portable drive connected to laptop

What a Data Erasure Certificate Should Contain (and How to Spot One That Proves Nothing)

When you sell or dispose of company computers, the erasure certificate is the document that proves the data is gone. It is what your auditor, your data protection officer or the ICO will ask to see if a question is ever raised. Most sellers accept whatever the buyer sends and file it. This article is about what a certificate should actually contain, so that you can tell a real one from a piece of paper with a logo on it.

What the certificate is for

Under UK GDPR, a company that hands personal data to another organisation for processing — and a buyer erasing your drives is processing your data — remains responsible for it. The certificate is your evidence that the processing happened and that the outcome was what you asked for. If it does not identify the specific drive, the method used and who did it, it does not prove much.

Seven things it should contain

1. The drive’s own serial number, not just the laptop’s

A laptop serial identifies the chassis. The data was on the drive inside it, and drives get swapped. A proper certificate lists the storage device by its own serial number (and usually model and capacity), and ties it to the host device serial. One certificate per drive; a single sheet saying “25 laptops erased” does not identify anything.

2. The standard the erasure meets, and the method

The standard most buyers and auditors recognise is NIST SP 800-88, which defines three outcomes: Clear (logical overwrite, adequate for most business data), Purge (makes recovery infeasible even with laboratory techniques, using firmware-level commands such as ATA Secure Erase, NVMe Sanitize or cryptographic erase) and Destroy (physical shredding or degaussing). The more recent IEEE 2883 covers the same ground with updated guidance for modern SSDs. The certificate should say which standard and which level was achieved, and the actual method — “NVMe Sanitize, crypto erase” tells you something; “securely wiped” does not.

One thing worth knowing: the old “DoD 5220.22-M three-pass” overwrite is still widely quoted because customers ask for it, but it was written for magnetic hard drives. On a modern SSD, overwrite passes do not reliably reach every cell, and the correct method is the drive’s own sanitise command. If a buyer only offers multi-pass overwrite on SSDs, ask why.

3. Verification

Erasure and verification are separate steps. A good process reads the drive back after erasure and confirms it contains no recoverable data. The certificate should state that verification was performed and what it found. “Erased” without “verified” is a claim, not a result.

4. Date, time and operator

When it was done and by whom, or at least by which workstation and software version. This is what makes the certificate part of a chain of custody rather than a standalone document.

5. The software or platform used, and its own certification

Erasure is done by software, and the software should be named. Blancco is the brand most people know; there are several others that meet the same standards. What matters is that the tool is named and that its compliance with the stated standard is documented. We use MIST, which sanitises to NIST SP 800-88, IEEE 2883 and DoD 5220.22-M and runs hardware diagnostics in the same pass; we say so plainly because the question is always asked.

6. The outcome for drives that could not be erased

Some drives fail. A failed or unresponsive drive cannot be certified as erased, and an honest certificate says so, along with what happened to it — normally physical destruction, with its own destruction record. A batch where every single drive passed with no exceptions is either a small batch or a certificate that is not telling you everything.

7. A signature and a company identity you can check

Registered company name and number, and an accreditation or standard you can verify. Be wary of vague claims. ADISA is the recognised UK accreditation scheme for IT asset disposal; companies that hold it will say so with a certificate number. Companies that do not should say so too. We do not hold ADISA accreditation, and our certificates and our website say that rather than imply otherwise; what we certify is the standard the erasure met and the evidence behind it.

What you should also receive alongside it

  • An asset register listing every device collected by serial number, so the certificates can be reconciled against what left your building.
  • A signed collection manifest from the day of collection, agreed by both sides.
  • A Waste Transfer Note for anything that went to recycling rather than reuse, showing the carrier’s Environment Agency registration number.
  • A data processing agreement under UK GDPR Article 28 if your organisation requires one — and if you handle sensitive personal data, it should.

The question to ask any buyer

Before you agree a price, ask: “Can you send me an example of the erasure certificate you issue, and what it looks like for a drive that fails?” The answer to the second half tells you more than the first. A buyer who has never had a drive fail has not erased very many.

Our certificate pack, asset register and Waste Transfer Note are standard on every collection, at no charge. If you are planning a disposal and want to see what they look like first, email info@hgctechnologies.uk or WhatsApp us on 0800 208 8010 and we will send samples. Details of how we buy, erase and pay are on our IT buyback page.