None of these frameworks tell you how many passes to run. What they ask for is narrower and harder: that data is destroyed when its purpose ends, that you can show which asset it was on, and that a third party can check the claim later.
That is why the certificate matters more than the method. What follows is what each framework requires at the point of disposal, and what has to be on the document to answer it. We implement the published erasure standards; being certified against a framework is a separate matter and is not claimed here.
The Risks This Removes
Deleted Is Not Destroyed
A deleted file, a formatted volume and a decommissioned array all still hold the data. Every one of these frameworks treats the obligation as ending when the data is unrecoverable, not when it stops being visible.
No Asset-Level Record
A policy saying drives are wiped is not evidence that a particular drive was. When a regulator asks about one serial number, an organisation-level statement does not answer it.
The Gap at Handover
Most exposure happens after the asset leaves — in transit, at a recycler, on a resale floor. If the erasure happened before it moved, and the certificate says so, that gap closes.
What Each Framework Asks For
The obligation in each case is the outcome, not the algorithm. What differs is who has to be able to check it, and for how long.
| Framework | Applies to | What it requires at disposal | What the record has to show |
|---|---|---|---|
| DPDP Act 2023 (India) | Anyone processing personal data of people in India | Personal data must be erased once the purpose it was collected for is served, and that obligation extends to processors acting for you. | The asset, the date, the method, and that the erasure was verified. |
| GDPR (EU/UK) | Controllers and processors handling EU or UK personal data | Storage limitation and the right to erasure. Data must not be kept past its purpose, and deletion has to be effective on every copy, retired media included. | Which media held the data, when it was destroyed, and by whom. |
| HIPAA (US) | Covered entities and business associates holding health records | Media holding protected health information must be sanitized before disposal or reuse, and the disposal has to be documented. | Device identity, the sanitization method, and the person accountable for it. |
| PCI-DSS | Anyone storing, processing or transmitting cardholder data | Cardholder data must be rendered unrecoverable once it is no longer needed, and media destruction has to be documented. | The media, the destruction method, and a retained record of both. |
| R2v3 | Electronics refurbishers and recyclers, and the clients who use them | A documented data sanitization process applied to every data-bearing device before resale or downstream transfer. | Per-device records that survive the chain, not a batch statement. |
What We Do, and What We Do Not Claim
- The software implements the published erasure standards listed on the standards page, including NIST SP 800-88 Rev. 2 and IEEE 2883-2022.
- Every run records the drive by serial, the standard used and a verification read, then issues a certificate for that asset.
- The certificate carries the operator, the approver and the organisation, which is what turns it from a log line into a record with accountability attached.
- Implementing a standard is not the same as being certified against a framework. Where a framework requires an audited certification, that is held by the organisation being audited — software does not confer it.
- Where a drive cannot be sanitized, because it refuses the command or fails verification, it is flagged for physical destruction rather than passed as clean.
Frequently Asked Questions
Does using this software make us DPDP compliant?
It gives you the erasure and the evidence, which is the part of the obligation that touches storage media. Compliance is broader than disposal, and no software makes an organisation compliant on its own.
How long should we keep the certificates?
For as long as you are answerable for the asset, which is set by whichever framework applies to you rather than by the erasure. They are ordinary PDFs and can be archived with the rest of your evidence.
Our recycler says they wipe drives. Is that enough?
It depends whether they give you a per-device record, and whether the data left your premises before it was erased. Erasing on site, before the asset moves, removes the question entirely.
Is a record valid if the drive was destroyed instead of wiped?
Yes. Destruction is a legitimate outcome and it is the correct one for a drive that cannot be sanitized. What matters is that the record says which happened to which serial number.
Do you claim any certifications yourselves?
Not here. Where the software implements a published standard, that is stated and can be checked against the run itself. Anything held by our services operation is separate from what the software does.
Check the Document Against Your Own Framework
The sample certificate is published in full. Hold it up against what your auditor asks you for.
See Sample Certificates
