What a data destruction certificate should record.
A data destruction certificate is the written record that one named storage device was wiped or destroyed. It should give the make, model and serial number, the method, the verification result, the date and the technician.
- Sheet
- Guide
- Published
- 30 September 2026
- Last updated
- 30 September 2026
- Written by
- Gentex AU
What a data destruction certificate is for.
A business keeps an asset register: every laptop, server and recorder it owns, by serial number. When a device is retired, its line needs an ending. The certificate is that ending: this drive, by this serial, was sanitised or destroyed by this method on this date.
It goes by several names. A certificate of destruction, a hard drive destruction certificate and a data erasure certificate are the same kind of document. The difference is the method each one records: an overwrite that leaves the drive usable, or a shredder that does not.
Our own data destruction service has three levels, and the certificate changes with the level. The fields below are the ones to look for on anybody's.
The fields, and the question each one answers.
Read a certificate the way an auditor does: one field, one question.
- 01 Make, model and serial number.
- Which device. The serial is what ties the certificate to a line in your asset register. Without it the document describes a drive, not your drive.
- 02 Method.
- What was done. An overwrite, a cryptographic erase and physical destruction are different acts with different evidence. If a provider claims to work to a standard, the certificate should name it and its version.
- 03 Pass count and verification.
- How anyone knows it worked. For an overwrite, the certificate records how many passes ran and the result of reading the drive back afterwards. A wipe with no verification result is a claim, not a record.
- 04 Physical method.
- A destroyed drive has no passes to count. The certificate records how it was destroyed, by shredding, crushing or degaussing, and the serial taken before the drive went in.
- 05 Date and technician.
- When, and who. The date closes the gap between the device leaving your building and the data being gone. A named technician can be asked about the work.
- 06 Certificate number and batch ID.
- Where it has been. The batch ID links the certificate to the chain-of-custody record: who collected the device, who moved it and where it was processed.
- 07 Client and site.
- Whose it was. It ties the document to your organisation and to the address the device was collected from.
What a batch-only certificate cannot prove.
A batch certificate says a pallet of drives was received and destroyed on a date. It is true, and it is thin. It records a count and sometimes a weight.
Now ask it about one machine. A laptop from the finance team is reported missing, or a customer asks whether their records were on a drive you disposed of. The batch certificate cannot say whether that serial was in the batch. It cannot say which drives were wiped and which were shredded, or whether any failed verification.
A batch certificate is sound when it carries a schedule listing every serial in the batch with its method and result. Then it is a per-device record on one document. Without the schedule, treat it as a receipt.
The test: pick one serial from your asset register and find it on the certificate.
Where it sits in a privacy audit.
Australian Privacy Principle 11.2 requires an organisation covered by the Privacy Act to take reasonable steps to destroy or de-identify personal information once it is no longer needed for any purpose the principles allow. There are exceptions, including where a law requires the information to be kept. The OAIC's guidelines say personal information is destroyed when it can no longer be retrieved.
The same guidelines give examples of reasonable steps. One is verifying and documenting when and what personal information is destroyed. Another covers information held on a third party's hardware: where that party has been instructed to destroy it, reasonable steps include verifying that this has occurred.
A certificate with a serial, a method and a verification result is that record. This is general information, not legal advice.
A checklist to read a certificate against.
Every line that is missing is a question you cannot answer later.
A certificate should show
- Your organisation and the site the device came from.
- A certificate number, and a batch ID that matches your collection paperwork.
- The make, model and serial number of each device or drive.
- The method in plain words: overwrite, cryptographic erase or physical destruction.
- For a wipe: the pass count and the verification result.
- For physical destruction: how the drive was destroyed, and the serial recorded beforehand.
- The date the work was done, not only the date of collection.
- The name of the technician.
- What happened to any drive that failed or could not be wiped.
Tell us what you have and who you answer to. We will confirm the level and the paperwork.
What to ask a provider before the drives leave.
- Ask for a specimen certificate. If it has no serial field, the real one will not either.
- Ask when serials are recorded: at collection, in front of you, or later at the facility.
- Ask what happens to a drive that fails verification or will not power up.
- Ask how solid-state drives are handled. Flash storage keeps data in cells an ordinary overwrite may not reach, so the method differs from a spinning disk.
- Ask for the chain-of-custody record as well as the certificate.
- Ask where the hardware goes afterwards.
What our own service records, for comparison. Each asset is tagged at intake and given a batch ID and a handling technician. The certificate is issued per device or per batch and records model, serial, method, pass count, verification, date and technician. Every movement is logged under the batch ID, and the eWaste goes to certified downstream recyclers.
The three destruction levels and a specimen certificate are set out on the service page. If the drives are coming out of machines we are replacing, the team that provides business IT support does both. To start, send the asset list through the quote form or email contact@gentex.au.
Questions we get asked.
Is a certificate of destruction a legal requirement in Australia?
Is a data erasure certificate different from a hard drive destruction certificate?
Does a certificate prove the data cannot be recovered?
What if a drive is dead and cannot be wiped?
Related sheets.
Send us the asset list.
A count of devices and what was stored on them is enough to start. We will confirm the level, the certificate you will receive and the collection window.
- To
- Gentex AU · Tullamarine VIC
- Reply
- Phone or email, usually the same business day
- Attending
- Mon–Fri 07:00–16:00
- Licensing
- Victorian Private Security Licence