Data Destruction Procedures¶
Last Updated: February 2026 Target Audience: Warehouse Staff (Hard Drive Team), IT Manager, Operations Manager, Management
This guide covers Scott Recycling's data destruction procedures, from the moment a data-bearing device enters our facility to the issuance of a Certificate of Destruction. Proper data destruction protects our customers, satisfies legal requirements, and is a core component of R2 certification.
Overview¶
Every device that enters Scott Recycling may contain sensitive data -- customer records, financial information, health data, intellectual property, or personal files. Our responsibility is to ensure that data is completely and irreversibly destroyed before any device is resold, recycled, or scrapped.
Data Breach Risk
A single improperly wiped hard drive can expose a customer to a data breach, resulting in lawsuits, regulatory fines, and loss of trust. Treat every data-bearing device as if it contains the most sensitive information imaginable.
Data-Bearing Devices¶
The following devices may contain data and must go through the data destruction process:
| Device Type | Common Data Storage | Destruction Method |
|---|---|---|
| Desktop computers | HDD, SSD | Software wipe or physical destruction |
| Laptops / Chromebooks | HDD, SSD, eMMC | Software wipe or physical destruction |
| Servers | HDD, SSD, RAID arrays | Software wipe or physical destruction |
| External hard drives | HDD, SSD | Software wipe or physical destruction |
| USB flash drives | Flash memory | Physical destruction |
| Phones / Tablets | Flash memory | Factory reset + physical destruction |
| Printers / Copiers (with storage) | HDD, flash memory | Physical destruction |
| Networking equipment | Flash memory, NVRAM | Factory reset or physical destruction |
| Tape drives / backup tapes | Magnetic tape | Degaussing or physical destruction |
Chain of Custody¶
Chain of custody documentation tracks every data-bearing device from the moment it arrives at our facility until data destruction is verified and documented.
Step 1: Receiving¶
When materials arrive (via driver pickup or customer drop-off):
- Log the incoming shipment in the receiving system with:
- Customer name and contact information
- Date and time received
- Receiving employee name
- General description of materials (e.g., "15 desktop towers, 8 laptops, 2 boxes loose hard drives")
- Segregate data-bearing devices from non-data-bearing materials immediately
- Move data-bearing devices to the secure staging area (access-controlled)
Step 2: Inventory and Serial Number Recording¶
Before any processing occurs:
- Record the serial number of every data-bearing device
- Hard drives: manufacturer serial number on the label
- SSDs: manufacturer serial number on the label
- Laptops/desktops: asset tag or service tag (Dell, HP, Lenovo)
- If no serial number is legible, assign an internal tracking number
- Link serial numbers to the customer in the tracking system
- Record the media type (HDD, SSD, tape, flash, etc.)
Serial Number Scanning
Use the Serial Number Scanner in Odoo to streamline serial number capture. Scan barcodes where available; manually enter where not.
Step 3: Secure Storage¶
Data-bearing devices awaiting destruction must be stored securely:
- Locked area with restricted access (authorized personnel only)
- No devices leave the secure area until destruction is complete and documented
- Inventory counts of the secure area should be conducted regularly
Step 4: Destruction¶
Destruction is performed using one of the approved methods described below.
Step 5: Verification and Documentation¶
After destruction:
- Verify destruction -- confirm the device is wiped (software) or physically destroyed
- Record the destruction in the tracking system:
- Serial number
- Destruction method used
- Date of destruction
- Employee who performed the destruction
- Verification result (pass/fail)
- Failed devices must be re-processed or escalated (see "Handling Failures" below)
Step 6: Certificate of Destruction¶
Issue a Certificate of Destruction to the customer (see section below).
Destruction Methods¶
Method 1: Software Wiping (Sanitization)¶
Software wiping overwrites all data on a storage device with random data patterns, rendering the original data unrecoverable.
When to use:
- HDDs and SSDs that will be resold or reused
- Devices where physical destruction is not required by the customer
Standard: NIST 800-88 "Clear" or "Purge" level (see NIST section below)
Procedure:
- Connect the drive to the wiping workstation
- Select the appropriate wiping method:
- HDDs: Minimum 1-pass overwrite (NIST 800-88 Clear) or 3-pass overwrite (DoD 5220.22-M) if customer requires
- SSDs: Use manufacturer Secure Erase command or NIST 800-88 Purge method (standard overwrite is insufficient for SSDs due to wear leveling)
- Run the wipe and wait for completion
- Verify the wipe -- the wiping software should produce a verification report
- Record the result with the serial number in the tracking system
SSD Wiping
Standard overwrite methods are NOT sufficient for SSDs. SSDs use wear leveling, which means overwrite passes may not reach all data cells. Always use the manufacturer's Secure Erase command or NIST 800-88 Purge method for SSDs. When in doubt, physically destroy the SSD.
Advantages:
- Drives can be resold, generating revenue
- Non-destructive -- preserves the hardware
- Automated and scalable
Limitations:
- Takes time (hours per drive for HDDs)
- May not work on damaged or failing drives
- SSD wiping requires specific methods
Method 2: Physical Destruction (Shredding)¶
Physical destruction reduces the storage device to small fragments, making data recovery physically impossible.
When to use:
- Any device where software wiping is not possible (damaged drives, failing drives)
- Devices where the customer requires physical destruction
- SSDs where Secure Erase is not available or cannot be verified
- Flash drives, tapes, and other media that cannot be reliably wiped
Procedure:
- Remove the hard drive or storage device from the computer/server
- Record the serial number (if not already recorded)
- Feed the drive into the shredder
- Verify destruction -- fragments should be no larger than the facility's defined maximum particle size
- Record the destruction with the serial number
Shredder Safety
Follow all lockout/tagout procedures before performing any maintenance on the shredder. Keep hands, clothing, and loose items away from the feed area. Wear required PPE: safety glasses, cut-resistant gloves, and hearing protection.
Advantages:
- Absolute data destruction -- no possibility of recovery
- Works on any storage media type
- Fast processing time per unit
- Visible, verifiable destruction
Limitations:
- Drives are destroyed and cannot be resold
- Equipment maintenance costs
- Generates scrap material that must be managed
Method 3: Degaussing¶
Degaussing uses a powerful magnetic field to erase data on magnetic media by disrupting the magnetic domains on the storage surface.
When to use:
- Magnetic HDDs (not effective on SSDs or flash media)
- Backup tapes
- Situations where physical destruction equipment is not available
Procedure:
- Place the drive in the degausser
- Run the degaussing cycle
- Verify the drive is non-functional (a properly degaussed drive will not spin up)
- Record the destruction with the serial number
Degaussing Limitations
Degaussing is NOT effective on SSDs, flash drives, or any solid-state media. It only works on magnetic media (HDDs and tapes). Always verify that degaussed drives are non-functional.
NIST 800-88 Guidelines for Media Sanitization¶
NIST Special Publication 800-88 (Revision 1) provides the federal standard for media sanitization. R2 certification references NIST 800-88 as the benchmark for data destruction.
Sanitization Levels¶
| Level | Method | Description | When to Use |
|---|---|---|---|
| Clear | Overwrite | Overwrites all addressable storage locations with a fixed value or random data | Drives being reused within the organization or resold to known parties |
| Purge | Enhanced overwrite, block erase, or cryptographic erase | More thorough than Clear; uses technology-specific methods to make data recovery infeasible | Drives leaving organizational control (resale, recycling) |
| Destroy | Physical destruction | Shredding, disintegration, incineration, or melting | Highest security requirements; media cannot be reused |
Selecting the Right Level¶
For Scott Recycling's operations:
- Customer drives being resold: Minimum Purge level
- Customer drives being scrapped: Destroy level (physical destruction)
- Drives with unknown contents: Purge or Destroy
- Drives where customer contract specifies destruction: Destroy level only
- Damaged drives that cannot be wiped: Destroy level
Verification Requirements¶
NIST 800-88 requires verification after sanitization:
- For Clear/Purge: Sample verification by attempting to read the sanitized media
- For Destroy: Visual verification that the media is destroyed beyond recovery
- All levels: Document the method, verification result, and date
Serial Number Tracking Requirements¶
Every data-bearing device must be tracked by serial number throughout the destruction process.
Required Data Points¶
| Field | Description | Example |
|---|---|---|
| Serial Number | Manufacturer serial or internal ID | WD-WCAV5H123456 |
| Customer | Who the device came from | ABC Corporation |
| Date Received | When it arrived at our facility | 2026-02-15 |
| Media Type | HDD, SSD, tape, flash, etc. | HDD |
| Capacity | Storage capacity | 500 GB |
| Destruction Method | Software wipe, shred, degauss | Shredded |
| Destruction Date | When destruction was performed | 2026-02-18 |
| Performed By | Employee who performed destruction | John Smith |
| Verification Result | Pass or fail | Pass |
| Certificate Number | CoD reference number | COD-2026-0215-001 |
Tracking System¶
Serial numbers and destruction records are maintained in the Odoo system. See the Serial Number Scanner guide for scanning and entry procedures.
Certificate of Destruction¶
A Certificate of Destruction (CoD) is a formal document provided to the customer confirming that their data-bearing devices have been securely destroyed.
What the Certificate Must Include¶
| Field | Description |
|---|---|
| Certificate number | Unique identifier (e.g., COD-2026-0215-001) |
| Customer name and address | The organization whose devices were destroyed |
| Date of destruction | When destruction was performed |
| Destruction method | Software wipe (to NIST 800-88 standard), physical destruction, or degaussing |
| Device list | Serial numbers, media types, and quantities of all destroyed devices |
| Sanitization standard | Reference to NIST 800-88 level (Clear, Purge, or Destroy) |
| Scott Recycling information | Company name, address, contact, authorized signature |
| Authorized signature | Signed by the employee responsible for data destruction operations |
Issuing Certificates¶
- After all devices for a customer shipment have been destroyed and verified, generate the CoD
- Review the certificate for accuracy -- verify serial numbers match the customer's shipment
- Obtain authorized signature
- Send the certificate to the customer (email PDF and/or mail hard copy, per customer preference)
- Retain a copy in the customer's file
Certificate Reports
See the Certificate Reports guide for generating Certificates of Destruction from Odoo.
Timing¶
- Certificates should be issued within 5 business days of completing destruction
- If the customer requests expedited certification, prioritize accordingly
Witnessed Destruction¶
Some customers -- particularly government agencies, healthcare organizations, and financial institutions -- require witnessed destruction of their data-bearing devices.
Procedure for Witnessed Destruction¶
- Schedule the visit -- coordinate a date and time with the customer
- Prepare the devices -- have all the customer's devices identified, serial numbers recorded, and staged in the destruction area
- Customer witness arrives -- verify their identity and provide required PPE (safety glasses, hearing protection)
- Perform destruction -- destroy each device while the customer observes
- Document each device -- record the serial number and destruction result as each device is processed
- Generate the CoD -- issue the certificate on-site if possible, with both parties signing
- Provide the certificate -- give the customer their copy immediately or within 24 hours
Witnessed Destruction Best Practices
Have everything staged and ready before the customer arrives. A smooth, professional witnessed destruction visit builds customer confidence and often leads to repeat business and referrals.
Handling Failures¶
When a drive cannot be successfully wiped (software returns an error or verification fails):
- Do not return the drive to general inventory
- Flag the drive in the tracking system as "wipe failed"
- Escalate to physical destruction -- the drive must be shredded
- Update the tracking record with the new destruction method and result
- Notify the team lead if failures are frequent -- may indicate equipment issues
Record Retention¶
| Record Type | Retention Period | Notes |
|---|---|---|
| Destruction logs (serial numbers, methods, dates) | Minimum 7 years | Many customer contracts require 7 years; some require longer |
| Certificates of Destruction | Minimum 7 years | Retain copies of all CoDs issued |
| Chain of custody documentation | Minimum 7 years | Receiving logs, transfer records |
| Wipe verification reports | Minimum 7 years | Software-generated wipe reports |
| Customer contracts/agreements | Duration of contract + 7 years | Data destruction service agreements |
| Employee training records | Duration of employment + 3 years | Data security training documentation |
Do Not Discard Records
If in doubt about whether to keep a record, keep it. The cost of storing records is trivial compared to the cost of being unable to produce them when a customer, auditor, or attorney asks.
Customer Communication¶
What to Tell Customers About Our Data Destruction¶
When discussing data security with customers:
- We follow NIST 800-88 Guidelines for media sanitization
- Every data-bearing device is tracked by serial number from receipt to destruction
- We provide a Certificate of Destruction listing every device and its serial number
- We offer both software sanitization (for drives being resold) and physical destruction (for drives being scrapped)
- Witnessed destruction is available upon request
- Our procedures are designed to meet R2 certification data security requirements
What NOT to Say¶
- Do not guarantee that data has "never" been accessed -- we guarantee it has been destroyed
- Do not make claims about specific certifications we do not yet hold
- Do not commit to turnaround times without checking with the destruction team
Employee Training Requirements¶
All employees who handle data-bearing devices must complete the following training:
| Training Topic | Frequency | Audience |
|---|---|---|
| Data security awareness | At hire + annually | All warehouse and processing staff |
| Chain of custody procedures | At hire + annually | Receiving staff, drivers, processing staff |
| Software wiping procedures | At hire + when methods change | Hard drive team |
| Physical destruction equipment operation | At hire + when equipment changes | Hard drive team |
| Certificate of Destruction generation | At hire + when process changes | Hard drive team lead, IT Manager |
| Serial number tracking system | At hire + when system changes | All processing staff |
All training must be documented with date, topic, trainer, and attendee signature.
Questions? Contact your supervisor or refer to the Getting Started guide.