Skip to additional navigation Skip to content

Response 3902477

Response to request for information

Reference 

3902477

Response date

4 March 2026

Request

Under the Freedom of Information Act 2000, please provide the following recorded information held by your department regarding assurance processes for software based data erasure of end of life IT equipment.

For clarity, this request relates solely to software based data destruction. Please exclude physical destruction methods such as shredding, crushing, degaussing or disintegration.

  1. Please confirm whether departmental policy, contractual terms or internal procedures require an explicit outcome based warranty or guarantee confirming that personal data has been rendered irretrievable through software based erasure, whether carried out internally or by an external provider.
  2. Where software based data destruction is performed internally, what recorded evidential assurance does the department rely upon to conclude that the final data state is irretrievable?
  3. Where software based data destruction is performed by a third party provider, does the department hold recorded information demonstrating that any warranty or assurance provided explicitly extends to the software erasure method used and its claimed effectiveness? If so, please confirm the recorded nature of that verification.
  4. Where no explicit outcome based warranty is required or provided, what recorded form of evidential assurance does the department rely upon to conclude that software based erasure has rendered personal data irretrievable?

 

Response

Under the Freedom of Information Act 2000, please provide the following recorded information held by your department regarding assurance processes for software based data erasure of end of life IT equipment.

For clarity, this request relates solely to software based data destruction. Please exclude physical destruction methods such as shredding, crushing, degaussing or disintegration.

  1. Please confirm whether departmental policy, contractual terms or internal procedures require an explicit outcome based warranty or guarantee confirming that personal data has been rendered irretrievable through software based erasure, whether carried out internally or by an external provider.
    • There is no explicit requirement in departmental policy, contractual terms, or internal procedures for an outcome based warranty guaranteeing that personal data has been rendered irretrievable after software based erasure.
      However, in practice secure erasure and destruction controls are fully in place, and are delivered as follows:
      • Blancco is used by ICT to wipe internal drives. This is an industry standard certified erasure tool that ensures data is securely removed and cannot be restored. 
      • Hard drives that cannot be securely wiped internally (for example, damaged disks or decommissioned units) are removed and sent to an approved third party destruction provider.

These drives are physically destroyed, ensuring all data and software are completely unrecoverable. Together, these procedures ensure that all data is either securely erased or physically destroyed, even though no policy requires a formal written warranty confirming irretrievability.

  1. Where software based data destruction is performed internally, what recorded evidential assurance does the department rely upon to conclude that the final data state is irretrievable?
    • Blanco serial number are saved on a spread sheet.
  2. Where software based data destruction is performed by a third party provider, does the department hold recorded information demonstrating that any warranty or assurance provided explicitly extends to the software erasure method used and its claimed effectiveness? If so, please confirm the recorded nature of that verification.
    • We held a copy of the wee certification and asset destruction for the last 5 years
  3. Where no explicit outcome based warranty is required or provided, what recorded form of evidential assurance does the department rely upon to conclude that software based erasure has rendered personal data irretrievable?
    • Between Blanco and BitLocker and Hdd disposal we are confident data is irretrievable.