← Blog ·

GDPR Data Disposal Duties: What UK Businesses Are Required to Do

GDPR data disposal is a legal obligation, not an optional good practice. Under UK GDPR, organisations must erase personal data when it is no longer needed, and must do so in a way that prevents recovery. They must also document that disposal took place — both to fulfil the accountability principle and to defend themselves in the event of a regulatory investigation.

Why Data Disposal Is a GDPR Obligation

Many UK businesses treat data disposal as a practical or logistical task — clearing out old equipment or deleting records to save storage space. UK GDPR frames it very differently. The storage limitation principle (Article 5(1)(e)) and the integrity and confidentiality principle (Article 5(1)(f)) together create a positive legal duty to erase data that is no longer needed, and to do so securely.

Failure to meet this duty is not just poor practice — it is a breach of UK GDPR, and the Information Commissioner’s Office (ICO) has enforcement powers that include fines of up to £17.5 million or 4% of global annual turnover, whichever is higher.

The Storage Limitation Principle

Article 5(1)(e) of UK GDPR requires that personal data be kept “in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.”

In practice, this means every category of personal data your organisation holds must have a defined retention period. Once that period expires, the data must be erased — not archived indefinitely, not moved to a “cold storage” folder and forgotten, but genuinely deleted. For digital data on hardware, deletion must be carried out in a way that prevents recovery.

What “Securely Erased” Means in Law

UK GDPR does not define a specific technical standard for data deletion. The ICO’s guidance, however, is clear that standard deletion — emptying a recycle bin, removing files or formatting a drive — does not constitute secure erasure. Data deleted this way remains recoverable using widely available tools.

Secure erasure means one of two things:

  • Certified data wiping: software overwrites every sector of the storage medium, typically multiple times, to a recognised standard. NIST Special Publication 800-88 (Guidelines for Media Sanitisation) is widely accepted as the benchmark.
  • Physical destruction: the storage medium — the hard drive, SSD, USB stick or backup tape — is physically destroyed to the point of being unreadable. This is appropriate for media at the end of its serviceable life or where data sensitivity warrants it.

Both approaches, properly carried out and documented, satisfy the GDPR data disposal obligation. The choice between them depends on whether the device can be reused after wiping, and on the sensitivity of the data it held.

Which Data and Which Devices Need Secure Disposal?

Any storage medium that has held personal data requires secure disposal. This includes:

  • Hard drives and SSDs in desktop computers, laptops and servers
  • Mobile phones and tablets
  • USB drives, SD cards, memory sticks and backup tapes
  • Internal drives in printers, photocopiers and multi-function devices
  • Network-attached storage (NAS) and external hard drives
  • Cloud accounts and virtual machines (data must be deleted, not merely decommissioned)

Organisations often overlook printers and photocopiers. Many hold hard drives that store copies of every document scanned, copied or printed. A photocopier returned to a leasing company without its drive being cleared can expose months or years of business correspondence.

The Accountability Requirement: Documenting Disposal

UK GDPR Article 5(2) — the accountability principle — requires organisations to be able to demonstrate compliance with all other principles, including the disposal obligation. For GDPR data disposal, this means retaining documentary evidence that disposal took place.

The standard document for this purpose is a certificate of data destruction. A reputable ITAD (IT asset disposal) provider will issue a certificate for each device destroyed, specifying the asset, the destruction method, the date and the standards applied. These certificates are your audit trail.

The ICO may request this documentation during an investigation or audit. Organisations that cannot demonstrate that data was securely disposed of face greater regulatory exposure than those that have clear records.

Building a Compliant Data Disposal Process

A formal GDPR data disposal process should cover the following steps:

Step Action
1. Identify Audit end-of-life devices and data stores requiring disposal
2. Classify Determine the sensitivity of data held on each device
3. Select method Choose certified wiping (for reusable devices) or physical destruction
4. Execute Engage a certified ITAD provider; maintain chain of custody
5. Document Obtain and retain certificate of data destruction for each asset
6. Record Log the disposal in your Record of Processing Activities

Organisations should not rely on individual staff members to carry out ad hoc deletion. Disposal should be a documented, auditable process managed by a responsible person — typically the data protection officer, IT manager or equivalent.

Responding to Individuals’ Right to Erasure

UK GDPR Article 17 gives individuals the right to request erasure of their personal data in certain circumstances — for example, where it is no longer necessary for the purpose for which it was collected, or where they withdraw consent and there is no overriding legal basis to continue. This “right to be forgotten” applies to digital records, paper records and any device that holds personal data about that individual.

Where a valid erasure request is received, the organisation must act within one calendar month. The response must confirm that data has been erased — and again, the organisation must be able to demonstrate this.

Choosing a Responsible ITAD Partner

Not all IT recyclers carry out certified data destruction. Before engaging a provider, verify that they:

  • provide a written certificate of data destruction for each asset
  • use a recognised standard for data wiping or physical destruction
  • maintain a documented chain of custody from collection to destruction
  • can describe what happens to devices or components after destruction

For businesses in London, Recycle4Charity offers certified data destruction alongside WEEE-compliant recycling. Where devices can be securely wiped and still function, they are refurbished and given free to digitally-excluded Londoners — turning your compliance obligation into a direct social benefit.

Find out more about how our process works on our data destruction service page, and read our overview of what is data destruction for more on methods and standards.

To arrange GDPR-compliant data disposal for your organisation, contact Recycle4Charity.

Blog

Frequently asked questions

UK GDPR does not have a single article dedicated to disposal, but several principles and provisions together create a clear duty. The storage limitation principle (Article 5(1)(e)) requires erasing data that is no longer needed. The security principle (Article 5(1)(f)) requires that erasure be done securely. The accountability principle (Article 5(2)) requires that you can demonstrate both.

No. Standard deletion — including emptying the recycle bin or formatting a drive — leaves data recoverable using common software tools. GDPR requires that personal data be erased in a way that prevents recovery. This means certified data wiping (overwriting all sectors) or physical destruction of the storage medium.

A certificate of data destruction is a document issued by an ITAD provider confirming that data on specified assets has been destroyed, including the method and date. UK GDPR does not use this specific term, but the accountability principle (Article 5(2)) requires that you can demonstrate compliance with the disposal obligation. A certificate is the standard way to do this.

UK GDPR does not specify a fixed retention period for disposal records. As a general principle, retain these records for at least as long as your standard data retention periods, and longer if you operate in a regulated sector with extended record-keeping requirements. The records should be available to the ICO on request.

Yes. Data stored in cloud accounts and virtual machines is subject to the same GDPR disposal obligations as data on physical hardware. When a cloud account or service is decommissioned, you should confirm with the provider how data is deleted and retain evidence that deletion occurred.

Need secure IT disposal in London?

Certified data destruction and WEEE recycling — with refurbished devices going to people who need them.