Media and device disposal and reuse procedure
October 1, 2026
Purpose and scope
This procedure protects company and customer information when devices or storage media are reassigned, reused, sold, donated, returned, recycled, or destroyed. It supports our Information security program.
It applies to company-controlled laptops, computers, phones, hard drives, solid-state drives (SSDs), USB drives, memory cards, backup media, and other equipment that stores information, including printers and network devices. Confidential paper records must also be securely destroyed when no longer needed.
For personally owned devices used for work, the security coordinator agrees with the owner how to remove company information and access without unnecessarily deleting personal information. Customer-owned and leased equipment must be handled according to the owner’s authorization and applicable agreements.
Responsibilities
The security coordinator or management approves disposal or reassignment and any required retention of information. A designated technical person or approved service provider performs the erasure or destruction, checks the result, and records completion. One person may perform more than one role.
Staff must not sell, discard, donate, or hand over equipment containing company or customer information without following this procedure.
Procedure
Step 1: Identify and authorize
Record the device or media identifier, such as its serial number or asset tag, and the intended destination. Identify the information it may contain and obtain approval from the coordinator or management. If the contents are unknown, treat the media as containing confidential information until assessed.
Keep equipment awaiting processing in a secure location with access limited to authorized people.
Step 2: Preserve required information
Check whether information must be retained for business, customer, contractual, or legal reasons, including any instruction to preserve records. Transfer required information to approved storage and check that it can be accessed before erasing the original. Do not erase information that is subject to a preservation requirement.
Step 3: Select and perform secure erasure or destruction
The technical person selects a method appropriate to the media type, information sensitivity, and destination, using current manufacturer instructions and relevant media-sanitization guidance. Sanitization means making the stored information infeasible to recover at the required level of protection.
| Situation | Required approach |
|---|---|
| Reuse within the organization | Use a supported whole-device sanitization method appropriate to the information and the new user’s access. Clearing may be suitable for lower-risk internal reuse; use a stronger purge method where the risk warrants it. |
| Sale, donation, return, or other transfer outside organizational control | Purge the media using a supported method intended to resist advanced recovery, or destroy the storage media. If neither is possible, retain it securely and resolve the issue before release. |
| Failed, damaged, or unsupported storage | If successful sanitization cannot be verified, arrange destruction of the storage components through an approved provider. Do not place them in ordinary waste. |
| Confidential paper or non-reusable physical media | Use suitable shredding or an approved secure destruction service so the information cannot reasonably be reconstructed. |
Deleting files, emptying the recycle bin, quick formatting, or reinstalling the operating system alone is not sufficient. Do not assume a factory reset sanitizes every device: confirm what the manufacturer’s process does for that model.
For SSDs and other flash storage, do not rely on ordinary file overwriting, which may miss storage areas. Use an appropriate supported sanitization function. Cryptographic erasure is acceptable only when the technical person confirms that the target data was properly encrypted and that the necessary encryption keys, including relevant recovery copies, are securely eliminated. Choose another method if those conditions cannot be confirmed.
Remove saved credentials and organizational access as appropriate, including device registrations, certificates, and active sessions. Revoke or rotate credentials if exposure is suspected. Reused devices must be securely configured and updated before reassignment.
Step 4: Verify before release
Check the tool’s completion status and errors, confirm that the selected method covered the intended storage, and perform the checks recommended for that method. An empty file listing alone does not prove successful sanitization.
The technical person records whether the result is acceptable. If the process fails or the result is uncertain, keep the media secure and repeat with a suitable method or arrange destruction. Release for reuse or disposal only after a satisfactory result is recorded.
When using a destruction provider, track the items handed over and obtain a completion record or certificate identifying the media or batch and the destruction performed. The coordinator checks that it accounts for the items transferred. Use an appropriate electronics recycler for the remaining equipment.
Step 5: Record completion
Keep a simple internal ticket or spreadsheet entry containing:
- Device or media identifier and intended destination.
- Authorization and confirmation that retention needs were checked.
- Date, method, and tool or provider used.
- Person who performed the work and the verification result.
- Final disposition and any supporting completion record or certificate.
Retain these records for at least one year, or longer where an applicable agreement or retention requirement requires it. Do not include passwords, encryption keys, or copies of the erased information in the record.
Provider-managed storage
For hosted services where we cannot directly sanitize physical media, the coordinator reviews the provider’s deletion, reuse, and disposal practices and records the applicable agreement or supporting documentation. When a service ends, request deletion of company data and available confirmation, accounting for agreed backup-retention periods and required records. Deleting a user account alone must not be assumed to delete all stored data.
Problems and review
Report missing equipment, accidental release, or suspected exposure to the coordinator or management promptly and follow the incident-response process in the information security program. If this procedure cannot be completed, keep the affected media secure while management determines a suitable solution; approval alone does not make unsanitized media safe to release.
Review this procedure at least annually and when equipment, disposal methods, or applicable requirements change.
Reference
NIST SP 800-88 Revision 2: Guidelines for Media Sanitization provides guidance for selecting and managing sanitization methods. This procedure does not claim independent certification of our practices.