...

For authorities, municipal administrations and companies with public contracts, the decommissioning of IT is more than just a data protection issue. As soon as confidential data was stored on the devices, additional rules apply. The most common classification is VS-NfD. This article explains what VS-NfD means, what requirements typically apply when decommissioning hardware and how to identify a suitable service provider.

The most important in a nutshell

  • VS-NfD stands for „Confidential matter – For service use only“ and is the lowest of the four levels of confidentiality.
  • The procedures for handling confidential information are governed by the federal regulations or the rules of the individual states; for companies, the VS-NfD guidance document from the order is applicable.
  • Data media containing VS-NfD content must be deleted or destroyed in such a way that reconstruction is excluded – with proof.
  • Always vote on the procedure with your or your privacy officer.

What does VS-NfD mean?

Confidential information is information whose disclosure could harm the interests of the federal government or a state. The Security Inspection Act defines four levels of secrecy:

Level of secrecy Meaning (simplified)
VS – FOR SERVICE USE ONLY (VS-NfD) The knowledge obtained by unauthorized persons can be detrimental to the interests of the state.
VS – CONFIDENTIAL Knowledge can be harmful to the interests of the state.
SECRET Knowledge may endanger the security or interests of the state or cause serious harm to them.
STRONGLY SECRET Knowledge can endanger the state’s assets or vital interests.

VS-NfD is thus the lowest level – and the most common. In many administrations, situation maps, internal concepts, security documents, or parts of tender documents carry this marking. Accordingly, VS-NfD data is also frequently stored on departmental servers, file servers, and mobile devices.

Which rules apply?

For federal authorities, the sealing procedures instruction (VSA) regulates the handling of sealed documents. The states have their own regulations that are based on it. Companies that work with VS-NFD as part of a public contract usually receive a VS-NFD leaflet, which is considered part of the contract.

For IT, these basic principles typically result in the following:

  • Access only for authorized personnel: Anyone who processes or transports VS-NF must be competent and knowledgeable to do so.
  • Appropriate IT: Certain security requirements must be met for processing and transmission, for example when encrypting data.
  • Safe storage: Data carriers with VS-NFD must be protected from unauthorized access.
  • Secure deletion and destruction: When removing content from the public domain, it must be ensured that unauthorized individuals cannot reconstruct the content.

The specific requirements vary depending on the authority, country, and the assignment. Your internal rules and the decision of your data protection officers are decisive. This article does not replace an individual assessment in each case.

Key point: With VS-NfD, „deleted securely“ is not enough. It must be verifiable who handled which device when.

The critical points regarding the expulsion

Recording

Which devices have VS-NfD processed? Often it is not possible to cleanly separate these two processes. Therefore, many authorities proactively treat all the data carriers in an area as VS-NfD data carriers. The basis is a list of serial numbers for all devices and data carriers.

Transport

The route between the service point and the destruction site is particularly sensitive. Safe transport without reloading and intermediate storage, with the cargo securely secured, tracking and documented handover are essential.

Deletion or destruction

Functional data carriers can be deleted using verified methods, provided your specifications allow it. Defective data carriers or those for which your rules require physical destruction are destroyed. The standard for destruction is DIN 66399 with its protection classes and safety levels.

Proof

For each data carrier, a proof should be provided: serial number, method, date, result. These proofs are part of your documentation regarding the whereabouts of the sealed items.

Requirements for a service provider

If you are not performing the outsourcing yourself, a service provider should meet at least these requirements:

Requirement What you should pay attention to
Processing according to VS-NFD guidelines Explicit commitment and documented procedures
Acquiring land Access control, video surveillance, security zones
Compulsory staff Obligation to confidentiality of data, confidentiality agreements, training
Own logistics Direct travel, tracking, location, handover protocol
Destruction in one's own home According to DIN 66399, without transfer to third parties
Information security Certified according to ISO/IEC 27001
Evidence Certificate of destruction or disposal per serial number

This is how Second IT works with VS-NFD data carriers

Second IT works for companies and the public sector. For confidential matters at VS-NfD level, our policy is:

  • Processing according to VS-NFD guidelines: We process and destroy data carriers with the „For Service Use Only“ confidentiality level in accordance with the applicable guidelines.
  • Destruction in one's own home: According to DIN 66399, certified for safety level H-5, without transport to external locations, monitored 24/7 by video surveillance.
  • Protected location: Biometric access control, video surveillance, security zones with controlled access, and highly secure storage rooms before destruction.
  • Compulsory team: All employees are bound by the confidentiality of data and are regularly trained. Upon request, we can enter into individual confidentiality agreements.
  • Security logistics: Direct trips without intermediate storage, GPS monitoring, tamper-proof locking, insured transport.
  • Certified deletion: With Blancco, whose software has been certified and recommended by the BSI and NATO, among other organizations, according to the manufacturer.
  • Evidence: Digital signed erasure certificate or destruction certificate per serial number, with audit reports attached.
  • Certified information security: ISO/IEC 27001.

More about it on the pages Data secrecy, Data carrier destruction and Certificates.

Public authorities are also subject to procurement law. Therefore, formulate the safety requirements in the tender specifications: transport, location of destruction, safety level, documentation, and the personnel’s obligation.

Process of VS-NFD exclusion

  1. Voting: Together with your data protection officer, we determine which data carriers are to be deleted and which are to be destroyed.
  2. Inventory: They create a list of devices and data media with serial numbers.
  3. Contract: Order with a description of the security measures, if necessary including a contract for the processing of the order and a confidentiality agreement.
  4. Pick-up: Direct drive, locked, GPS-monitored, with delivery protocol.
  5. Recording: Registration of each data carrier by serial number in secure areas.
  6. Deletion or destruction: According to the agreed procedure.
  7. Evidence: Certificates per serial number for your documents.
  8. Recycling: Only when approved by you will deleted devices be prepared and resold. All your agency's markings will be removed beforehand.

Reusing despite sealed containers?

Many authorities destroy all data carriers for precautionary reasons. That is certainly the case, but not always necessary. If your requirements allow for a verified deletion, functional devices can be reused after the deletion. This saves budget and resources. A pragmatic solution: Destroy the data carriers; use devices without data carriers instead. Which variant is permissible is decided by your data protection officer or your data protection officer.

Which devices may be affected

In government agencies and public contractors, VS-NFD data is processed on completely different hardware. When considering a migration, you should check these device categories:

  • Workstation computers and laptops with local copies, status updates and email archives.
  • File servers, storage systems and backup tapes with large data sets.
  • Mobile phones and tablets with emails, calendars, and messenger conversations.
  • Multifunctional printer with internal storage for scanned documents.
  • External data carriers like USB sticks, external hard drives and memory cards.

Especially with mobile devices and printers, the assignment to VS-NFD is often unclear. In case of doubt, the stricter standard applies – namely, treating it as a VS-NFD data carrier with full proof.

Frequently asked questions about VS-NfD

What does VS-NfD mean?

VS-NfD is the abbreviation for „Confidential matter – For service use only“. It is the lowest of four levels of confidentiality in Germany. Information of this level may only be made available to persons who need it for their work duties. The confidentiality guidelines of the Federal Government or corresponding rules of the Länder apply to handling this information.

What regulations apply to the handling of VS-NfD?

Federal authorities are subject to the confidentiality regulations; the states have their own regulations. Companies usually receive a VS-NfD leaflet as part of the contract when awarding public contracts. These rules concern labeling, storage, disclosure, IT processing, and destruction. The contact persons are the privacy protection officers of your organization.

Should VS-NfD data carriers be deleted or must they be destroyed?

It depends on your requirements. In principle, unauthorized persons must not be able to reconstruct the contents. Depending on the regulations, this requires a verified deletion or physical destruction. Many authorities choose to destroy defective or particularly sensitive data media in accordance with DIN 66399.

Can an external service provider destroy VS-NFD data carriers?

Yes, if he meets the requirements of your specifications and you commission him accordingly. Be sure to have secure premises, assigned personnel, a seamless transport chain, and destruction in-house. It is also important to have proof for each serial number. Please clarify the commission in advance with your secret protection officers.

What happens to government smartphones during decommissioning?

Mobile devices are treated like other data carriers: they are recorded, deleted or destroyed and documented. Before that, they should be released from the device management and SIM and storage cards removed. Whether a verified deletion is sufficient or a destruction is necessary depends on your requirements. Second IT uses a certified deletion solution from Blancco for mobile devices.

Isolation of VS-NfD hardware – secure, documented, from a single source.

Send us your requirements and a list of devices. You will receive a quote within an average of 48 hours.

Send inquiry More about data secrecy

Blog News

Stay up to date with our latest blog posts.

Skip to content