Freedom of information request
Certification process for software-based data erasure
- Freedom of information request reference
- CAS-320977
- Request resolved
Request
My enquiry relates solely to the type of recorded assurance held by your organisation.
You note that system logs are available, that certificates of destruction may be issued, and that data drives are encrypted. A certificate or record confirming that an erasure process was applied demonstrates that a recognised method was used. What I am seeking to understand is whether your organisation holds any recorded evidence of the outcome, namely evidence that the data on a specific storage device is irrecoverable following erasure, rather than confirmation that the erasure process was executed.
With that distinction in mind, please confirm:
- Do the IT asset disposal certificates or related contractual terms held by your organisation constitute an explicit outcome based warranty or guarantee that the personal data on each specific storage device has been rendered irrecoverable as a final data state, or do they primarily confirm that a certified erasure process was followed?
- Beyond reliance on supplier accreditation, recognised standards including but not limited to ADISA certification, ISO accreditation, HMG IA standards, or confirmation that an erasure process was completed, does your organisation hold any recorded, device specific documentation evidencing independent verification, testing, or validation that the data on the particular storage media processed has been rendered irrecoverable in practice?
For clarity, this request relates specifically to recorded outcome evidence demonstrating irrecoverability of data on the individual storage device, not documentation confirming that an accredited or certified method was applied.
If no explicit outcome based warranty or device specific outcome evidence is held beyond certification, accreditation, or confirmation of process completion, please confirm accordingly.
I am not seeking technical configuration detail, only clarification of the recorded assurance basis relied upon when concluding irrecoverability of the final data state.
Outcome
Information provided.
Response
1. Do the IT asset disposal certificates or related contractual terms held by your organisation constitute an explicit outcome based warranty or guarantee that the personal data on each specific storage device has been rendered irrecoverable as a final data state, or do they primarily confirm that a certified erasure process was followed?
We are provided with documentation/ certificates as an outcome which is considered our warranty and/or guarantee.
2. Beyond reliance on supplier accreditation, recognised standards including but not limited to ADISA certification, ISO accreditation, HMG IA standards, or confirmation that an erasure process was completed, does your organisation hold any recorded, device specific documentation evidencing independent verification, testing, or validation that the data on the particular storage media processed has been rendered irrecoverable in practice?
Device information is registered internally, drives are encrypted as an organisational standard resulting in irrecoverable data from the on-set. No additional 3rd party verification/ validation beyond our supplier Blancco certificates/ documentation is pursued as our service providers are Cyber Essentials and Cyber Essentials Plus certified and are compliant with ISO/IEC 27001. All operations comply with ICO approved ADISA-8 Standards. NIST approved software 'Blancco' provides The National Archives with certificates ensuring that data is destroyed and complies with UK GDPR guidelines.