing or overwrite feature, and where it exists and is properly configured it helps. But it varies by model, is often turned off by default, and rarely produces the certificate a business needs as evidence. Treating the built-in function as the whole answer is risky; treating it as one input, alongside a verified wipe or physical destruction of the drive with a certificate, is sound.
Four steps turn a copier from an invisible data risk into a documented, cleared device.
Most multifunction devices have an internal hard drive; a certified provider identifies it and any secondary storage, so nothing is missed. Check the lease terms for whether the drive can be retained.
The drive is securely wiped to a recognised standard such as NIST 800-88, or removed and physically shredded where the data is highly sensitive or the drive cannot be reliably wiped.
Time the destruction to the lease return or retirement, so the data is dealt with while the machine is still under your control, not after it has entered a supply chain.
A certificate of destruction for the copier's drive gives you the same evidence you would hold for any other data-bearing device, reconcilable to your records.
The simplest way to make sure copiers are never missed is to include them in the same certified process you use for laptops and servers, rather than leaving them to the facilities team and the lease company. When one provider handles all data-bearing devices, the copier is caught automatically. Talk to our team about including copiers in your disposal.
The copier concentrates a lot of sensitive data in a device nobody is watching, which is exactly the profile of a costly breach. Figures from named sources.
What makes the copier such a potent risk is concentration and invisibility together. A single machine can hold an image of documents from every department that used it, built up over years, and it is the one device in the office that no one thinks to secure at disposal. A retired laptop holds one person's data and gets wiped; the copier holds everyone's and gets handed back. Against a maximum privacy penalty of $50M or more, and the specific sensitivity of what copiers hold in legal, health and financial settings, adding one step to the copier's return is among the cheapest risk reductions a business can make. The question to ask your facilities team is simple: when the last copier went back, what happened to its hard drive.
The questions businesses ask most about the data on copiers and multifunction devices.
Most multifunction devices made in the last two decades contain an internal hard drive, and depending on the model and settings it can retain an image of documents scanned, copied, printed or faxed. The exact behaviour varies by machine, but the safe assumption for any office copier is that its drive holds recoverable images of sensitive material, which is why it should be treated as a data-bearing device at disposal.
Unless you deal with it first, the drive goes back inside the machine, into the supply chain of the finance company or supplier, which may refurbish and re-lease or resell the copier. That is the classic copier data risk: a device holding years of your documents leaves your control as a routine return. Before handing a copier back, wipe or destroy its drive and get a certificate.
It helps where it exists and is properly configured, but it varies by model, is often disabled by default, and rarely produces the certificate a business needs as evidence. Relying on it alone is risky. The sound approach is a verified wipe to a recognised standard, or removal and physical destruction of the drive, with a certificate, using any built-in function as a supplement rather than the whole answer.
Yes. Where the copier is being returned intact, the internal drive can be securely wiped to a recognised standard in place, leaving the machine functional. Where the data is highly sensitive or the drive cannot be reliably wiped, the drive can be removed and physically destroyed, and the copier returned without it if the lease allows. The right approach depends on the machine and your lease terms.
Any business handling sensitive documents, but especially law firms, medical and health providers, and financial services, where the copier accumulates privileged, patient or customer data. For these sectors a copier drive can hold exactly the material their compliance obligations require them to protect, so the copier belongs firmly within their certified disposal process, not their facilities routine.
Include them in the same certified data destruction process you use for laptops and servers, rather than leaving them to facilities and the lease company. When one provider handles every data-bearing device, the copier is caught automatically and certified like the rest. Building a drive-destruction step into every copier return or retirement is the reliable fix.
See how ITC destroys the data on photocopier and MFP hard drives, wiped to a recognised standard or removed and destroyed, timed to your lease return or retirement, with a certificate for the drive.
Destroy it properly
Knowing the right method is only half of it. The other half is being able to prove what happened to each serial number. ITC works to the NIST 800-88 standard under ISO/IEC 27001:2022, records chain of custody from your desk to the shredder, and issues a Certificate of Data Destruction listing the devices processed.