IT & Services / capability
Secure IT Asset Disposal (ITAD) and Data Erasure
A deleted file is not an erased disk, and an erased disk is not a destroyed one. NIST SP 800-88 governs the data. The E-Waste Rules take the metal.
The device leaves the building. The data on it is still your liability.
A deleted file is not an erased disk, an erased disk is not a destroyed one, and only one of those three produces something you can hand to a regulator. The gap between them is where most ITAD arrangements sit: collected by somebody, taken somewhere, and evidenced by an email.
Talk to SECCOM about reviewing your real disposal route, from your storeroom to the point of processing. Where devices go today, who holds them in between, and what evidence exists at each step.
What you get. A certificate of erasure or destruction against every serial number, a chain-of-custody record from your site to the point of processing, and a recycling receipt from a recycler authorised under India's e-waste rules. Media that cannot be sanitised is physically destroyed to a stated DIN 66399 protection class.
Where SECCOM stops. SECCOM works to external standards and names them: NIST SP 800-88 and DIN 66399. SECCOM does not hold a data-sanitisation accreditation and will not present its own procedure as one. Recycling authorisation belongs to the authorised recycler and its authorisation number appears in your pack.