White paper · For boards, Data Protection Officers and disposal operators
Data Destruction Is Binary
Data is either permanently and irretrievably destroyed, or it is not. UK GDPR does not frame destruction as an effort, it frames it as an outcome, and Article 5(2) asks a controller to demonstrate that the outcome was achieved rather than that a process was followed.
This is the full argument, set out end to end. Why an overwrite that passes its own verification can leave the data in place on flash storage. Why determining the correct method is necessary but not sufficient, and what a complete evidence loop additionally requires: a known state to test against, an empirical test of the result rather than a reading of the drive’s own status flag, two distinct gates that both fail closed, and evidence that can be re-checked later rather than taken on trust. Why a downstream warranty cannot repair an upstream disclaimer. And what a sufficient guarantee looks like, stated in three parts so that any supplier can be tested against it.
It is supplier agnostic and names no product, including ours. Sections 1 to 10 and 12 make the argument; Section 11 states our own position and is separated and labelled for that reason. The Freedom of Information evidence behind it is the public record of 684 classified responses from UK public bodies, and the regulator’s own correspondence is quoted verbatim with its case reference. Every source is listed at the back.
Read the white paper (PDF, 502 KB, opens in a new tab) →
Pack · For Data Protection Officers
Conducting a DPIA on End-of-Life Data Destruction
Most organisations hold a supplier certificate recording that a destruction process was followed. Article 5(2) UK GDPR asks for something else: the ability to demonstrate the outcome, that the personal data on a specific storage device was actually rendered irretrievable. Those are not the same thing, and the difference is where the accountability gap sits.
These two documents are written for a Data Protection Officer assessing whether their own organisation can demonstrate that outcome. The framework sets out the method. The annex supplies the technical material, the sector evidence, a way of reading your existing destruction certificates, and specification language you can hand to procurement.
Both are technology neutral and supplier agnostic. They name no product, including ours, and they hold physical destruction to exactly the same evidential test as software erasure. Neither is a DPIA and neither is legal advice: the DPIA remains the controller’s own document. Every source is listed at the back of each, and every one can be checked without asking us.
01
A Framework for Conducting a Data Protection Impact Assessment on End-of-Life Data Destruction
The method. Scope and statutory basis, the risks to assess, the eight elements of evidence the assessment looks for, the three assurance models found in current UK practice, and the two pathways available where the standard is not met.
Version 1.4 · September 2026 · 37 pages · PDF, 554 KB
Read the framework (PDF, 554 KB, opens in a new tab) →
02
Annex A: Reference Material
The working material. Why overwrite fails on flash storage and what does work; what a Freedom of Information programme across 684 UK public bodies establishes about current practice, and what it does not; four specimen destruction records analysed against the eight elements; and sample procurement specification language for each pathway.
Version 2.3 · September 2026 · 29 pages · PDF, 531 KB
Read the annex (PDF, 531 KB, opens in a new tab) →