Data Safe Solutions / Research
Findings as at 22 May 2026

The Erasure Gap

One question was put to UK public bodies: what recorded evidence do you hold that the data on your disposed storage devices was actually destroyed? Of 684 substantive answers, 437 held no outcome evidence.

We publish this research because we built the answer to it. We are the only company we can find anywhere in the world that warrants the outcome of data destruction.

A new standard nobody has yet matched, backed by £10 million of professional indemnity insurance. Our commercial interest is declared in full at section 06.

01 / The question

The question that was asked


Between 2025 and May 2026, 1,036 Freedom of Information requests were issued to UK public bodies by a private individual. Each asked, in substance, four things:

  1. Where storage media are disposed of through a third party, do the certificates or contractual documents held constitute an explicit outcome-based warranty or guarantee of irrecoverability for each specific device?
  2. Where software-based erasure is undertaken internally, what recorded evidential assurance is relied upon to conclude that the final data state of the specific device is irrecoverable, as distinct from confirmation that an erasure process was executed?
  3. What device-specific verification, testing or independent validation of irrecoverability is held?
  4. What policy or contractual requirement mandates an outcome-based guarantee at individual device level?

The distinction running through all four is between evidence that a process ran and evidence that the data is gone. Nothing in the questions asks a body to defend itself, and nothing assumes a failure. It asks what is on file.

02 / What came back

Findings


1,036requests issued
684substantive responses received
437held no outcome warranty and no device-specific evidence

Roughly two thirds of the bodies that answered substantively confirmed that they hold no warranty that the data was rendered irretrievable, and no device-level evidence of the outcome. What they hold instead is a certificate that a process completed, and a supplier’s accreditations.

This is not a finding about negligence. In almost every case the body had followed its policy, used certified software or an accredited disposal provider, and retained the records that policy required. The gap is in what those records are capable of showing.

03 / In their words

What the responses say


These are named departments and regulators, quoted from their own responses. Every reference is the authority’s own and every response is published.

The contradiction, in one letter

Its certificates and contractual terms do, it said, constitute an explicit outcome-based warranty that the data on each specific device has been rendered irrecoverable.

Revenue Scotland answered the other way to every other body here. Then, in the next answer, in the same letter, it confirmed that it holds no recorded, device-specific documentation evidencing any verification, testing or validation that this is so. The warranty is asserted. The evidence for it does not exist.

Ministry of DefenceFOI2026/11404 · 11 June 2026
“Defence Digital does not hold a single, centrally recorded wording of an explicit outcome-based warranty or guarantee confirming that data has been rendered irrecoverable following software-based erasure.”

On 7 April 2026, under FOI2026/05904, the Department had answered “Yes” to holding exactly such a warranty. Asked for its wording, it applied the cost limit. Asked to reconcile the two, it amended the answer, stating that the “Yes” “arose from a misinterpretation of your questions.”

“The methods used are designed to only signal completion when that data has been removed successfully. Therefore, if the process indicates completion, that means the data has been erased.”

Asked in the same response for the wording of the warranty: “There is no such warranty or guarantee.” Asked what independent verification is held: “No independent verification is undertaken for sanitisation other than providing certificate of completion.”

That first sentence is the assumption the whole model rests on. Completion is treated as proof of the outcome, because the tool was designed to report completion only when the outcome was achieved. Nothing is tested. The conclusion is inherited from the software’s own design intent.

“Your request has highlighted a gap in our Data Protection Accountability obligations for this processing.”

The regulator confirmed it would now draft a Data Protection Impact Assessment to document the processing and meet Article 32 of the UK GDPR. In a separate response, F0200913, it had already confirmed that its policy, internal procedures and standard contractual terms “do not require an explicit outcome-based warranty or guarantee”.

“I can confirm that the destruction certificates do not constitute an explicit outcome-based warranty or guarantee that the personal data on each storage device has been rendered irrecoverable as a final state.”

The certificates relied on list ISO 9001, ISO 45001, ISO 27001, ISO 14001, ISO 20000-1 and an Environment Agency waste management licence.

NHS Property ServicesPSC-226248-Y4S3
“Our contractual terms do not contain an explicit guarantee that personal data has been rendered irrecoverable.”

Where bodies were asked what gave them confidence, the answer was repeatedly a list of supplier accreditations. One council cited ADISA Standard 8.0, ISO 14001, ISO 27001 and ISO 9001. Another cited ADISA asset recovery standard 8.0, Cyber Essentials and Cyber Essentials Plus. In each case the certificates are offered in place of evidence of the outcome, because no evidence of the outcome exists.

04 / Why it happens

A verified overwrite and a drive full of data are not in conflict


On a traditional hard drive an overwrite replaces data where it sits. A solid state or NVMe drive does not work that way. Its controller does not write in place. When new data arrives it is placed in a fresh physical location and the address is repointed, leaving the original data intact in the original flash cells, marked only as available for reuse. That reuse happens through wear levelling at some later point, which may be far off, or may never arrive while the drive has spare capacity.

So the overwrite completes. The verification reads the address back, finds the new pattern, and passes. A certificate is produced. But the verification only ever tested the addresses it wrote to, and it cannot see the original data still sitting in the cells the controller moved it out of, which can be read directly from the flash with readily available tools, bypassing the controller entirely.

This is why NCSC guidance, NIST SP 800-88 and IEEE 2883 all direct that flash media be sanitised by cryptographic erase or the drive’s own purge command rather than by overwriting. A device carrying a completed, verified, certified erasure record can be one on which the data was never destroyed, and on the face of the certificate it is indistinguishable from one that was.

05 / Why it matters in law

Accountability is a duty to demonstrate, not to assert


The gap is not only technical. Under the UK GDPR a controller carries obligations that a process certificate does not discharge.

ProvisionWhat it requires
Article 5(1)(e)Personal data kept in identifiable form no longer than necessary. Data still recoverable on a disposed device has not stopped being kept.
Article 5(1)(f)Integrity and confidentiality, including protection against unauthorised access. A device released with recoverable data is a confidentiality failure at the point of release.
Article 5(2)The controller is responsible for, and must be able to demonstrate compliance with, Article 5(1). A record that a process ran demonstrates the process, not the outcome.
Article 17Right to erasure. Erasure means the data is gone, not that an erasure routine was executed against it.
Article 24The controller must implement appropriate measures and be able to demonstrate that processing is performed in accordance with the Regulation.
Article 32(1)(d)A process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures. Effectiveness is measured at the outcome, not at completion.

Taken together, 5(2), 24 and 32(1)(d) place the burden on the controller to show the measure worked. That is the burden 437 of the bodies that answered cannot currently discharge for any individual device.

06 / Interest

Declaration


We are not a neutral party and we are not pretending to be

The requests were not made by Data Safe Solutions. They were made by a private individual, at his own cost and in his own time, and that individual is a co-founder of this company. We sell software that addresses the gap the research describes, so there is a direct commercial interest in the finding. We state it plainly, because research is worth what its method and its sources are worth, and both are set out above for anyone who wants to test them.

The requests were made under the Freedom of Information Act, which is applicant blind: a public authority answers the question regardless of who asks or why, which is precisely why one person with no budget and no commercial access was able to run a study of this size. Nothing in the responses is confidential, and any person or competitor can put the same questions to the same bodies and compare what they get back. We would encourage it.

The findings were submitted to the Information Commissioner’s Office and provided as briefing notes to the departments and agencies concerned before any of this was published commercially.

07 / Verification

Check it without asking us


Most of these requests were made through WhatDoTheyKnow, which publishes the request and the authority’s reply in full and permanently, and many bodies also publish the same response in their own disclosure log. Nothing here depends on us. The references below are the authorities’ own, and every one of them can be pulled up and read in full.

Ministry of Defence, Defence DigitalFOI2026/05904 (7 April 2026), FOI2026/07909 (28 April 2026), FOI2026/11404 (11 June 2026). The three together are the record of a Yes, a cost-limit refusal, and an amended No.
Department for Work and PensionsFOI2026/13404, FOI2026/20463, FOI2026/25131
Ministry of Justice260212112 (17 March 2026) and internal review 260713119 (26 August 2026)
Scottish Environment Protection AgencyF0200913 and F0201023, under the Freedom of Information (Scotland) Act 2002
Office for Nuclear RegulationFOI202602073 and FOI202603081
NHS Property ServicesPSC-226248-Y4S3

Those are seven of 684. Full response sets, the request wording as issued, and the correspondence with the Information Commissioner’s Office are available on request.