IT & Services / capability
Secure IT Asset Disposal (ITAD) and Data Erasure
A deleted file is not an erased disk, and an erased disk is not a destroyed one. NIST SP 800-88 governs the data. The E-Waste Rules take the metal.
The device leaves the building. The data on it is still your liability.
A deleted file is not an erased disk, an erased disk is not a destroyed one, and only one of those three produces something you can hand to a regulator. The gap between them is where most ITAD arrangements sit: collected by somebody, taken somewhere, and evidenced by an email.
Where SECCOM stops. SECCOM works to external standards and names them: NIST SP 800-88 and DIN 66399. SECCOM does not hold a data-sanitisation accreditation and will not present its own procedure as one. The e-waste Extended Producer Responsibility (EPR) registration with CPCB is the recycler's, not SECCOM's, and its registration number appears in your handover pack.
Next step