Certificate of Data Destruction

Written by Taras Zavalinii
Founder, T&C Logistics · 5+ years UK logistics experience
Last updated: Companies House verified
Updated August 2026
A certificate of data destruction is a document issued by the party that erased or physically destroyed data-bearing media, recording what was destroyed, by what method, when and by whom. It is not a statutory document and no single UK regulator prescribes its contents, which is why the useful ones itemise serial numbers rather than stating a quantity. It proves nothing about environmental compliance — that is what a waste transfer note does — and it does not transfer your UK GDPR responsibility as data controller.

A certificate of data destruction is the document businesses ask for after disposing of computers, and the one most often misunderstood. It is not required by statute, its contents are not prescribed, and holding one does not move your data-protection responsibility onto someone else. What a good certificate does is evidence that a specific set of drives was destroyed by a specific method on a specific date — which, reconciled against an asset list, is what an auditor or an investigation actually needs. This guide covers what to look for, what to ignore, and how the document differs from the environmental paperwork that accompanies the same collection.

What is a certificate of data destruction?

A certificate of data destruction is a written record, issued by whoever performed the erasure or physical destruction, confirming that specified data-bearing media were destroyed. It records the method used, the date, and the party that carried it out.

The term is industry practice rather than statute. No UK regulation prescribes the format, and the certificate carries no legal force of its own — its value is entirely evidential. That has a practical consequence: two certificates can look equally official while differing enormously in what they actually prove. A document stating that "42 hard drives were destroyed" evidences almost nothing, because it cannot be tied back to the specific drives that left your building. A document listing 42 serial numbers can be.

How is it different from a certificate of destruction for a vehicle?

They are unrelated documents that share a name. A Certificate of Destruction in UK official usage most commonly means the document issued for an end-of-life vehicle, confirming the vehicle has been scrapped and prompting removal from the DVLA record.

The distinction matters when searching for guidance, because the vehicle document is statutory and prescribed while the data document is neither. Unlike the vehicle certificate, which has a defined issuer and a defined regulatory effect, a data destruction certificate is a commercial assurance whose weight depends entirely on the credibility of the issuer and the specificity of its contents. Do not assume the formality of the name implies a regulated standard behind it.

What should a certificate of data destruction contain?

Enough detail to tie named media to a method and a date. Anything less cannot be reconciled against what actually left your site, which is the only test that matters when the document is relied on.

FieldWhy it matters
Itemised media list with serial numbersThe only way to reconcile the certificate against your asset list
Destruction methodErasure, degaussing and physical destruction are different assurances
Date and location of destructionEstablishes when custody of readable media ended
Issuing organisation and named signatoryIdentifies who is standing behind the assurance
Reference to the collection or jobLinks the certificate to the transfer document for the same batch

A certificate quoting only a quantity is the common failure case. It is not useless, but it cannot answer the question an investigation asks, which is whether one specific drive was destroyed.

Does a certificate of data destruction satisfy UK GDPR?

No. It is evidence that you took a step, not a transfer of responsibility. Under UK GDPR the data controller remains accountable for personal data through to its disposal, and that accountability cannot be contracted away.

What the certificate supports is the demonstrability side of the obligation: if asked how you ensured personal data on decommissioned equipment was rendered irrecoverable, the certificate plus the reconciled asset list is the answer. The Information Commissioner's Office is the supervisory authority here, not the Environment Agency, and it is looking at a different question from the one the environmental paperwork answers. Both documents can be present and correct while addressing entirely separate obligations.

Which destruction methods are used, and how do they differ?

Three are common, and they are not interchangeable. Each leaves the media in a different state, carries a different cost, and has different implications for whether the asset retains any value afterwards.

MethodWhat it doesAsset afterwards
Verified erasureOverwrites the data and verifies the result, leaving the drive functionalReusable or resaleable
DegaussingDisrupts the magnetic field of magnetic mediaGenerally unusable; not applicable to solid-state media
Physical destructionShreds or otherwise destroys the drive itselfDestroyed; recovered as material

The distinction that catches people out is degaussing and solid-state drives: a technique built around magnetic media does not address flash storage, so applying it to an SSD is not the assurance it appears to be. Whereas verified erasure preserves residual value and is generally the better environmental outcome, physical destruction is simpler to evidence and is often preferred for the most sensitive data. The certificate should state which method was applied to which items, because a mixed batch frequently receives mixed treatment.

How does it differ from a waste transfer note?

They record different events. A waste transfer note records the movement of waste from you to a registered carrier; a destruction certificate records what happened to the data on that equipment afterwards.

Neither substitutes for the other, and the two are typically issued by different parties. The transfer note is completed at collection and signed by both sides; the certificate is issued later, by whoever performed the destruction, once it has been carried out. Filing them together against the same job reference is the practical discipline, because an audit that asks about a disposal will usually want both, and reconstructing the pairing months later from separate systems is where the time goes.

Who can issue a certificate of data destruction?

Whoever actually performed the destruction. That is the only meaningful constraint, since the document is an assurance about work done rather than a regulated instrument.

It follows that a carrier who transported equipment but did not destroy anything is not the right issuer, and a certificate from such a party is worth less than it appears. Where physical destruction or certified erasure is performed at a partner facility, the certificate should come from that facility in its own name. Some processors work to recognised destruction and erasure standards; where they do, the certificate should say which standard and the claim should be checkable against that scheme rather than asserted in passing.

What should you do before equipment leaves your site?

Capture the asset list yourself. Everything the certificate can later prove depends on a record made before the equipment moves, and that record is the one part of the chain nobody else can create for you.

  1. Itemise data-bearing assets with serial numbers, before collection.
  2. Record which items are being erased and which physically destroyed, since the certificates differ.
  3. Agree who issues the certificate and confirm it will itemise rather than summarise.
  4. File it against the transfer document for the same collection.

For the full documentation set, see the documents you receive when disposing of business IT, and for the collection itself, chain-of-custody IT collection or get in touch.

Related Questions

Is a certificate of data destruction a legal requirement?
No UK regulation requires one or prescribes its contents. The obligation it supports comes from UK GDPR, which requires appropriate security for personal data through to disposal and requires you to be able to demonstrate compliance. The certificate is one of the more convenient ways to evidence that step, which is why it is near-universal commercially despite not being statutory.
Should the certificate list serial numbers or is a quantity enough?
Serial numbers. A quantity cannot be reconciled against the assets that left your site, so it cannot answer whether a particular drive was destroyed — which is precisely the question asked when something goes wrong. Itemised certificates also make it possible to spot a discrepancy between what was collected and what was processed, while there is still time to investigate.
Is physical destruction better than software erasure?
They serve different purposes rather than ranking. Verified erasure preserves the asset for reuse or resale, which is generally the better environmental and financial outcome; physical destruction removes the drive from service entirely and is simpler to evidence. The right choice depends on the sensitivity of the data and whether the equipment has residual value worth recovering.
Can the carrier that collected the equipment issue the certificate?
Only if that carrier performed the destruction. The certificate is an assurance about work actually done, so it should be issued by the party that did it. Where collection and destruction are performed by different organisations — the common arrangement — the certificate comes from the processor, while the carrier's contribution to the evidence chain is the transfer document and the asset list.
How long should a certificate of data destruction be kept?
No period is prescribed, because the document is not statutory. A practical approach is to keep it at least as long as the transfer document it pairs with, which for a waste transfer note is two years, and longer where your own retention policy or sector requirements demand it. Storing both against the same job reference makes the retention decision a single one rather than two.

Explore more

How It Works

1

Get a Quote

Call, WhatsApp, or use our online form. Quote in under 2 minutes.

2

We Collect in 30-60 Min

A dedicated driver dispatched to your door. GPS tracked from pickup.

3

Delivered with POD

Signed proof of delivery with photo. Real-time updates throughout.

URGENT? Call NowWhatsApp Quote
2,400+
Deliveries Completed
43
UK Cities Covered
24/7
Available 365 Days
5.0★
Google Rating

Compliance & Trust

Companies House
Registered
Fully Insured
Up to £50K
ADR Licensed
Hazardous goods
Pharma Partner Network
GDP-certified carriers
ULEZ Compliant
No surcharges
GPS Tracked
Live updates
24/7 Dispatch
365 days/year
GDPR Compliant
Data protected
CallWhatsAppQuote