We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. IT asset disposal compliance
Asset disposal, UAE

A factory reset on an SSD is not sanitisation. Wear levelling means some of your data is still there.

Published guidance separates Clear, Purge and Destroy, and the decision is based on the confidentiality of the information rather than the type of media. Most UAE disposal processes pick a technique first and never verify the result.

Book a disposal process reviewSee the three categories
IT asset disposal compliance for UAE organisations
  • 3 categoriesClear, Purge and Destroy
  • 10 percentMinimum sampling coverage when verifying
  • 20 percentMedia requiring secondary verification
  • ConfidentialityWhat the decision is based on, not media type
The four assumptions that fail

Most disposal processes rest on beliefs that the published guidance contradicts.

None of these are obscure. They are simply not checked, because disposal is usually somebody else task and nobody asks how it is done.

  • That a factory reset sanitises a solid state drive. Flash devices may contain spare cells and perform wear levelling, which makes it infeasible for a user to sanitise all previous data through the standard read and write interface the reset uses.
  • That physical damage means destroyed. Bending, cutting and improvised methods may only damage the media, since portions can remain undamaged and therefore accessible using advanced laboratory techniques. Destruction has a defined standard and a visual inspection is not it.
  • That degaussing handles everything. It purges legacy magnetic devices when strength is matched to coercivity, and should never be solely relied upon for flash based storage or magnetic devices that also contain non volatile non magnetic storage.
  • That a supplier certificate is verification. A certificate records that an action was claimed. Verification is a separate step with published sampling expectations, and where possible it should be performed by personnel who were not part of the original sanitisation.
Ask us to test your disposal chain
What proper sanitisation requires

Eight things a disposal process has to get right.

Disposal is treated as a logistics problem, handled by whoever collects the hardware. It is a data protection control, and it is one of the few where a failure produces data in the hands of a stranger with no way to recall it.

Three categories, not one

Clear applies logical techniques against simple non invasive recovery. Purge applies physical or logical techniques that render recovery infeasible using state of the art laboratory techniques. Destroy does the same and leaves the media unusable for storage.

The decision follows the data, not the device

The decision process is based on the confidentiality of the information, not the type of media. Once the organisation decides what type of sanitisation is best, the media type then influences which technique achieves that goal.

Overwriting fails on flash storage

Flash memory based devices may contain spare cells and perform wear levelling, making it infeasible for a user to sanitise all previous data by overwriting. Overwriting also cannot be used on media that are damaged or not rewriteable.

Cryptographic erase is fast and needs verifying

It sanitises the target data encryption key, leaving only ciphertext on the media. Where verification cannot be performed, organisations should use an alternative method that can be verified, or use it in combination with one that can.

Verification is not optional

Two types should be considered: verification every time sanitisation is applied where practical, and representative sampling on a subset. Where possible the sampling should be executed by personnel who were not part of the original sanitisation action.

Sampling has published coverage targets

Pseudorandom locations selected each time the tool is applied, with coverage reaching at least ten percent of the media once all subsections have had two samples. Secondary verification covers at least twenty percent of items using a tool from a separate developer.

Degaussing has real limits

It purges a legacy magnetic device when the degausser strength is carefully matched to the media coercivity. It should never be solely relied upon for flash based storage or for magnetic devices that also contain non volatile non magnetic storage.

The activity has to be documented

The published guidance includes a sample certificate of sanitisation form for documenting sanitisation activities. Without a record tying a specific device to a specific action, there is nothing to show an auditor or a regulator after the fact.

The three categories

Clear, Purge and Destroy, and what each actually achieves.

Taken from the published definitions. The right column is what determines which one your data requires, and it is a confidentiality judgement rather than a technical preference.
CategoryWhat it achievesWhen it is chosen
ClearProtects against simple non invasive recoveryLower confidentiality, media staying in the organisation
PurgeRecovery infeasible with laboratory techniquesHigher confidentiality, media being reused or sold
DestroyRecovery infeasible and media unusable afterwardsHighest confidentiality, or where Clear and Purge fail
Cryptographic eraseSanitises the key, leaving only ciphertextFast, where verification is achievable
OverwritingA Clear technique using read and write commandsNot for damaged, non rewriteable or flash media
DegaussingPurges legacy magnetic media when matched to coercivityNever alone for flash or hybrid devices
Shredding and disintegrationDestruction, when applied to the appropriate mediaWhere reuse is not intended
Manufacturer reset on network devicesClear for routers and switchesReturning to factory default settings
Paper cross cut shreddingParticles of 1 mm by 5 mm or smallerDestruction of paper records
Paper disintegrationDisintegrator with a 2.4 mm security screenAn alternative to cross cut shredding
How we approach it

Four things that turn disposal into a control.

The failure mode here is unusually severe. Data that leaves on a disposed device cannot be recalled, and you generally never find out.

We start from the information, not the hardware

The decision process is based on the confidentiality of the information, not the type of media. Once the required category is decided, media type determines the technique, which is the reverse of how most disposal processes are actually designed.

We treat flash storage as its own problem

Spare cells and wear levelling make overwriting unreliable on flash devices, and degaussing should never be relied on alone for them. Estates that replaced spinning disks years ago often kept a disposal process designed for the older media.

We build verification with real coverage targets

Pseudorandom sampling reaching at least ten percent of the media, secondary verification on at least twenty percent of items using a tool from a separate developer, and sampling performed where possible by people who did not do the sanitisation.

We make each device traceable to a record

A certificate of sanitisation per device, tying a serial number to a technique, an operator, a date and a verification result. That record is the only thing that answers the question after the hardware has left the building.

How an engagement runs

Three phases across roughly four to seven weeks.

Short, because the process is narrow. The value is in the verification design and the record keeping, both of which are usually absent rather than weak.
  1. 01
    Weeks 1 to 2

    Establish what leaves and what is on it

    Which media types the organisation disposes of, what confidentiality of information each has held, and what currently happens to them. The decision process is based on the confidentiality of the information rather than the type of media.

    • Media types and volumes documented
    • Information confidentiality mapped per media type
    • Current disposal route traced end to end
    • Chain of custody gaps identified
  2. 02
    Weeks 3 to 5

    Select techniques and design verification

    Clear, Purge or Destroy chosen per category of information, then the technique that achieves it for each media type. Verification designed to the published expectations, including who performs the sampling and with which tools.

    • Sanitisation category decided per information category
    • Techniques selected per media type
    • Verification approach designed with coverage targets
    • Equipment calibration and operator competence addressed
  3. 03
    Weeks 6 to 7

    Document, train and prove

    A certificate of sanitisation process so each device has a record, operator competence confirmed, and a test run through the whole chain including verification. Sanitisation methods should be identified before the disposal phase, not at it.

    • Certificate of sanitisation process in place
    • Operators trained and competence confirmed
    • End to end test run completed with records
    • Supplier contract terms reviewed against the process
Where this matters

Six situations where disposal becomes a real risk.

The common factor is hardware leaving an organisation faster than anybody is tracking it.

A business refreshing laptops across the company

A hardware refresh sends hundreds of devices out at once, usually to a trade in or recycling arrangement. Volume is exactly when a process breaks, and it is also when the consequences of a weak process multiply.

A regulated firm asked to evidence destruction

Supervisors and auditors ask what happened to the data on decommissioned systems. A certificate per device tying serial number to technique and verification result is a materially better answer than a collection receipt from a supplier.

A healthcare provider disposing of imaging and records systems

Where media held health information, the confidentiality of that information drives the sanitisation category. Devices in medical equipment frequently hold data in places a general disposal process does not consider at all.

An office relocation or closure

Network devices, printers, copiers and access control systems all hold configuration, credentials and sometimes documents. The published guidance addresses routers and switches specifically, and they are almost never in a disposal inventory.

An organisation reselling or donating equipment

Where media is intended for reuse, Purge is generally the required category rather than Clear, because the device is leaving your control while remaining usable. That distinction is the one most often collapsed in practice.

A drawer full of failed drives nobody can wipe

Overwriting cannot be used on damaged or non rewriteable media, which is why failed devices accumulate. Destructive techniques may be the only option when media fails or when verification of Clear or Purge fails.

Three positions

How UAE organisations dispose of IT assets.

The middle column is the most common and it is the one that produces a certificate nobody has ever tested against the media it describes.
Sanitisation category chosen deliberately
Designed and verified processPer information confidentiality
Supplier collects and certifiesSupplier default
Ad hocNone
Flash media handled correctly
Designed and verified processYes
Supplier collects and certifiesUnknown
Ad hocNo
Verification performed
Designed and verified processEvery item where practical
Supplier collects and certifiesClaimed
Ad hocNone
Independent sampling
Designed and verified processYes, different personnel
Supplier collects and certifiesNo
Ad hocNo
Secondary verification
Designed and verified processTwenty percent, separate tool
Supplier collects and certifiesNo
Ad hocNo
Chain of custody documented
Designed and verified processEnd to end
Supplier collects and certifiesFrom collection
Ad hocNone
Certificate per device
Designed and verified processYes
Supplier collects and certifiesPer collection
Ad hocNone
Damaged media handled
Designed and verified processDefined route
Supplier collects and certifiesUnclear
Ad hocLeft in a drawer
Position in an audit
Designed and verified processEvidenced
Supplier collects and certifiesDependent on the supplier
Ad hocIndefensible
Effort to reach
Designed and verified processWeeks
Supplier collects and certifiesA purchase order
Ad hocNone
Feature
Designed and verified process
Supplier collects and certifies
Ad hoc
Sanitisation category chosen deliberately
Per information confidentialitySupplier defaultNone
Flash media handled correctly
YesUnknownNo
Verification performed
Every item where practicalClaimedNone
Independent sampling
Yes, different personnelNoNo
Secondary verification
Twenty percent, separate toolNoNo
Chain of custody documented
End to endFrom collectionNone
Certificate per device
YesPer collectionNone
Damaged media handled
Defined routeUnclearLeft in a drawer
Position in an audit
EvidencedDependent on the supplierIndefensible
Effort to reach
WeeksA purchase orderNone
The verification standard

Verification has published expectations, and almost nobody meets them.

This is the part of the guidance that most clearly separates a disposal process from a disposal habit.

  • The highest assurance outside a laboratory is typically achieved by a full reading of all accessible areas to verify that the expected sanitised value is in all addressable locations, and a full verification should be performed if time and external factors permit.
  • Where representative sampling is used instead, pseudorandom locations should be selected each time the analysis tool is applied, so that a tool sanitising only a subset of the media does not produce a verification success while sensitive data remains.
  • Sampling coverage should reach at least ten percent of the media once all subsections have had two non overlapping samples taken. That is a specific and testable expectation rather than a general instruction to spot check.
  • And secondary verification should cover at least twenty percent of sanitised items by number, using a tool from a separate developer, performing a full verification. That provides assurance that the primary operation is working as expected.
Ask us to design the verification step
How an engagement runs

Five steps, and the first happens long before disposal.

The guidance is explicit that sanitisation methods should be identified and developed before arriving at the disposal phase of the system life cycle.
  1. 1

    Categorise the information, not the hardware

    What confidentiality of information each class of media has held. That determines whether Clear, Purge or Destroy is required, and only afterwards does the media type influence which technique achieves the chosen category.

  2. 2

    Select techniques per media type

    Accounting for flash storage where wear levelling defeats overwriting, damaged media where overwriting is not possible, hybrid devices where degaussing is insufficient, and network equipment where a manufacturer reset is the documented Clear technique.

  3. 3

    Design verification with coverage targets

    Full verification where the device remains operational and time permits, pseudorandom sampling reaching at least ten percent otherwise, and secondary verification on at least twenty percent of items using a tool from a separate developer.

  4. 4

    Address equipment and people

    Calibration, testing and scheduled maintenance for sanitisation tools such as degaussers and dedicated workstations, and confirmation that operators are competent to perform sanitisation functions. Both are stated requirements rather than good practice.

  5. 5

    Document every device and test the chain

    A certificate of sanitisation per device following the published sample form, a documented chain of custody from desk to disposal, and one end to end test that proves the process works before it is relied upon at volume.

Straight answers

What organisations ask about IT asset disposal.

For some devices it meets the definition of Clear, and Clear only protects against simple non invasive recovery. On flash based storage, spare cells and wear levelling make it infeasible to sanitise all previous data through the standard interface at all.

Clear applies logical techniques against simple non invasive recovery. Purge applies physical or logical techniques making recovery infeasible using state of the art laboratory techniques. Destroy achieves the same and leaves the media unusable for storage afterwards.

By the confidentiality of the information, not the type of media. Once the category is chosen, the media type influences which technique achieves it. Reversing that order is the most common design error in a disposal process.

Not necessarily. Bending, cutting and improvised methods may only damage the media, since portions can remain undamaged and accessible using advanced laboratory techniques. Destruction has a defined outcome, and visible damage does not demonstrate it.

For legacy magnetic devices, when the degausser strength is carefully matched to the media coercivity, which the manufacturer rather than the label can confirm. It should never be relied on alone for flash storage or hybrid devices containing non magnetic storage.

Sanitising the encryption key used to encrypt the target data, leaving only ciphertext on the media and preventing read access. It is fast, and where its effectiveness cannot be verified an alternative verifiable method should be used instead or alongside it.

Full verification of all accessible areas where the device remains operational and time permits. Otherwise pseudorandom sampling reaching at least ten percent of the media, plus secondary verification on at least twenty percent of items with a different tool.

Where possible, personnel who were not part of the original sanitisation action. Where sampling follows a full verification in low risk tolerance cases, a different verification tool from the one used originally should be used.

It is a record of a claim, not a verification. A robust arrangement combines the supplier certificate with your own sampling, chain of custody documentation, and a certificate per device tying a serial number to a technique and a result.

It holds configuration, credentials and sometimes logs. The published guidance treats routers and switches specifically, with a full manufacturer reset to factory default settings as the Clear technique. They are routinely omitted from disposal inventories.

Overwriting cannot be used on damaged or non rewriteable media, so destructive techniques may be the only option, which the guidance acknowledges directly. A defined route for failed media prevents the drawer of drives nobody can process.

The guidance is specific: cross cut shredders producing particles of one millimetre by five millimetres or smaller, or disintegrator devices equipped with a security screen of about two point four millimetres.

Before the disposal phase. The guidance states the need for, and methods to conduct, media sanitisation should be identified and developed before arriving at disposal in the system life cycle, ideally when the system security plan is first written.

A certificate of sanitisation per device, following the published sample form, recording what was sanitised, by which method, by whom, when, and with what verification result. That record is what survives after the hardware has gone.

We scope by media volume and how many disposal routes exist. The free first step: pick a laptop your organisation disposed of last year and try to produce a record showing how its drive was sanitised and who verified it.

Whoever owns the information rather than whoever collects the hardware. The decision is based on the confidentiality of the information, which is a business judgement, and delegating it to a disposal supplier inverts the decision entirely.

Often yes, provided operators are competent and any equipment is calibrated, tested and maintained. Both of those are stated expectations, and an internal process that ignores them is not obviously better than an unverified supplier.

They are storage devices with the same flash characteristics that make overwriting unreliable. Where the device only supports a return to factory state, that meets the definition of Clear provided the interface does not facilitate retrieval of the cleared data.

Frequently, in internal storage holding scanned and printed documents. Office equipment is exactly the category the guidance describes as sometimes only supporting a return to factory state, and it is routinely absent from disposal inventories.

Cryptographic erase becomes available, sanitising the encryption key and leaving only ciphertext. Where its effectiveness cannot be verified, the guidance is to use an alternative verifiable method instead or in combination with it.

As a disposal event, because the media is leaving your control. Whether the device is being sold to the employee, donated or written off, the confidentiality of the information it held determines the sanitisation category required.

Where practical, yes. Sanitising on site before the media leaves your custody removes the chain of custody risk entirely, and it means the verification step is performed by you rather than accepted on a certificate afterwards.

Devices that never reach the process. Drawers of failed drives, decommissioned network equipment left in a rack, and devices held by departed staff. The inventory gap is a bigger practical risk than the technique choice in most organisations.

Yes, and the guidance supports doing it early. The need for, and methods to conduct, media sanitisation should be identified before reaching the disposal phase, which places it in the system security plan rather than in a facilities procedure.
Disposal check

Fifteen questions about what happens to your old hardware.

Most of these can be answered in an afternoon, and the answers are frequently uncomfortable for organisations that have never asked them.

The decision

  • Do we choose Clear, Purge or Destroy?
    Three different outcomes.
  • Is the choice based on confidentiality?
    Not on media type.
  • Is it decided before disposal?
    It should be, per the guidance.
  • Do we treat SSDs differently?
    Wear levelling changes everything.
  • What about network devices?
    They hold configuration and keys.

The execution

  • Who physically performs sanitisation?
    Internal or a supplier.
  • Are operators competent?
    A stated requirement.
  • Is equipment calibrated and maintained?
    Also stated.
  • Is there a chain of custody?
    From desk to disposal.
  • What happens to damaged media?
    Overwriting will not work.

The proof

  • Do we verify every sanitisation?
    Where practical.
  • Do we sample independently?
    By different personnel.
  • Does sampling reach ten percent?
    The published target.
  • Is twenty percent secondary verified?
    With a different tool.
  • Is there a certificate per device?
    A sample form is published.
Related reading

The pages around this one.

Backup audit

The other place old copies of data survive.

Learn more

Data discovery and classification audit

Knowing what confidentiality the data carried.

Learn more

UAE PDPL compliance

Why disposal is a data protection control.

Learn more
Next step

Pick a laptop your organisation disposed of last year and try to produce its sanitisation record.

Which method, by whom, on what date, verified how. If that record does not exist, neither does your evidence about where the data went.

Book a disposal process reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Backup and Restore Audit

We test whether your backups actually restore

Learn more

Data Discovery Audit

Where the sensitive data is, and who can reach it

Learn more

UAE PDPL Compliance

Federal Decree-Law 45 of 2021 readiness and operations

Learn more

Data Lifecycle Management

Retention policies, labels and defensible deletion

Learn more

IT Infrastructure Audit

What you run, how much is supported, what fails

Learn more

IT Risk Assessment

A short register with an owner against every risk

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

Software Asset Management Audit

What is installed against what you own

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy