Disposal records in the United States
When a customer asks a service provider to prove that a drive was disposed of properly, they are asking for a record — not a reassurance. This guide sets out what that record contains, and which sanitization standard a United States certificate should cite.
1. The standard a United States certificate cites
United States tenants configure their certificates to cite NIST SP 800-88, Guidelines for Media Sanitization, published by the National Institute of Standards and Technology. It is the reference most commonly named in American disposal requirements, and it is widely recognized by auditors and insurers.
NIST SP 800-88 describes three categories of sanitization, chosen according to how sensitive the data is and whether the media will leave the organization’s control:
- Clear — logical techniques that protect against recovery using ordinary system tools.
- Purge — techniques that render recovery infeasible using state-of-the-art laboratory methods.
- Destroy — physical destruction of the media, after which it can no longer be used for storage.
The practical consequence is the same as in any regime: the category actually applied has to be recorded against the individual drive. Custodyne records the sanitization method against each drive at the wipe stage, and the certificate quotes the standard named in the customer’s signed consent — never a default substituted afterwards.
2. What a defensible record contains
Regardless of which framework a customer operates under, the questions asked after the fact are consistent. A record that answers them contains:
Authorization, obtained before anything moves
A disposal approval signed by someone authorized to give it on the customer’s behalf, naming the media, the method, and the sanitization standard — captured before the item leaves the customer’s control, not reconstructed later.
One record per physical item
Each drive and each device is documented individually. Batching several items under one approval is the most common weakness in a paper process, because it prevents anyone from later proving what happened to a particular serial number.
Unbroken possession
Who took possession, when, and every transfer afterwards — collection, transport, intake, storage, and final disposition — each recorded at the time it happened rather than summarized at the end.
The method actually used, per drive
Not the method intended or usually used. Where a drive cannot be sanitized — because it is not functional — the record should say so and show that the item proceeded to physical destruction instead.
The correct disposition for each stream
Drives are sanitized and destroyed, and receive a Certificate of Destruction. Devices are recycled or returned to the customer, and receive a Certificate of Device Disposal. A device is never described as wiped, sanitized, or destroyed — conflating the two is the error most likely to undermine an otherwise sound record.
A certificate that can be checked
A certificate that carries a document hash and can be independently verified is materially stronger than a PDF that merely asserts a disposal took place.
Retention that outlives the relationship
The record needs to remain available for as long as the customer may need it, including after they stop being your customer. Custodyne’s default retention is seven years, configurable per tenant.
3. Frameworks your customers may operate under
The following are named so you know what your customers are likely to be thinking about when they ask how you dispose of media. Whether any of them applies — and what it requires — depends entirely on the organization, its sector, and its state. This is not a list of duties, and it is not exhaustive.
- HIPAA — applies to protected health information held by covered entities and their business associates, and is frequently the reason a healthcare customer asks detailed disposal questions.
- GLBA — the Gramm-Leach-Bliley Act, relevant to financial institutions and the safeguarding of customer information.
- FACTA and the associated disposal rules — concerned with the disposal of consumer report information.
- State law — data disposal and breach-notification statutes exist in every state and differ meaningfully between them; a customer operating in several states may be working to the strictest of them.
- Sector regulators and contractual obligations — in practice, a customer’s disposal expectations are frequently set by a regulator, an insurer, a certification scheme such as SOC 2, or a clause in their own customer contracts rather than by statute alone.
4. Questions worth taking to counsel
Rather than assuming, these are the questions that determine how your disposal process should be documented:
- Which state laws apply to us and to our customers, and does operating across state lines change what we must be able to produce?
- How long must a disposal record be retained, and who is responsible for it once the customer relationship ends?
- Do any of our contracts or customer audits commit us to a specific sanitization category under NIST SP 800-88, or to a specific form of certificate?
- What are we required to do, and to tell the customer, when a drive cannot be sanitized and proceeds directly to destruction?
5. How Custodyne produces this record
Custodyne captures the signed approval with the evidence of signing, tracks possession by scanning each item’s label at every transfer, records the sanitization method against each individual drive, and issues a hash-sealed certificate for every item — a Certificate of Destruction for a drive, a Certificate of Device Disposal for a device. See how it works →