
There’s a moment that plays out in schools, engineering firms, architectural practices, and offices across Wiltshire with predictable regularity: a hardware refresh happens, a stack of old laptops or desktops ends up in a corner of the building, and somebody eventually has to decide what to do with them.
The instinct, understandably, is to treat this as a logistics problem: get the old kit out of the way. But for any organisation that has held personal data on that hardware, it’s a compliance problem first, and a logistics problem second.
Deleting a File Is Not the Same as Destroying It
It’s worth being precise about this, because the confusion causes real harm. Deleting a file, or running a factory reset on a device, does not remove the underlying data. It removes the pointer that tells the operating system where to find it. The data itself remains on the drive until it’s overwritten by something else, which, on a drive with free space, can take a very long time. Free, widely available recovery software can pull “deleted” files back from a formatted drive in a matter of minutes.
For a school, that might mean pupil records or safeguarding notes. For an engineering firm or architectural practice, it might mean staff files, client correspondence, or commercially sensitive project data. Either way, the organisation that held the data carries the legal responsibility for what happens to it, including after the device has left the building.
What UK GDPR Actually Requires
The UK GDPR requires organisations to put “appropriate technical and organisational measures” in place to protect personal data throughout its lifecycle, and the ICO has been explicit that this obligation extends to disposal. A standard format does not meet the bar. What’s required is destruction that renders the data permanently unrecoverable, along with documented evidence that it happened.
That evidence takes the form of a certificate of data destruction a document that records, device by device, what was destroyed, how, and when. Without it, an organisation has no way of demonstrating compliance if it’s ever asked to. This aligns directly with strict GDPR Compliant Data Disposal Wiltshire standards.
What a Certificate Should Actually Contain
Not every certificate offered in this market is worth much. A certificate that would actually hold up under an ICO audit, a governor’s review, or a client’s due diligence check should list, for each device processed:
- Make, model, and serial number
- Whether the data was destroyed by wiping or by physical destruction
- The date it was processed
A single generic statement covering an entire batch of hardware doesn’t meet this standard and if your organisation is currently receiving one, it’s worth asking your provider for something more specific.
Two Standards Worth Knowing
For any device that can still be powered on, the recognised method of secure destruction is NIST 800-88 Compliant Data Wiping a process that overwrites every addressable sector of the drive, rather than just the parts visible to the operating system, to a level that makes recovery impossible using any known technique.
For devices that are physically damaged or can’t be powered on, physical destruction of the storage media is used instead. Either route produces the same outcome: the data is irrecoverably gone, and it’s documented.
Not Just a Schools Issue
Because pupil and safeguarding data carries such obvious sensitivity, it’s easy to assume this is primarily a schools problem. It isn’t. Any Wiltshire business that holds staff or client data which is most of them has exactly the same legal obligation when hardware reaches end of life. An engineering firm decommissioning a server, an architectural practice replacing office desktops, or a general office clearing out old laptops all carry the same responsibility as a school clearing out a computer suite.
Getting This Right Doesn’t Need to Be Complicated
The practical answer is straightforward: use a provider that applies NIST 800-88 compliant data wiping or certified physical destruction as standard, and issues an itemised, serialised certificate of data destruction for every device processed.
EcoTech IT provides exactly this service for schools, multi-academy trusts, and businesses across Wiltshire and the wider South West: certified data destruction, GDPR compliant documentation, and a straightforward, scheduled collection process.
If your organisation is currently disposing of old IT equipment without a proper certificate of data destruction to show for it, that’s worth reviewing before the next hardware refresh not after a query lands from the ICO.