Deleting and formatting both leave data recoverable with ordinary tools, which matters the moment hardware leaves your control. The right method depends entirely on the media — and in most cases the certificate listing serial numbers is the actual deliverable.
We read every drive back once it’s been overwritten — confirmation that nothing recoverable survives has to be in hand before any certificate leaves the lab.
Both leave the data recoverable with ordinary tools. If hardware is leaving your control — sold, returned at lease end, sent for disposal — the difference between deleted and destroyed is the difference between compliance and a breach.
Applying the wrong one is how organisations end up with a certificate and a problem.
In most cases the paperwork is the deliverable rather than the destruction itself.
Each item is recorded by make, model and serial number, with the method used, the date, and confirmation of verification where the media allowed it. That record is what satisfies an auditor, a client contract, or the ICO if the question ever arises — and it is why a drive that simply went in a skip is a problem even when nobody could realistically have read it.
Under UK GDPR the obligation is to dispose of personal data securely and to be able to demonstrate you did. A certificate listing serial numbers demonstrates it. An assurance that the IT contractor took the old machines away does not.
There are cases where paying for this is unnecessary and we would rather say so.
If BitLocker or FileVault was enabled and the machine is being reset properly, the encryption key is discarded and the data is already unreadable.
Redeployment to another user rarely needs certified destruction — a standard reimage is usually sufficient under most policies.
Not everything is personal data. Where the content genuinely does not matter, a straightforward wipe is fine.
Personal data, client records, financial or medical material, anything under a contractual obligation, and any drive that has failed — those need doing properly and documenting.
Priced per item with the documentation as standard rather than an extra.
Data destruction is quoted on volume and media type — a handful of drives is priced differently to a decommissioned rack. Certificates listing serial numbers, method and date are included as standard rather than charged for separately.
This is one of the three services outside no fix, no fee: the work is performed and documented regardless of outcome, because the outcome is the destruction. Collection can be arranged for larger volumes across Greater Manchester, or drop items at Peter House on Oxford Street.
No. Both leave data recoverable with ordinary software — deleting removes the index entry and a quick format replaces it, neither touching the data. If hardware is leaving your control, that gap is the difference between compliance and a breach.
Because wear levelling means the drive holds data in blocks outside the addressable range, so an overwrite cannot reliably reach everything. Cryptographic erase destroys the internal key instead, rendering every block unreadable at once.
It cannot be overwritten or erased, because it no longer responds to commands. Those are destroyed physically — the platters or flash packages themselves, not just the enclosure — and recorded by serial number.
Yes, as standard rather than as an extra. Each item is listed by make, model and serial number with the method and date, which is what an auditor or the ICO would expect to see.
No, and we will tell you when you don’t. A modern encrypted laptop reset properly has already discarded its key, and a machine being redeployed internally usually just needs reimaging. It matters for personal data, client records, contractual obligations and failed drives.
Quoted on volume and media type, with certificates included. Collection can be arranged for larger volumes across Greater Manchester.