Secure Data Destruction Services for UK Businesses
Every laptop, server, phone and backup tape your business retires still holds data: client records, payroll, contracts and login credentials. Deleting files or formatting a drive doesn’t remove it. Until that data is destroyed to a recognised standard, and you can prove it, it remains your organisation’s responsibility under UK GDPR.
Computer IT Disposals provides secure data destruction for businesses and public sector organisations across England, Scotland and Wales. We erase to HMG IS5 and NIST 800-88, shred to BS EN 15713 at your premises or ours, and issue your certificates within five working days, with every device accounted for.
Data Destruction At A Glance
- What it is:Data destruction is the process of making data on storage media permanently unrecoverable, by certified erasure or physical shredding, and documenting it so the owner can prove it was done.
- Who provides it:Computer IT Disposals (Commercial IT Recycling Ltd) provides certified data destruction services to UK organisations. Established 2014, processing at an Environment Agency licensed facility in Nottingham.
- Methods and standards:Certified erasure to HMG Infosec Standard No. 5 and NIST SP 800-88 Revision 2 (Clear or Purge), degaussing, hard drive crushing and punching, and physical shredding to BS EN 15713.
- Where:At our licensed facility, or on site at your premises with witnessed shredding. Collections across England, Scotland and Wales.
- Evidence:Serialised audit report, Data Destruction Certificate and full compliance pack within five working days, under one collection reference.
- Security:BS 7858-screened staff, Cyber Essentials Plus, ICO registered (ZA246798), ISO 9001 and ISO 14001, and GPS-tracked vehicles.
What Is Certified Data Destruction?
Certified data destruction means two things happen, not one. First, the data on every device is destroyed to a named standard, so it can’t be recovered with forensic tools. Second, the destruction is recorded device by device and certified, so your organisation can prove to an auditor, a client or the ICO exactly what was destroyed, how, when and by whom.
That second part is what separates secure data destruction by a professional data destruction company from a skip or a drill. NIST SP 800-88 recommends a certificate of sanitisation for each item, recording details such as the make, model, serial number, media type, method and verification used. Our certificates and serialised audit reports follow the same approach, so the evidence matches the standard your security policy names.
Why Data Destruction Matters: Deleting Is Not Destroying
Files sent to the recycle bin, formatted drives and laptops reset to factory settings all routinely yield recoverable data to basic forensic tools. Disposal is one of the most avoidable ways a breach happens: the equipment left your building, but the data didn’t leave the equipment.
In the wrong hands, what sits on a redundant company machine isn’t an IT problem. It means regulatory action, a contractual breach and client trust you spent years building, gone in an afternoon.
Solid-state storage makes this harder. SSDs and NVMe drives spread data across spare memory cells the operating system can’t reach, so a simple overwrite can miss it, and degaussing has no effect on flash memory. Modern devices need the firmware-level sanitisation that the standards describe, or physical shredding.
Our Data Destruction Methods
There is no single right method for every device. We match the method to the media type, its condition and your security policy, and your certificate records exactly what was done.
If you don’t have a policy, HMG IS5 erasure is our default for working equipment, with shredding for anything that can’t be verifiably erased.
-
1. Certified Data Erasure to HMG IS5
Our defaultHMG Infosec Standard No. 5 is the UK Government’s long-standing data erasure standard, still specified in many public and private sector contracts. Our default is the Enhanced level: three overwrite passes with verification, using Blancco’s ADISA-certified data erasure software. Our data erasure services, sometimes called data wiping, leave the hardware reusable, which is better for the environment and can offset your costs.
-
2. NIST 800-88 Clear or Purge
NIST SP 800-88 is the internationally recognised media sanitisation standard, now in Revision 2, published in September 2025 and superseding the 2014 edition. It defines three outcomes: Clear, Purge and Destroy. If your compliance team names the level, we work to exactly that, using the right technique for each media type, including firmware-level sanitisation for SSDs.
This matters to overseas clients too: US and European organisations with servers in UK data centres routinely specify NIST 800-88, and we deliver it to the current revision.
-
3. Physical Shredding to BS EN 15713
Where erasure isn’t possible or your policy demands physical destruction, media is shredded in accordance with BS EN 15713, the standard for secure destruction of confidential material: hard drives to 6–8mm and SSDs to 2mm. Failed drives, locked devices, tapes and flash media all go this way. For volume or per-drive work, see our hard drive shredding and SSD shredding services.
-
4. Degaussing for Magnetic Media
Degaussing exposes magnetic media to a powerful magnetic field that scrambles the stored data, leaving hard drives and backup tapes unreadable in seconds. It is fast for large volumes of HDDs and LTO tapes, and it works on drives that have failed and can’t be erased. It has no effect on SSDs, flash memory or phones, so those are erased or shredded instead.
| Method | Best for | Standard | Hardware afterwards |
|---|---|---|---|
| Data erasure | Working drives, laptops, desktops and servers | HMG IS5 Enhanced, NIST 800-88 Clear or Purge | Reusable |
| Physical shredding | Failed drives, SSDs where policy requires, tapes, flash media, locked devices | BS EN 15713 | Destroyed and recycled |
| Degaussing | Magnetic hard drives and backup tapes, including failed drives | Method recorded on your certificate | Unusable, then recycled |
| On-site shredding | Policies that say data can’t leave the building | BS EN 15713, witnessed by your team | Destroyed at your premises |
Our guide to data destruction methods explains each approach in more depth.
Destroying Data by Device Type
Electronic data destruction covers far more than hard drives, and different media need different treatment. This is how we destroy the data on the equipment businesses send us most often.
Data tape destruction deserves a special mention. A single backup tape can hold years of complete company records, and tapes are easy to overlook in a clear-out. We degauss or shred LTO and legacy tapes and list them on your certificate like any other media.
Every route ends in certified erasure or destruction, and the hardware is then recycled, with 100% diverted from landfill, as part of our full IT asset disposal service.
On-Site Data Destruction at Your Premises
Some data should never leave the building intact. For legal practices, financial firms and any organisation whose policy requires confidential data destruction on site, we bring the destruction to you: on-site shredding at your premises, witnessed by your own team, with a serialised audit report and certificate covering everything destroyed. See our on-site hard drive shredding service.
Where your policy requires the complete destruction of the hardware itself, full physical destruction of the entire device is available on the same basis. Witnessed destruction at our facility can also be arranged by appointment.
On-site shredding may carry a charge and complete device destruction is chargeable, always agreed and approved by you before anything is booked. Confidential paper shredding to the same BS EN 15713 standard can be added to the same visit (charges may apply).
Your Data Destruction Certificate
The certificate is the part auditors actually read. Within five working days of processing, you receive a Data Destruction Certificate covering every collected device and stating the method used, with serial-level detail in your IT Asset Audit report where required, reconcilable line by line against your own asset register.
No batch totals hiding gaps and no devices unaccounted for: that is what auditors and client security questionnaires ask for, and what a certificate of data destruction has to show.
What makes this possible is our own purpose-built ITAD management system. Every collection is booked in, documented digitally at your site, tracked into processing and certified out under one collection reference. Each device is logged by make, model, serial number, asset tag, hard drive serial and grading status in our ITAD asset portal, which your team can access at any point in the process. View a sample Data Destruction Certificate.
Do You Need a Certificate of Destruction?
No law names a specific document, but UK GDPR’s accountability principle requires you to be able to demonstrate that personal data was protected, right through to disposal. In practice, a data destruction certificate is how businesses do that, and most security policies, ISO audits and client contracts ask for one.
A Chain of Custody You Can Trust
Destruction is only as strong as the journey before it. Every collection is carried out by our own directly employed team, never third-party couriers. Equipment is counted item by item at your site and recorded onto your Waste Transfer Note and Duty of Care documents, signed digitally on our ITAD management system, which emails your copies before our vehicle has left your site.
Equipment travels in locked cages and secure containers in GPS-tracked vehicles, direct to our Environment Agency licensed facility in Nottingham: alarmed, access-controlled and CCTV-monitored around the clock by an external security company. The consignment is checked in against the collection record before processing begins. Our staff are security-screened to BS 7858, our information security is Cyber Essentials Plus certified, we are ICO registered, and the whole operation runs under ISO 9001 and ISO 14001 certified management systems. See our licences and certifications.
Data Destruction and Your Legal Duties
Under UK GDPR and the Data Protection Act 2018, your organisation stays responsible for personal data until it is destroyed, including the data on equipment you no longer use. UK GDPR requires appropriate security for personal data and the ability to demonstrate compliance, and the ICO can and does act on careless disposal.
The National Cyber Security Centre’s guidance on secure sanitisation of storage media sets out how media should be sanitised and disposed of, and NIST SP 800-88 is the benchmark named in many international contracts. Separately, the equipment itself is waste: your Duty of Care requires a licensed carrier and a Waste Transfer Note, and electrical items must be recycled under the WEEE Regulations.
Our compliance pack proves both obligations were met, in one place: Data Destruction Certificate, WEEE Certificate, ESG Report and IT Asset Audit where required.
Does Your Business Need a Data Destruction Policy?
A policy like this sets out which method applies to which media, who approves disposal and what evidence you keep. If you have one, we work to it exactly. If you don’t, we’ll recommend a sensible default and document it so it can become your policy.
Why Businesses Choose Our Computer Recycling Services
-
Established 2014
Over a decade doing nothing but secure IT disposal.
-
Our own fleet, our own people
BS 7858 vetted staff, GPS-tracked vehicles, no subcontracted couriers.
-
Evidence by design
Digital Waste Transfer Note on site, then one compliance pack under one reference.
-
Certified throughout
ISO 9001, ISO 14001, Cyber Essentials Plus, CHAS, ICO registered and an Environment Agency licensed facility. See our certifications.
-
Straight answers on cost
Clear free-collection criteria, and any charge agreed before booking.
-
Trusted on regulated work
From IT service providers running national utility and healthcare infrastructure programmes to schools, law firms and public bodies, including corporate computer recycling programmes across multi-site estates.
Sector-specific requirements
Data Destruction for Regulated Sectors
Some sectors face extra scrutiny. We provide data destruction services across:
- Healthcare:patient and clinical records on laptops, servers and practice IT, with serial-level evidence.
- Financial services and banking:client financial data, destroyed to the standard your risk and compliance teams specify.
- Legal:privileged client files, with witnessed on-site shredding where firm policy requires it. See IT disposal for the legal sector.
- Education:pupil and staff data across schools, colleges and universities. See education IT disposal.
- Public sector:HMG IS5 erasure and full documentation for procurement. See public sector IT disposal.
- Data centres:racks, arrays and tape libraries during migrations. See data centre decommissioning.
Data Destruction Across the UK
We provide data destruction UK-wide, with collections across England, Scotland and Wales. London is our busiest area: see our London IT disposal service and our off-site data destruction service in London. For local details, choose your area:
- London and the South East: London, Reading, Slough, Oxford and Milton Keynes
- The Midlands: Birmingham, Coventry, Leicester and Nottingham
- The North West: Manchester
- The South West: Bristol and Bath
Not listed? We collect across England, Scotland and Wales. See all locations we cover.
Data Destruction Case Studies
We’ve helped organisations across the UK securely erase and destroy data on redundant IT equipment, fully documented for audit.
Frequently Asked Questions
Book A Collection
Free collection available for qualifying items · certificates within 5 working days · 100% diverted from landfill.














