A factory reset on an SSD is not sanitisation. Wear levelling means some of your data is still there.
Published guidance separates Clear, Purge and Destroy, and the decision is based on the confidentiality of the information rather than the type of media. Most UAE disposal processes pick a technique first and never verify the result.

- 3 categoriesClear, Purge and Destroy
- 10 percentMinimum sampling coverage when verifying
- 20 percentMedia requiring secondary verification
- ConfidentialityWhat the decision is based on, not media type
Most disposal processes rest on beliefs that the published guidance contradicts.
None of these are obscure. They are simply not checked, because disposal is usually somebody else task and nobody asks how it is done.
- That a factory reset sanitises a solid state drive. Flash devices may contain spare cells and perform wear levelling, which makes it infeasible for a user to sanitise all previous data through the standard read and write interface the reset uses.
- That physical damage means destroyed. Bending, cutting and improvised methods may only damage the media, since portions can remain undamaged and therefore accessible using advanced laboratory techniques. Destruction has a defined standard and a visual inspection is not it.
- That degaussing handles everything. It purges legacy magnetic devices when strength is matched to coercivity, and should never be solely relied upon for flash based storage or magnetic devices that also contain non volatile non magnetic storage.
- That a supplier certificate is verification. A certificate records that an action was claimed. Verification is a separate step with published sampling expectations, and where possible it should be performed by personnel who were not part of the original sanitisation.
Eight things a disposal process has to get right.
Three categories, not one
Clear applies logical techniques against simple non invasive recovery. Purge applies physical or logical techniques that render recovery infeasible using state of the art laboratory techniques. Destroy does the same and leaves the media unusable for storage.
The decision follows the data, not the device
The decision process is based on the confidentiality of the information, not the type of media. Once the organisation decides what type of sanitisation is best, the media type then influences which technique achieves that goal.
Overwriting fails on flash storage
Flash memory based devices may contain spare cells and perform wear levelling, making it infeasible for a user to sanitise all previous data by overwriting. Overwriting also cannot be used on media that are damaged or not rewriteable.
Cryptographic erase is fast and needs verifying
It sanitises the target data encryption key, leaving only ciphertext on the media. Where verification cannot be performed, organisations should use an alternative method that can be verified, or use it in combination with one that can.
Verification is not optional
Two types should be considered: verification every time sanitisation is applied where practical, and representative sampling on a subset. Where possible the sampling should be executed by personnel who were not part of the original sanitisation action.
Sampling has published coverage targets
Pseudorandom locations selected each time the tool is applied, with coverage reaching at least ten percent of the media once all subsections have had two samples. Secondary verification covers at least twenty percent of items using a tool from a separate developer.
Degaussing has real limits
It purges a legacy magnetic device when the degausser strength is carefully matched to the media coercivity. It should never be solely relied upon for flash based storage or for magnetic devices that also contain non volatile non magnetic storage.
The activity has to be documented
The published guidance includes a sample certificate of sanitisation form for documenting sanitisation activities. Without a record tying a specific device to a specific action, there is nothing to show an auditor or a regulator after the fact.
Clear, Purge and Destroy, and what each actually achieves.
| Category | What it achieves | When it is chosen | |
|---|---|---|---|
| Clear | Protects against simple non invasive recovery | Lower confidentiality, media staying in the organisation | |
| Purge | Recovery infeasible with laboratory techniques | Higher confidentiality, media being reused or sold | |
| Destroy | Recovery infeasible and media unusable afterwards | Highest confidentiality, or where Clear and Purge fail | |
| Cryptographic erase | Sanitises the key, leaving only ciphertext | Fast, where verification is achievable | |
| Overwriting | A Clear technique using read and write commands | Not for damaged, non rewriteable or flash media | |
| Degaussing | Purges legacy magnetic media when matched to coercivity | Never alone for flash or hybrid devices | |
| Shredding and disintegration | Destruction, when applied to the appropriate media | Where reuse is not intended | |
| Manufacturer reset on network devices | Clear for routers and switches | Returning to factory default settings | |
| Paper cross cut shredding | Particles of 1 mm by 5 mm or smaller | Destruction of paper records | |
| Paper disintegration | Disintegrator with a 2.4 mm security screen | An alternative to cross cut shredding |
Four things that turn disposal into a control.
We start from the information, not the hardware
The decision process is based on the confidentiality of the information, not the type of media. Once the required category is decided, media type determines the technique, which is the reverse of how most disposal processes are actually designed.
We treat flash storage as its own problem
Spare cells and wear levelling make overwriting unreliable on flash devices, and degaussing should never be relied on alone for them. Estates that replaced spinning disks years ago often kept a disposal process designed for the older media.
We build verification with real coverage targets
Pseudorandom sampling reaching at least ten percent of the media, secondary verification on at least twenty percent of items using a tool from a separate developer, and sampling performed where possible by people who did not do the sanitisation.
We make each device traceable to a record
A certificate of sanitisation per device, tying a serial number to a technique, an operator, a date and a verification result. That record is the only thing that answers the question after the hardware has left the building.
Three phases across roughly four to seven weeks.
- 01Weeks 1 to 2
Establish what leaves and what is on it
Which media types the organisation disposes of, what confidentiality of information each has held, and what currently happens to them. The decision process is based on the confidentiality of the information rather than the type of media.
- Media types and volumes documented
- Information confidentiality mapped per media type
- Current disposal route traced end to end
- Chain of custody gaps identified
- 02Weeks 3 to 5
Select techniques and design verification
Clear, Purge or Destroy chosen per category of information, then the technique that achieves it for each media type. Verification designed to the published expectations, including who performs the sampling and with which tools.
- Sanitisation category decided per information category
- Techniques selected per media type
- Verification approach designed with coverage targets
- Equipment calibration and operator competence addressed
- 03Weeks 6 to 7
Document, train and prove
A certificate of sanitisation process so each device has a record, operator competence confirmed, and a test run through the whole chain including verification. Sanitisation methods should be identified before the disposal phase, not at it.
- Certificate of sanitisation process in place
- Operators trained and competence confirmed
- End to end test run completed with records
- Supplier contract terms reviewed against the process
Six situations where disposal becomes a real risk.
A business refreshing laptops across the company
A hardware refresh sends hundreds of devices out at once, usually to a trade in or recycling arrangement. Volume is exactly when a process breaks, and it is also when the consequences of a weak process multiply.
A regulated firm asked to evidence destruction
Supervisors and auditors ask what happened to the data on decommissioned systems. A certificate per device tying serial number to technique and verification result is a materially better answer than a collection receipt from a supplier.
A healthcare provider disposing of imaging and records systems
Where media held health information, the confidentiality of that information drives the sanitisation category. Devices in medical equipment frequently hold data in places a general disposal process does not consider at all.
An office relocation or closure
Network devices, printers, copiers and access control systems all hold configuration, credentials and sometimes documents. The published guidance addresses routers and switches specifically, and they are almost never in a disposal inventory.
An organisation reselling or donating equipment
Where media is intended for reuse, Purge is generally the required category rather than Clear, because the device is leaving your control while remaining usable. That distinction is the one most often collapsed in practice.
A drawer full of failed drives nobody can wipe
Overwriting cannot be used on damaged or non rewriteable media, which is why failed devices accumulate. Destructive techniques may be the only option when media fails or when verification of Clear or Purge fails.
How UAE organisations dispose of IT assets.
| Feature | Designed and verified process | Supplier collects and certifies | Ad hoc |
|---|---|---|---|
Sanitisation category chosen deliberately | Per information confidentiality | Supplier default | None |
Flash media handled correctly | Yes | Unknown | No |
Verification performed | Every item where practical | Claimed | None |
Independent sampling | Yes, different personnel | No | No |
Secondary verification | Twenty percent, separate tool | No | No |
Chain of custody documented | End to end | From collection | None |
Certificate per device | Yes | Per collection | None |
Damaged media handled | Defined route | Unclear | Left in a drawer |
Position in an audit | Evidenced | Dependent on the supplier | Indefensible |
Effort to reach | Weeks | A purchase order | None |
Verification has published expectations, and almost nobody meets them.
This is the part of the guidance that most clearly separates a disposal process from a disposal habit.
- The highest assurance outside a laboratory is typically achieved by a full reading of all accessible areas to verify that the expected sanitised value is in all addressable locations, and a full verification should be performed if time and external factors permit.
- Where representative sampling is used instead, pseudorandom locations should be selected each time the analysis tool is applied, so that a tool sanitising only a subset of the media does not produce a verification success while sensitive data remains.
- Sampling coverage should reach at least ten percent of the media once all subsections have had two non overlapping samples taken. That is a specific and testable expectation rather than a general instruction to spot check.
- And secondary verification should cover at least twenty percent of sanitised items by number, using a tool from a separate developer, performing a full verification. That provides assurance that the primary operation is working as expected.
Five steps, and the first happens long before disposal.
- 1
Categorise the information, not the hardware
What confidentiality of information each class of media has held. That determines whether Clear, Purge or Destroy is required, and only afterwards does the media type influence which technique achieves the chosen category.
- 2
Select techniques per media type
Accounting for flash storage where wear levelling defeats overwriting, damaged media where overwriting is not possible, hybrid devices where degaussing is insufficient, and network equipment where a manufacturer reset is the documented Clear technique.
- 3
Design verification with coverage targets
Full verification where the device remains operational and time permits, pseudorandom sampling reaching at least ten percent otherwise, and secondary verification on at least twenty percent of items using a tool from a separate developer.
- 4
Address equipment and people
Calibration, testing and scheduled maintenance for sanitisation tools such as degaussers and dedicated workstations, and confirmation that operators are competent to perform sanitisation functions. Both are stated requirements rather than good practice.
- 5
Document every device and test the chain
A certificate of sanitisation per device following the published sample form, a documented chain of custody from desk to disposal, and one end to end test that proves the process works before it is relied upon at volume.
What organisations ask about IT asset disposal.
Fifteen questions about what happens to your old hardware.
The decision
- Do we choose Clear, Purge or Destroy?Three different outcomes.
- Is the choice based on confidentiality?Not on media type.
- Is it decided before disposal?It should be, per the guidance.
- Do we treat SSDs differently?Wear levelling changes everything.
- What about network devices?They hold configuration and keys.
The execution
- Who physically performs sanitisation?Internal or a supplier.
- Are operators competent?A stated requirement.
- Is equipment calibrated and maintained?Also stated.
- Is there a chain of custody?From desk to disposal.
- What happens to damaged media?Overwriting will not work.
The proof
- Do we verify every sanitisation?Where practical.
- Do we sample independently?By different personnel.
- Does sampling reach ten percent?The published target.
- Is twenty percent secondary verified?With a different tool.
- Is there a certificate per device?A sample form is published.
Pick a laptop your organisation disposed of last year and try to produce its sanitisation record.
Which method, by whom, on what date, verified how. If that record does not exist, neither does your evidence about where the data went.
Related Services
Explore more solutions that work great with this service
Backup and Restore Audit
We test whether your backups actually restore
Data Discovery Audit
Where the sensitive data is, and who can reach it
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations
Data Lifecycle Management
Retention policies, labels and defensible deletion
IT Infrastructure Audit
What you run, how much is supported, what fails
IT Risk Assessment
A short register with an owner against every risk
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
Software Asset Management Audit
What is installed against what you own