Disposal records in Canada
When a customer asks a service provider to prove that a drive was disposed of properly, they are asking for a record — not a reassurance. This guide sets out what that record contains, and which sanitization standard a Canadian certificate should cite.
1. The standard a Canadian certificate cites
Canadian tenants configure their certificates to cite CCCS ITSP.40.006, IT Media Sanitization, published by the Canadian Centre for Cyber Security. It is the current Government of Canada guidance on sanitizing IT media, and it supersedes the legacy CSEC ITSG-06, which now appears only as a superseded reference.
The guidance distinguishes between sanitization approaches according to how sensitive the data is and what will happen to the media afterwards — whether it stays in the organization, leaves it, or is destroyed. The practical consequence for a disposal workflow is that the method actually used has to be recorded against the individual drive, rather than asserted once for a batch.
Custodyne records the sanitization method against each drive at the wipe stage, and the certificate quotes the standard named in the customer’s signed consent — never a default substituted afterwards.
2. What a defensible record contains
Regardless of which framework a customer operates under, the questions asked after the fact are consistent. A record that answers them contains:
Authorization, obtained before anything moves
A disposal approval signed by someone authorized to give it on the customer’s behalf, naming the media, the method, and the sanitization standard — captured before the item leaves the customer’s control, not reconstructed later.
One record per physical item
Each drive and each device is documented individually. Batching several items under one approval is the most common weakness in a paper process, because it prevents anyone from later proving what happened to a particular serial number.
Unbroken possession
Who took possession, when, and every transfer afterwards — collection, transport, intake, storage, and final disposition — each recorded at the time it happened rather than summarized at the end.
The method actually used, per drive
Not the method intended or usually used. Where a drive cannot be sanitized — because it is not functional — the record should say so and show that the item proceeded to physical destruction instead.
The correct disposition for each stream
Drives are sanitized and destroyed, and receive a Certificate of Destruction. Devices are recycled or returned to the customer, and receive a Certificate of Device Disposal. A device is never described as wiped, sanitized, or destroyed — conflating the two is the error most likely to undermine an otherwise sound record.
A certificate that can be checked
A certificate that carries a document hash and can be independently verified is materially stronger than a PDF that merely asserts a disposal took place.
Retention that outlives the relationship
The record needs to remain available for as long as the customer may need it, including after they stop being your customer. Custodyne’s default retention is seven years, configurable per tenant.
3. Frameworks your customers may operate under
The following are named so you know what your customers are likely to be thinking about when they ask how you dispose of media. Whether any of them applies — and what it requires — depends entirely on the organization, its sector, and its jurisdiction. This is not a list of duties, and it is not exhaustive.
- PIPEDA — the federal Personal Information Protection and Electronic Documents Act, which applies to personal information handled in the course of commercial activity in Canada.
- Provincial private-sector privacy legislation — British Columbia, Alberta, and Quebec each have private-sector privacy legislation that has been recognized as substantially similar to the federal regime, and that may apply in place of it.
- Public-sector and health-sector legislation — separate statutes apply to public bodies and to health information, and these differ by province.
- Sector regulators and contractual obligations — in practice, a customer’s disposal expectations are frequently set by a regulator, an insurer, a certification scheme, or a clause in their own customer contracts rather than by privacy legislation alone.
4. Questions worth taking to counsel
Rather than assuming, these are the questions that determine how your disposal process should be documented:
- Which privacy legislation applies to our customers, and does that change what we must be able to produce?
- How long must a disposal record be retained, and who is responsible for it once the customer relationship ends?
- Do any of our contracts commit us to a specific sanitization standard or a specific form of certificate?
- What are we required to do, and to tell the customer, when a drive cannot be sanitized and proceeds directly to destruction?
5. How Custodyne produces this record
Custodyne captures the signed approval with the evidence of signing, tracks possession by scanning each item’s label at every transfer, records the sanitization method against each individual drive, and issues a hash-sealed certificate for every item — a Certificate of Destruction for a drive, a Certificate of Device Disposal for a device. See how it works →