Why Data Disposal Is a GDPR Obligation
Many UK businesses treat data disposal as a practical or logistical task — clearing out old equipment or deleting records to save storage space. UK GDPR frames it very differently. The storage limitation principle (Article 5(1)(e)) and the integrity and confidentiality principle (Article 5(1)(f)) together create a positive legal duty to erase data that is no longer needed, and to do so securely.
Failure to meet this duty is not just poor practice — it is a breach of UK GDPR, and the Information Commissioner’s Office (ICO) has enforcement powers that include fines of up to £17.5 million or 4% of global annual turnover, whichever is higher.
The Storage Limitation Principle
Article 5(1)(e) of UK GDPR requires that personal data be kept “in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.”
In practice, this means every category of personal data your organisation holds must have a defined retention period. Once that period expires, the data must be erased — not archived indefinitely, not moved to a “cold storage” folder and forgotten, but genuinely deleted. For digital data on hardware, deletion must be carried out in a way that prevents recovery.
What “Securely Erased” Means in Law
UK GDPR does not define a specific technical standard for data deletion. The ICO’s guidance, however, is clear that standard deletion — emptying a recycle bin, removing files or formatting a drive — does not constitute secure erasure. Data deleted this way remains recoverable using widely available tools.
Secure erasure means one of two things:
- Certified data wiping: software overwrites every sector of the storage medium, typically multiple times, to a recognised standard. NIST Special Publication 800-88 (Guidelines for Media Sanitisation) is widely accepted as the benchmark.
- Physical destruction: the storage medium — the hard drive, SSD, USB stick or backup tape — is physically destroyed to the point of being unreadable. This is appropriate for media at the end of its serviceable life or where data sensitivity warrants it.
Both approaches, properly carried out and documented, satisfy the GDPR data disposal obligation. The choice between them depends on whether the device can be reused after wiping, and on the sensitivity of the data it held.
Which Data and Which Devices Need Secure Disposal?
Any storage medium that has held personal data requires secure disposal. This includes:
- Hard drives and SSDs in desktop computers, laptops and servers
- Mobile phones and tablets
- USB drives, SD cards, memory sticks and backup tapes
- Internal drives in printers, photocopiers and multi-function devices
- Network-attached storage (NAS) and external hard drives
- Cloud accounts and virtual machines (data must be deleted, not merely decommissioned)
Organisations often overlook printers and photocopiers. Many hold hard drives that store copies of every document scanned, copied or printed. A photocopier returned to a leasing company without its drive being cleared can expose months or years of business correspondence.
The Accountability Requirement: Documenting Disposal
UK GDPR Article 5(2) — the accountability principle — requires organisations to be able to demonstrate compliance with all other principles, including the disposal obligation. For GDPR data disposal, this means retaining documentary evidence that disposal took place.
The standard document for this purpose is a certificate of data destruction. A reputable ITAD (IT asset disposal) provider will issue a certificate for each device destroyed, specifying the asset, the destruction method, the date and the standards applied. These certificates are your audit trail.
The ICO may request this documentation during an investigation or audit. Organisations that cannot demonstrate that data was securely disposed of face greater regulatory exposure than those that have clear records.
Building a Compliant Data Disposal Process
A formal GDPR data disposal process should cover the following steps:
| Step | Action |
|---|---|
| 1. Identify | Audit end-of-life devices and data stores requiring disposal |
| 2. Classify | Determine the sensitivity of data held on each device |
| 3. Select method | Choose certified wiping (for reusable devices) or physical destruction |
| 4. Execute | Engage a certified ITAD provider; maintain chain of custody |
| 5. Document | Obtain and retain certificate of data destruction for each asset |
| 6. Record | Log the disposal in your Record of Processing Activities |
Organisations should not rely on individual staff members to carry out ad hoc deletion. Disposal should be a documented, auditable process managed by a responsible person — typically the data protection officer, IT manager or equivalent.
Responding to Individuals’ Right to Erasure
UK GDPR Article 17 gives individuals the right to request erasure of their personal data in certain circumstances — for example, where it is no longer necessary for the purpose for which it was collected, or where they withdraw consent and there is no overriding legal basis to continue. This “right to be forgotten” applies to digital records, paper records and any device that holds personal data about that individual.
Where a valid erasure request is received, the organisation must act within one calendar month. The response must confirm that data has been erased — and again, the organisation must be able to demonstrate this.
Choosing a Responsible ITAD Partner
Not all IT recyclers carry out certified data destruction. Before engaging a provider, verify that they:
- provide a written certificate of data destruction for each asset
- use a recognised standard for data wiping or physical destruction
- maintain a documented chain of custody from collection to destruction
- can describe what happens to devices or components after destruction
For businesses in London, Recycle4Charity offers certified data destruction alongside WEEE-compliant recycling. Where devices can be securely wiped and still function, they are refurbished and given free to digitally-excluded Londoners — turning your compliance obligation into a direct social benefit.
Find out more about how our process works on our data destruction service page, and read our overview of what is data destruction for more on methods and standards.
To arrange GDPR-compliant data disposal for your organisation, contact Recycle4Charity.