Most companies have their GDPR house in order for live systems: access control, retention policies, processor agreements. But GDPR doesn't stop when a device is retired. The moment a laptop, server or phone leaves your organisation with readable data on it, you have a data breach waiting to be discovered. Here is what compliant disposal actually requires, and the paperwork that proves it.
GDPR doesn't stop at the storage room
Two GDPR principles follow your hardware to the very end. Storage limitation (Art. 5.1.e) says personal data may not be kept longer than needed, including on retired drives in a cellar. Integrity and confidentiality (Art. 5.1.f) demands protection against unauthorised access, including access to a discarded or resold device.
Add accountability (Art. 5.2): you must be able to demonstrate compliance. It's not enough that data was destroyed, you must be able to prove it was. That's why documentation matters as much as the destruction itself.
Erasure or physical destruction, which does GDPR require?
GDPR is technology-neutral: it requires appropriate measures, not a specific method. In practice two approaches meet the bar. Certified software erasure overwrites the entire data carrier and verifies the result, the device stays usable, which enables reuse and resale. Physical destruction shreds or destroys the data carrier itself, the right choice for failed drives and the most sensitive data.
A professional partner uses both: verified erasure where reuse is possible, physical destruction where it isn't or where the risk profile demands it. What matters for compliance is that the method is documented per data carrier, and that erasure is verified, not assumed.
The three documents your auditor wants to see
One: a registered intake list, every device and data carrier logged by serial number at handover, so there's no gap between what left your building and what was processed.
Two: a certificate of destruction, stating per data carrier which method was applied (verified erasure or physical destruction), when, and with what result.
Three: a final asset report, the end destination of every registered device: refurbished and resold, donated, or recycled. Together these three documents form a closed chain of custody from your office to the final report. File them with your GDPR records (Art. 30 processing register).
The five most common disposal mistakes
One: relying on factory resets or formatting, recoverable with free tools. Two: storing old devices 'for now' in an unsecured room, the data remains your liability the entire time. Three: giving devices to employees or movers without documented erasure. Four: selling to a broker who doesn't provide per-device destruction certificates. Five: destroying everything blindly, you burn residual value that could have offset the cost, without gaining any extra compliance.
What non-compliance actually costs
GDPR fines can reach up to 4% of worldwide annual turnover or €20 million, and data-carrier disposal is a documented enforcement theme across the EU. But the realistic cost usually arrives earlier: a lost or resold drive with customer data is a notifiable data breach, with the forensics, notifications and reputation damage that follow. Compared to that, professional destruction with full documentation is one of the cheapest insurance policies in IT.
Frequently asked questions
Is BitLocker or disk encryption enough for GDPR-compliant disposal?
Encryption is a strong safeguard during a device's life, but for disposal it's not a substitute for documented destruction: keys can leak, implementations age, and you can't demonstrate compliance with 'the disk was probably encrypted'. Verified erasure or physical destruction, documented per data carrier, is the defensible route.
If we outsource disposal, who is responsible under GDPR?
You remain the data controller. Outsourcing shifts the work, not the accountability, which is exactly why you should choose a partner that registers every serial number and hands you certificates and a final report you can show your auditor.
Do we need a certificate for every single drive?
Best practice is destruction evidence per data carrier, tied to its serial number. A single 'everything was wiped' statement for a whole batch leaves gaps an auditor, or a court, will notice.
How fast can retired devices be collected in Belgium?
GreenByte collects on site across Belgium and France, Monday to Saturday from 07:00 to 20:00, from a single pallet to a full office clear-out. Request a free quote and you'll have an answer within one business day.
Rather talk it through?
