A decommissioned laptop is a depreciated asset for accounting purposes. For the data protection officer, it is a filing cabinet full of personal data. Anyone who wants to dispose of data carriers must reconcile both perspectives. This article shows what obligations the GDPR creates in this context, how an erasure concept helps, and what evidence is really relevant in an audit.
The most important in a nutshell
- The GDPR does not prescribe a specific procedure, but requires that data be effectively deleted – and that you can prove this.
- If you hire a service provider, you usually need a contract for the processing of orders in accordance with Article 28 of the GDPR.
- A deletion concept determines which data carriers are deleted or destroyed when, how and by whom.
- Crucial in the audit: Proofs per serial number, a seamless transport chain, and documented disposal.
Why data media disposal is a data protection issue
Laptops, PCs, servers, smartphones, printers with built-in hard drives, USB sticks: All these devices store data, often even when they appear to be empty. If such a data carrier falls into the wrong hands, a data privacy breach is quickly imminent. Then there is a risk of reporting obligations, fines, and loss of customer trust.
The GDPR provides for fines of up to 20 million euros or 4 % % of global annual revenue for violations of its principles. The damage to reputation is often even more expensive when customer data appears on a used hard drive that has been sold.
Which GDPR obligations apply?
| Requirement | What they demand | What that means for old devices |
|---|---|---|
| Art. 5(1)(e) GDPR (storage limitation) | Only store data for as long as necessary | Discontinued devices are not allowed to „take“ any data. |
| Article 5(2) GDPR (Accountability) | Compliance must be verifiable | You need proof for every deletion or destruction. |
| Article 17 GDPR (Right to erasure) | Data must be deleted upon request or upon expiration of the purpose for which it was collected. | Deleted means that it cannot be restored. |
| Article 28 GDPR (Data processing) | Contracts with service providers that process data | Anyone who deletes or destroys your data is processing your data. |
| Article 32 GDPR (Security of Processing) | Appropriate technical and organizational measures | Safe transportation, access control, and verified procedures. |
Note: This overview does not replace legal advice. Consult your data protection officer or your data protection officer regarding your actions.
The extinguishing concept: order instead of individual case decisions
Many companies decide anew what happens to their old devices when they replace hardware. This takes time and leads to gaps. A deletion concept creates a fixed rule. The DIN 66398, the guideline for developing a deletion concept, and the CON.6 „Delete and Destroy“ component from the IT Basic Protection of the BSI often serve as a reference.
A practical extinguishing concept for hardware answers at least these questions:
- What data carriers are there? Hard drives, SSDs, smartphones, memory cards, tapes, printer memory.
- What protection is required? Normal, high or very high – based on the protection classes of DIN 66399.
- Which procedure? Certify deletion, physically destroy, or both.
- Who is responsible? Who releases equipment, who collects it, who verifies the proofs?
- How is it documented? What evidence is kept for how long?
- What happens in the case of exceptions? For example, with defective data carriers or devices from leasing contracts.
Key point: The GDPR does not ask whether you have deleted it. It asks whether you can prove it.
The four weaknesses in practice
1. The Collection Area
Old equipment ends up in the basement, the server room, or a storage room – often for months. Who has access there? Who knows how many devices are there? A list of serial numbers is the first step in the control process.
2. The transport
The most dangerous stretch lies between your building and the disposal point. Unlocked boxes, intermediate storage at freight forwarders or transshipments increase the risk. Direct trips with loaded cargo and tracking are safer.
3. The forgotten data carriers
The USB stick in the docking station, the second hard drive in the server, the memory card in the camera bag, the hard drive in the multifunctional printer—such media are all included in a mere count of devices.
4. The lack of proof
An invoice for „Disposal of 1 Grid Box IT“ is not proof of recovery. In an audit, you need a receipt for every data carrier detailing what happened to it.
The checklist for GDPR-compliant disposal
- Create inventory: Record devices by type, manufacturer and serial number. A simple table is sufficient for getting started.
- Service providers check: Certificates (for example ISO/IEC 27001, DIN 66399, waste management company), place of processing, use of subcontractors.
- Signing a contract for order processing: With a description of the technical and organizational measures.
- Organizing secure delivery: Plumbed containers, delivery protocol, direct transport.
- Delete or destroy: Certified deletion of functioning data carriers, destruction of defective ones in accordance with DIN 66399.
- Compare evidence: Do the serial numbers on the certificates match your inventory list?
- Documenting disposal: Anything that cannot be reused must be properly recycled and evidence submitted.
Disposing of waste does not automatically mean burying it.
Many companies equate „DSGVO-compliant disposal“ with „shredding everything.“ That is certainly possible, but it is expensive and not very sustainable. Functional devices that have been certified as deleted no longer contain data. They can be prepared and resold. The proceeds flow back to your company.
A sensible sequence therefore separates:
- Devices with market value: certified to be deleted, prepared for reuse, and re-marketed.
- Defective data carriers: destroy according to DIN 66399, with certificate.
- Devices without a market value: dispose of it properly according to the circular economy law, with a waste disposal certificate.
How Second IT fulfills its obligation to provide proof
Since 2011, Second IT in Schwäbisch Hall has been processing decommissioned IT equipment – currently around 1.8 million devices. For data protection officers, these points are particularly important:
- Own security logistics: Direct shipments without intermediate storage, GPS tracking, tamper-proof packaging, insured transport. For smaller quantities, there are tamper-proof PELI cases and trolleys.
- Recording by serial number: Each device and data carrier is registered. You can track the status in the customer portal.
- Certified deletion: With Blancco, including hidden areas, and with a digitally signed deletion certificate per device.
- Destruction in one's own home: According to DIN 66399, safety level H-5, video-monitored and with destruction certificate.
- Protected area: Access control with biometric systems, video surveillance, employees bound by data secrecy.
- Anonymization: Inventory stickers and other signs that identify your business will be removed.
- Certified management systems: ISO 9001, ISO 14001, ISO 45001 and ISO/IEC 27001, as well as a waste disposal company in accordance with § 56 KrWG.
More about it on the pages Data security, Waste disposal and Certificates. How to sell used laptops in a data protection-compliant manner can be read in our article. Selling used laptops and smartphones.
Special case: printers, copiers and network devices
When disposing of data media, most people think of laptops and servers. But other devices also store data:
- Multifunctional printer and copier They often have a built-in hard drive or flash memory on which scanned and printed documents are stored in between.
- Routers, Switches and Firewalls contains configurations, access data, and logs.
- Thin Clients and Point-of-Sale Systems have small internal storage that is often overlooked during inventory checks.
- Cameras, dictation devices and memory cards They often end up in bins instead of the waste disposal process.
Explicitly include these device classes in your disposal plan. For leased printers, it’s worth taking a look at the contract: Who is responsible for deleting the internal memory, and what proof is provided?
Frequently asked questions about data media disposal
How do I dispose of data carriers in accordance with the GDPR?
They ensure that the data cannot be recovered and document this for each data carrier. Functional data carriers are deleted using certified software, defective ones are destroyed in accordance with DIN 66399. If a service provider takes on this task, you enter into a contract for order processing. Keep the deletion and destruction certificates with serial numbers.
Do I need an AV contract for data destruction?
As a rule, yes. A service provider who deletes or destroys your data has access to personal data and processes them on your behalf. Therefore, a contract in accordance with Art. 28 GDPR is customary. It regulates, among other things, the technical and organizational measures and the handling of subcontractors. Please clarify details with your data protection officer.
What should be included in a hardware disposal plan?
A deletion plan describes which data carriers exist, what protection the data require, and which procedure is used. It defines responsibilities and regulates documentation. Special cases such as defective devices or lease returns should also be included. The DIN 66398 and the BSI component CON.6 serve as guidelines.
How long should I keep proof of destruction and removal?
There is no uniform legal deadline specifically for destruction certificates. Many companies follow their general retention periods and the requirements of their audits. It is important that you can quickly and fully provide the evidence during an audit. Define the deadline in your destruction plan.
Can I simply bring old company laptops to the recycling center?
This should be avoided. The data on the devices remain on them while you are on your way to recycling. Furthermore, you have no proof that they have been deleted. Commercial waste appliances are also subject to their own return and disposal regulations. A safer way is to use a certified service provider that deletes, recycles, and documents the process.
Disposal with complete traceability – from collection to the certificate.
Send us your list of devices. We will check what can be sold and create a quote within an average of 48 hours.