Data wiping services exist to close the gap between what most people think “deleted” means and what deletion actually does to data on a storage device. When a file is deleted, the operating system marks its space as available and removes the pointer to it. The data itself remains on the drive, intact and recoverable, until new data physically overwrites those sectors. On a busy office laptop, that might happen quickly. On a server drive removed from service, it may never happen at all. Professional data wiping replaces this uncertainty with certified, documented destruction.

The Problem with Standard Deletion

Most organisations rely on operating system-level operations to clean devices before disposal: emptying the recycle bin, running a factory reset, or using the built-in drive wipe utility. These operations are adequate for casual privacy between trusted users. They are not adequate for devices leaving an organisation that has handled personal data, financial records, client information, or commercially sensitive material.

Recovery tools that cost nothing and require no technical expertise can retrieve files from drives that have been through factory resets. Forensic tools used by investigators can recover data from drives that have been formatted multiple times. The practical consequence is that any device retired without certified data wiping carries recoverable data that someone with modest technical means could access.

What Certified Data Wiping Involves

Data wiping services provided by a professional ITAD company use methods defined under recognised standards – principally NIST Special Publication 800-88 – that are specifically designed to defeat recovery. For traditional hard drives, overwrite passes replace all stored data with meaningless values across every sector. For solid-state drives, the process accounts for the different way SSDs manage data at the hardware level, using drive-specific commands that address the full storage capacity including remapped sectors.

The process generates a destruction certificate for each device. This certificate records the drive’s serial number, the specific method applied, the date and operator, and confirmation of successful completion. For organisations in regulated industries, this per-device record is the evidence that satisfies a data protection audit or regulatory inquiry.

Devices that cannot be wiped due to hardware failure or physical damage bypass software methods and go directly to physical destruction – shredding or degaussing – with separate documentation generated for each.

PDPA Obligations and What They Mean in Practice

Singapore’s Personal Data Protection Act places a direct obligation on organisations to destroy personal data that is no longer needed for the purpose for which it was collected. This obligation applies to data on physical storage media and survives the decision to retire a device. The PDPC has acted on cases where retired equipment left an organisation with data intact, treating the resulting exposure as a PDPA breach.

Organisations can review PDPC guidelines on data protection obligations to confirm current requirements. As former Prime Minister Lee Hsien Loong has noted, “Trust is earned by doing the right thing even when no one is watching.” For data disposal, doing the right thing means certified destruction with documented proof, not informal processes that are assumed to work.

Beyond Laptops and Desktops

The data wiping requirement extends across the full inventory of devices an organisation retires.

Servers contain drives that may hold years of database backups, application data, and transaction logs. Backup tapes archive sensitive data in compressed format and require treatment appropriate to tape media. Photocopier and multifunction printer drives store images of every document processed through the machine, an often-overlooked category with real exposure potential. Smartphones and tablets hold email, contacts, calendar data, and application caches that simple factory resets may not fully clear. USB drives and portable storage devices frequently contain copies of sensitive files that were never formally inventoried.

A complete data wiping programme covers all of these categories, not just the devices that appear obviously sensitive.

Choosing Between Wiping and Physical Destruction

Not every situation calls for software wiping. The right choice depends on whether the device will be remarketed after treatment and what level of assurance the organisation’s security policy or data classification requires.

Software wiping to NIST 800-88 standards is the appropriate method for devices going to resale, it destroys the data while preserving the device for further use. Physical destruction is appropriate for devices that are damaged, non-functional, or subject to a security policy that requires physical elimination of the storage medium.

TD ITAD provides data wiping services covering both approaches, with per-device documentation for every device processed. Their service covers the full range of storage media types used in business environments, and their process is designed to produce the documentation trail that regulatory compliance in Singapore requires.

Building Data Wiping Into the Disposal Process

For organisations retiring equipment on any regular basis, the most effective approach is to treat certified data wiping as a mandatory step in the decommissioning workflow rather than an optional add-on. Devices should not move from decommissioned status to exit the building without passing through a certified data wiping service. That single procedural commitment closes the data disposal gap that leaves organisations exposed.

Author