
Pressing delete does not remove data. It only removes the signpost to it, and free recovery software can often bring the files back.
That is why data erasure standards exist. They set out how to remove data so it cannot be recovered, and how to prove you did it. When an auditor, a client or the ICO asks what happened to your old laptops, a named standard and a certificate are the answers they expect.
The short answer
- NIST SP 800-88 Revision 2 (September 2025) is the most quoted reference for wiping data. Revision 1 is withdrawn.
- IEEE 2883 sets out the wiping methods for each type of storage.
- NCSC guidance is the current UK government reference. The old HMG IS5 standard is no longer maintained.
- BS EN 15713:2023 covers physical destruction, not erasure.
- Whatever the method, you need a record. Total Shred provides a certificate of destruction with every job.
What is a Data Erasure Standard?
A data erasure standard is a published rulebook for removing data from storage. A good one covers:
- The method for each type of media
- The check that proves the method worked
- The record of what was done, when and by whom
Erasure keeps the device usable. That is its advantage over shredding, and its risk. If the wipe fails, the data is still on a working drive.
Why Deleting a File is not Digital Data Destruction
- Deleting removes the file from the index. The data stays on the disk.
- Formatting builds a new, empty index. Most old data is still underneath.
- Factory reset results vary by make and model.
Real digital data destruction means the data cannot be recovered with any reasonable tool. That takes a verified wipe, a firmware-level sanitise, or physical destruction. See our guide to hard drive shredding vs wiping.
The Data Erasure Standards That Matter in the UK
NIST SP 800-88 Revision 2
- Published on 26 September 2025. Revision 1 from 2014 was withdrawn the same day.
- Groups methods into three levels: Clear, Purge and Destroy.
- Focuses on running a sanitisation programme, with policies, roles and records.
- If a contract or policy still says “Rev 1”, it needs updating.
IEEE 2883
- The technical standard for sanitising hard drives, SSDs and flash storage.
- NIST now points to it for device-by-device methods.
NCSC guidance and HMG IS5
- The NCSC says data should be sanitised before any device leaves your control.
- The original HMG IS5 document is no longer maintained. If a provider quotes “IS5”, ask what process sits behind it.
ISO/IEC 27001:2022
- Control 7.14 covers secure disposal or reuse of equipment.
- Control 8.10 covers information deletion.
- A Total Shred certificate of destruction gives your auditor the record for every job.
Erasure Standards vs Destruction Standards
- Erasure standards (NIST 800-88, IEEE 2883, NCSC) cover removing data while the device survives.
- Destruction standards cover destroying the media. BS EN 15713:2023 sets out how secure destruction services must work, and states that erasure is outside its scope. ISO/IEC 21964 sets shred sizes.
Total Shred follows BS EN 15713 for secure destruction, from staff vetting to the final shred. For shred sizes by security level, see our guide to ISO 27001 hard drive destruction.
Matching The Method To The Media
- Hard drives (HDDs): a verified wipe for healthy drives being reused. Shred failed drives or sensitive data. Total Shred shreds hard drives on-site or at our facility.
- SSDs and USB devices: normal overwriting is not reliable, so use a built-in sanitise command or destroy the device. Total Shred destroys SSDs and USB devices.
- Backup tapes: degauss or shred. Total Shred destroys backup tapes.
- Phones and tablets: devices that will not power on cannot be wiped. Total Shred collects them through our IT disposal service.
- Servers and RAID drives: every drive needs a record, including old spares. Total Shred destroys servers and RAID drives with a full audit trail.
Sensitive Data Destruction: Choosing The Right Level
Sensitive data destruction should match the harm a leak would cause.
- Routine business data: a verified wipe is usually enough.
- Personal data: a verified wipe with full records, or physical destruction.
- Health, financial and legal records: physical destruction, with a certificate for every batch.
- Failed or damaged drives: always destroy. You cannot prove a wipe on a drive that does not respond.
What UK GDPR Expects
UK GDPR does not name a data erasure standard. It sets outcomes and leaves the method to you.
- Article 5: do not keep personal data longer than needed, and keep it secure.
- Article 28: only use processors, including disposal companies, that give sufficient guarantees about security.
- Article 32: use security measures that fit the level of risk.
- Fines can reach £17.5 million or 4% of annual worldwide turnover, set by section 157 of the Data Protection Act 2018.
Read the full UK GDPR or the ICO’s UK GDPR guidance. Total Shred’s processes are GDPR compliant.
How Total Shred Handles Confidential Data Destruction
Total Shred provides confidential data destruction for businesses, councils and NHS trusts across the UK.
- Certified data wipe and destruction through our IT equipment disposal service
- Hard drive and media destruction for HDDs, SSDs, USB devices, backup tapes and servers
- On-site shredding, where you can watch your drives destroyed
- Off-site destruction, with devices collected in sealed, tamper-proof containers
- A full audit trail and certificate of destruction with every job
- Accreditations including ISO 9001, ISO 14001, Cyber Essentials and BSIA membership
Frequently asked questions
What are data erasure standards?
Data erasure standards are published rules for removing data from storage so it cannot be recovered. The most widely used are NIST SP 800-88 Revision 2 and IEEE 2883, alongside NCSC guidance in the UK.
Is HMG IS5 still valid in the UK?
The original HMG IS5 document is no longer maintained. NCSC guidance is now the UK reference, so ask any provider quoting “IS5” what process they actually follow.
Can an SSD be wiped securely?
Not with standard overwriting software. SSDs need a built-in sanitise command or cryptographic erase. For faulty SSDs or sensitive data, physical destruction is safer, and Total Shred destroys SSDs.
What is standardized secure data destruction?
Standardized secure data destruction means following a recognised, published standard instead of an in-house method. For erasure that means NIST 800-88 or IEEE 2883. For shredding it means BS EN 15713.
Is confidential data destruction a legal requirement?
UK GDPR requires personal data to be kept secure and not held longer than needed, including when you dispose of it. Total Shred provides a certificate of destruction with every job, so you have the proof.
