For Chief Risk Officers
You have been told data disposal is covered. Here is what that assurance actually rests on.
Your CIO and your CISO are not wrong to report it as controlled. They followed policy and used a certified supplier. The gap is in what the paperwork is capable of proving, and nobody in the chain is asked to prove more than that.
Every supplier certificate we have examined records that a process ran. Not one warrants that the data is gone.
Every erasure licence we have examined, other than our own, disclaims or caps liability for the outcome. The certificate in your file is evidence of activity, not of destruction.
The risk on your register
What you are told, and what the certificate actually says
Disposal is handled by an accredited supplier. Every device comes back with a certificate. The risk is controlled.
The method that ran. Not whether it was the right method for that device, and not whether the data is gone. The licence behind it disclaims the outcome the certificate implies.
Those are not the same statement, and the difference is the whole of your exposure. What follows is why a correct, certified, fully accredited process can leave recoverable data on a device, and why no one downstream of you has accepted responsibility for it.
Why it fails
The verification checks the part of the drive that no longer holds the data
This is not negligence and it is not a bad supplier. It is how overwriting works on modern storage.
An overwrite can only reach the addresses the drive reports to the computer it is plugged into. That is the limit of what any erasure software can touch from outside the drive.
On flash storage the drive’s own controller has already moved copies of the data into remapped, spare and overprovisioned blocks. The host cannot address those blocks and cannot see them.
The overwrite fills the addresses it was given. The verification then reads those same addresses back, finds exactly what was just written, and reports success.
The report is accurate. It is accurate about the part of the drive that no longer holds the data. The copies the controller moved are untouched, and the device leaves with a certificate.
Nothing failed. No setting was wrong, no operator made a mistake and no supplier cut a corner. The process ran, the verification passed and the certificate is correct. The data is still there.
This is why NIST SP 800-88 Revision 2 directs that overwrite not be relied on for current flash media, and sends the choice of method to IEEE 2883, the standard written for the media itself.
The second failure
When the correct method is refused, the software falls back and certifies anyway
Even where the right device native command is selected, it is not always accepted. The drive can refuse it, or the command can fail to complete.
At that point production logic takes over. The software falls back to an overwrite, finishes the job, records the erasure as successful and issues the certificate. Nothing on the certificate distinguishes that device from one where the correct method ran and worked.
Erasure completed. Method recorded. Certificate issued. The device moves on and the asset register is closed.
The correct method was refused, an overwrite ran in its place, and no one was told. The evidence you hold cannot tell the two apart.
Who is carrying it
The assurance runs in a circle and stops with you
Nobody in that chain has accepted responsibility for whether the data is gone. The only party carrying a legal duty is the one at the start of it.
Asked for the text of the guarantee it had said it held, one central government department answered: “There is no such warranty or guarantee.” Department for Work and Pensions, FOI2026/25131
How common is this
1,036 requests to UK public bodies, and what came back
Between January and September 2026 the question was put to the UK public sector under the Freedom of Information Act, by a private individual rather than by a company. What evidence do you hold that the data on your end of life storage media was actually rendered irretrievable?
Those 248 are more than a third of the organisations that answered. Same regulator, same supplier market, same question put to them. So the question is no longer whether a certificate without a warranty can be defended in principle. It is why an organisation would keep relying on one when a third of its peers already do not.
“These records confirm that an erasure process has been completed successfully in accordance with the tool’s validation method, but they do not constitute a guarantee of irrecoverability for each specific device.” An NHS foundation trust, describing the assurance it relies on
“Your request has highlighted a gap in our Data Protection Accountability obligations for this processing.” Scottish Environment Protection Agency, FOISA response F0201023, which committed to drafting a DPIA in the answer itself
Before you take anyone’s word, including ours
Four questions to put to your own people
Put these to your CIO, your CISO and your disposal supplier, in writing. The answers tell you where you stand without involving us at all.
We answer all four in writing about our own engine, and we would expect you to require the same of anyone else you are considering, including your current supplier.
What it takes from you
Your supplier changes the tool. You do not change the supplier.
One instruction, and nothing else changes. You are not appointing us, moving a contract or running a competition, because you are not the one licensing anything. Your existing disposal supplier changes the erasure software it runs on your assets, and you get evidence that answers the question above.
The instruction
With effect from [date], data destruction on our assets is to be carried out using the DSS Smart Wipe Engine. DSS will ensure every successful destruction produces a device specific certificate, warranted as irrecoverable and backed by £10 million of professional indemnity insurance. Sent to your existing disposal supplier. That is the whole of it.
If your contract needs a variation to carry it, it is one paragraph, and we will give you the wording. Ask for it →
The supplier’s side
Why your supplier will be glad you asked
This does not land on your supplier as a complaint. It lands as a cheaper, faster tool and a stronger service to sell, with the contract kept.
Who stands behind it
Engine, warranty, liability, insurance
Do not take our word for it
Test it on your own devices
Have your supplier run 100 devices through its current tooling and keep the results. Then have them run the same 100 through ours, free of charge. Same drives, same bench, same operator. You compare the evidence side by side and keep both sets either way.