Data destruction is the step before recycling: the point at which a drive, a phone or a copier stops being a record and becomes hardware. The rules that reach most businesses name the obligation, not the method, and none of them is satisfied by a dumpster and a good intention. What they ask for, in practice, is a defensible process and a record of it, and the record is the product you are buying from any destruction vendor.
#What the rules require
Three federal rules do most of the work. For health information, the HIPAA Security Rule requires covered entities to "implement policies and procedures to address the final disposition of electronic protected health information, and/or the hardware or electronic media on which it is stored." The same standard covers media that will be reused: the information has to be removed from the media before the media are made available for reuse.
For consumer information, the FTC Disposal Rule requires "reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal," and gives as an example "destruction or erasure of electronic media containing consumer information so that the information cannot practicably be read or reconstructed." Financial institutions under the FTC Safeguards Rule must "develop, implement, and maintain procedures for the secure disposal of customer information in any format no later than two years after the last date the information is used."
None of the three names a shredder, a wiping tool or a certificate. Each requires a method you can defend and a record that shows it was applied.
#What counts as sanitization
The reference most auditors use is NIST Special Publication 800-88, which defines media sanitization as "a process that renders access to target data on the media infeasible for a given level of effort." In plain terms there are two honest routes. Sanitize the drive with a verified software or firmware process, logged per serial number, when the hardware has resale or reuse value. Destroy it physically when the data is sensitive enough, the drive old enough or the volume large enough that per-drive verification is not worth the time.
Deleting files, formatting the drive or resetting the device is neither. The data is still there for anyone with ordinary recovery tools, and no auditor reads a factory reset as sanitization.
Solid-state drives need a separate question. Methods built for spinning disks do not necessarily remove data from flash memory, so ask which method the vendor uses for SSDs and get that method named on the certificate.
#The five records
Sanitization proves nothing on its own; the record trail does. A defensible chain of custody has five documents, each handing off to the next: an inventory with serial numbers and asset tags, written before anything moves; a collection manifest signed at the dock; a destruction or sanitization record for each data-bearing device, naming the method and the date; a disposition record for where the chassis, boards and materials went; and a certificate of destruction that ties the four together. If any one is missing, the chain has a gap, and the gap is where the questions land. The chain of custody guide walks through each record and where chains break in practice.
#Devices people miss
The drives that cause breaches are rarely the ones in the server room. Copiers come first: the FTC's guidance for businesses is that "the hard drive in a digital copier stores data about the documents it copies, prints, scans, faxes or emails." A copier returned to a lessor with its drive in place has not been sanitized.
Laptops in drawers, handed to departing staff or boxed during a move carry whatever their last user did. UPS units and network gear hold configurations, credentials and logs. Phones and tablets are computers with smaller screens. Anything with an operating system or a drive belongs on the inventory and goes through the same step as a server.
Storage media are wiped or physically destroyed before any device enters the recycling stream, and every job closes with documents listing the devices processed, the method, and the date. The IT asset disposition page describes that process at scale, the electronics recycling page the pickup itself, and the medical practices and dealerships and financial firms pages the two most regulated cases.





