CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

  • Home
  • Services
  • Chain of Custody for Data Erasure & Media Destruction

Chain of Custody for Data Erasure & Media Destruction

Track Every Data-Bearing Asset From Collection to Final Disposition

A data erasure certificate tells you what happened to a device. Chain of custody tells you where that device was and who was responsible for it along the way.

When a hard drive, SSD, laptop, server or other data-bearing asset changes hands, the security risk does not end when it is collected.

It may move through:

  1. Collection
  2. Transport
  3. Secure Storage
  4. Sanitization
  5. Verification
  6. Certificate
  7. Final Handover

Every movement creates another point where an asset can be misplaced, mixed with another device or become difficult to reconcile.

Our chain of custody data erasure service provides a documented record of the asset journey, helping organizations connect the physical device with its sanitization or destruction result.

The goal is simple:

Know the asset. Track the asset. Process the asset. Prove the outcome.

  • Chain of Custody
  • Data Erasure
  • Data Sanitization
  • Media Destruction
  • Asset Tracking
Chain of Custody for Data Erasure & Media Destruction

What Is Chain of Custody in Data Erasure?

A chain of custody for data erasure is the documented history of a data-bearing asset from the moment it is collected or released for processing until the final handover, reuse, resale, recycling or destruction.

It records the important events in the asset's journey.

Depending on the project, this can include:

  • Asset identification
  • Serial number
  • Client asset reference
  • Collection date
  • Collection location
  • Custodian or responsible person
  • Seal number
  • Handover date and time
  • Transfer details
  • Receiving location
  • Processing status
  • Sanitization method
  • Verification result
  • Destruction status
  • Certificate reference
  • Final disposition

This creates a traceable relationship between:

  1. Physical Asset
  2. Custody Record
  3. Sanitization/Destruction
  4. Verification
  5. Certificate

That relationship becomes especially important when an auditor, customer, security team or internal investigator asks:

“What happened to this specific drive?”

Why Chain of Custody Matters for Data Destruction

A batch-level disposal statement may say that 500 drives were processed.

An audit question is usually more specific:

What happened to serial number ABC123?

That is why asset-level chain-of-custody documentation matters.

Without Proper Tracking

An organization may know:

500 drives collected

but not be able to quickly demonstrate:

  • Which drive was processed
  • Who received it
  • Where it was stored
  • When it was sanitized
  • Which method was used
  • Whether verification passed
  • Which certificate belongs to it
  • What happened when an exception occurred

With a Documented Chain of Custody

The asset can be followed through the workflow:

  1. Collection
  2. Identification
  3. Transfer
  4. Processing
  5. Verification
  6. Certificate
  7. Disposition

This provides a much clearer audit trail.

Our Data Erasure Chain of Custody Process

  1. 01

    Collection & Asset Intake

    The process starts when the data-bearing media enters the controlled workflow.

    Relevant details are recorded before processing begins.

    This may include:

    • Asset ID
    • Manufacturer
    • Model
    • Serial Number
    • Capacity
    • Device Type

    The asset record becomes the reference point for everything that follows.

  2. 02

    Identification & Reconciliation

    The physical asset is matched to the client-provided asset list or processing manifest.

    Any mismatch can be identified before sanitization begins.

    This helps prevent:

    • Missing assets
    • Duplicate records
    • Incorrect serial numbers
    • Unidentified devices
    • Asset-to-certificate mismatches
  3. 03

    Secure Transfer or Internal Handover

    If the asset moves between authorized locations or custodians, the transfer is recorded.

    Relevant information can include:

    • Sender
    • Receiver
    • Date
    • Time
    • Location
    • Seal number
    • Asset reference
    • Signature or acknowledgement
  4. 04

    Secure Storage

    Assets waiting for processing can remain in the designated controlled area according to the project's handling procedures.

    The custody record continues while the asset is waiting.

  5. 05

    Data Erasure or Physical Destruction

    The asset is processed using the approved method.

    Depending on the device and project requirements, this may involve:

    • HDD data erasure
    • SSD sanitization
    • NVMe sanitization
    • Laptop data wiping
    • Server media erasure
    • Removable-media erasure
    • Physical media destruction

    The processing method should match the actual storage technology and organizational requirements.

  6. 06

    Verification

    The completed erasure process is verified where applicable.

    A device that fails the required verification should be recorded as failed rather than being incorrectly certified as successfully sanitized.

  7. 07

    Certificate & Documentation

    The processing result is tied back to the specific asset.

    Relevant records can include:

    • Erasure method
    • Verification result
    • Processing time
    • Operator
    • Asset reference
    • Certificate number
  8. 08

    Final Handover & Disposition

    After processing, the asset can move to its next approved lifecycle stage:

    1. Reuse
    2. Redeployment
    3. Refurbishment
    4. Resale
    5. Recycling
    6. Retirement

    For destroyed media, the final record reflects the applicable destruction outcome.

Every Handover Should Be Recorded

The word “custody” matters because assets can change hands.

A professional chain of custody for data destruction should make those transitions visible.

For each handover, the record can contain:

  1. From
  2. To
  3. Date
  4. Time
  5. Location
  6. Asset
  7. Seal
  8. Acknowledgement

This makes the movement of the physical asset easier to reconstruct later.

It also reduces dependence on memory or a spreadsheet completed at the end of the project.

The objective is to create the record as the event happens, not after the fact.

Chain of Custody for Data Erasure Services

Chain-of-custody documentation works alongside the actual sanitization process.

A typical workflow is:

  1. 01

    Identify the Asset

    The device is matched to its serial number and asset reference.

  2. 02

    Establish Custody

    The current responsible party and transfer details are recorded.

  3. 03

    Process the Asset

    The selected data erasure or destruction operation is performed.

  4. 04

    Verify the Result

    The result is checked and recorded.

  5. 05

    Issue the Certificate

    The certificate is tied to the specific device.

  6. 06

    Complete the Handover

    The asset moves to its next approved lifecycle stage with the relevant documentation.

This means the chain-of-custody record and the erasure certificate support each other rather than functioning as separate documents.

Chain of Custody for Hard Drives, SSDs & NVMe

Different storage technologies can travel through the same asset-management workflow.

Hard Drives

For HDDs, the record can include:

  • Manufacturer
  • Model
  • Capacity
  • Serial number
  • Interface
  • Erasure method
  • Verification result
  • Certificate reference

SSDs

For SSDs, documentation can identify:

  • SSD manufacturer
  • Model
  • Serial number
  • Capacity
  • Interface
  • Sanitization method
  • Verification result

NVMe Drives

For NVMe media, the record can also identify the device and the operation used during sanitization.

This is especially important in data center and enterprise environments where storage assets may be removed from racks in large quantities.

Read More

Chain of Custody for Data Center Decommissioning

Data center decommissioning can involve large numbers of drives and complex storage environments.

Assets may move from:

  1. Rack
  2. Staging Area
  3. Processing Bench
  4. Verification
  5. Certificate
  6. Exit

Without clear records, reconciling every physical drive against every certificate becomes difficult.

A structured data center chain of custody process can track:

  • Rack reference
  • Shelf or enclosure
  • Slot where applicable
  • Drive serial number
  • Asset reference
  • Custodian
  • Transfer event
  • Processing status
  • Verification result
  • Certificate
  • Final disposition

Data-center workflows can therefore connect physical decommissioning records with media sanitization evidence.

Data Sanitization Pro's current data-center workflow similarly emphasizes serial-level reconciliation and a certificate for each physical drive.

Chain of Custody for Data Center Decommissioning

Chain of Custody for ITAD

IT Asset Disposition (ITAD) is one of the areas where chain-of-custody documentation becomes particularly important.

ITAD assets can move through several organizations or facilities:

  1. Customer
  2. ITAD Provider
  3. Sanitization
  4. Refurbishment
  5. Resale / Recycling

Every transition creates a custody event.

A strong ITAD chain of custody can help track:

  • Asset received
  • Asset identified
  • Asset transferred
  • Asset sanitized
  • Asset verified
  • Certificate issued
  • Asset released
  • Final disposition

This creates a clearer record for the customer as well as the service provider.

Chain of Custody for ITAD

Chain of Custody for On-Site Data Erasure

On-site processing changes the custody model.

When data-bearing assets are sanitized at the customer's facility, there may be fewer external handovers because the media does not need to leave the site before processing.

The basic flow can become:

  1. Customer Custody
  2. On-Site Processing
  3. Verification
  4. Certificate
  5. Release

The chain-of-custody principle still matters.

Internal movement within the facility, asset identification, operator responsibility and final release can still be documented according to the project's controls.

For environments requiring strict physical control, on-site processing can therefore complement chain-of-custody documentation.

Secure Transport & Sealed Media Handling

Not every project can be completed on site.

When assets need to move to another controlled processing facility, transportation becomes part of the custody record.

A secure transfer workflow can document:

  • Packaging reference
  • Seal number
  • Asset count
  • Asset manifest
  • Dispatch date
  • Dispatch time
  • Receiving date
  • Receiving time
  • Sender
  • Receiver
  • Condition of the seal
  • Transfer discrepancy

The objective is not simply to document that a vehicle left one location and arrived at another.

The objective is to maintain a clear record of which assets were transferred and under whose responsibility.

What Happens if a Seal Is Broken?

A chain-of-custody process should define what happens when a discrepancy is discovered.

For example, if a sealed consignment arrives with a broken or mismatched seal, the asset should not simply enter normal processing.

The appropriate workflow can be:

  1. Identify
  2. Quarantine
  3. Record the Discrepancy
  4. Notify the Responsible Party
  5. Resolve
  6. Resume Processing

The event becomes part of the permanent custody record.

This is much stronger than silently replacing a seal and continuing the job.

Asset Reconciliation: Every Device Must Have a Place

One of the most important parts of chain-of-custody management is reconciliation.

At the end of the project:

Assets Received = Assets Processed + Exceptions + Assets Released

For each device, the final status should be clear.

Possible status categories may include:

  • Erased
  • Verified
  • Failed
  • Destroyed
  • Pending
  • Exception
  • Released

This is especially valuable for high-volume projects involving hundreds or thousands of assets.

A consolidated register can be matched against individual certificates so the customer does not have to rely on a general batch statement.

Chain of Custody & Data Erasure Certificates

A certificate answers:

What happened to this asset?

The chain-of-custody record answers:

Where was this asset and who handled it before and after processing?

Together, they create stronger evidence.

A certificate can contain:

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Asset reference
  • Erasure method
  • Verification result
  • Processing date
  • Start and completion time
  • Operator
  • Certificate identification

The custody record can additionally contain:

  • Collection information
  • Location
  • Custodian
  • Handover events
  • Seal numbers
  • Transfer timestamps
  • Receipt information
  • Discrepancy records

This connects:

Custody Evidence + Processing Evidence = Asset-Level Audit Trail

Data Sanitization Pro's current service architecture similarly emphasizes certificates tied to individual serial numbers and documented handovers.

Digital Signatures & Record Integrity

Where supported by the service workflow, certificate integrity can be strengthened through digital signatures or other record-protection mechanisms.

The purpose is to make it easier to determine whether a certificate or processing document has been modified after generation.

For high-volume enterprise projects, record integrity matters because documentation may need to be retained long after the hardware has left the organization.

The exact integrity mechanism should be documented accurately for the specific certificate format and service configuration.

Chain of Custody for Physical Data Destruction

Physical destruction requires its own evidence trail.

A destruction workflow can record:

  1. Asset Identification
  2. Custody
  3. Destruction
  4. Verification/Observation
  5. Certificate
  6. Final Disposition

Relevant records can include:

  • Device identification
  • Serial number where available
  • Destruction date
  • Location
  • Destruction method
  • Operator
  • Witness
  • Destruction status
  • Certificate reference
  • Video documentation where requested

The important distinction remains:

Erasure Certificate ≠ Certificate of Destruction

They document different outcomes.

Chain of Custody for Physical Data Destruction

Chain of Custody for Failed or Unreadable Media

Some media cannot be securely erased through software.

A drive may:

  • Fail detection
  • Have severe read/write errors
  • Be physically damaged
  • Fail verification
  • Be technically unsuitable for the required method

The asset should remain visible in the custody record.

Instead of disappearing from the workflow, its status changes:

  1. Received
  2. Failed Processing
  3. Further Assessment
  4. Destroyed / Other Approved Disposition

This prevents unresolved media from becoming an undocumented exception.

Chain of Custody for Government & Regulated Environments

Government, defence, financial, healthcare and other regulated environments can have specific requirements around access, media movement, witnessing and destruction.

A chain-of-custody process can support controls such as:

  • Restricted access
  • Named custodians
  • Controlled handovers
  • Sealed transport
  • Witnessed processing
  • Asset-level documentation
  • Verification records
  • Detailed audit trails
  • Final certificates

The exact control requirements depend on the organization's policy, contracts and applicable regulations.

Chain of custody itself is not a universal certification or guarantee of regulatory compliance. It is a documentation and control mechanism that can support an organization's broader information-security and media-disposition program.

Chain of Custody for Government & Regulated Environments

Data Sanitization Standards & Chain of Custody

Chain of custody and sanitization standards solve different problems.

NIST SP 800-88 Rev. 2

NIST SP 800-88 Rev. 2 provides guidance for media sanitization and selecting appropriate techniques based on information sensitivity and media characteristics. It does not turn “chain of custody” into a sanitization method. (csrc.nist.gov)

ISO/IEC 27001

Organizations using an ISO/IEC 27001-based information-security management system may include controls for asset handling, disposal and information protection.

PCI DSS

Organizations subject to PCI DSS may need documented controls for media containing sensitive payment-card information.

HIPAA

Healthcare organizations covered by HIPAA need appropriate safeguards for electronic protected health information and the media on which it is stored.

GDPR

Organizations processing personal data under GDPR may need appropriate controls for data retention, deletion, security and accountability.

The important distinction is:

  1. Chain of Custody
  2. Tracks the Asset
  1. Sanitization Method
  2. Removes or destroys the Data
  1. Verification
  2. Checks the Result
  1. Certificate
  2. Documents the Outcome

What Your Chain-of-Custody Record Can Contain

Depending on the project scope, records can include:

Asset Information

  • Asset ID
  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Device type
  • Customer reference

Custody Information

  • Collection date
  • Collection location
  • Custodian
  • Handover date
  • Handover time
  • Sender
  • Receiver
  • Seal number
  • Transfer location

Processing Information

  • Sanitization method
  • Operation performed
  • Processing date
  • Start time
  • Completion time
  • Operator
  • Verification result

Final Disposition

  • Erased
  • Verified
  • Destroyed
  • Failed
  • Pending
  • Released
  • Recycled
  • Resold
  • Reused

Documentation

  • Certificate number
  • Report reference
  • Witness information
  • Destruction documentation
  • Exception record

A Simple Example

Imagine a company retires 250 laptops.

The assets are collected from three offices.

The chain-of-custody process records:

  1. Office A
  2. Collection
  3. Secure Transport
  4. Processing Facility
  5. Erasure
  6. Verification
  7. Certificate

The same process applies to Office B and Office C.

At the end, the organization should be able to answer:

How many assets were received?

Which serial numbers were processed?

Which assets passed verification?

Which assets failed?

Which assets were physically destroyed?

Which certificate belongs to each serial number?

That is the practical value of a properly maintained chain-of-custody record.

Who Needs Data Erasure Chain-of-Custody Services?

Enterprise IT

For laptop, desktop, server and storage retirement.

Read More

ITAD Providers

For customer-facing asset tracking and documented disposition.

Data Centers

For rack, shelf and drive-level decommissioning.

Government & Defence

For controlled media movement and documented handovers.

Read More

Banking & Finance

For secure handling of sensitive storage assets.

Read More

Healthcare

For controlled processing of devices containing sensitive information.

Read More

MSPs & IT Service Providers

For maintaining clear customer asset records.

Recyclers & Refurbishers

For documenting the transition from collected equipment to sanitized hardware.

Security & CCTV Companies

For tracking storage media removed from DVR and NVR environments.

Why Choose Data Sanitization Pro for Chain of Custody?

Asset-Level Tracking

Track the individual storage asset rather than relying only on a batch summary.

Serial-Level Reconciliation

Connect each physical device with the processing result and certificate.

Erasure + Verification

Keep the sanitization result separate from the custody record.

Certificate-Based Evidence

Generate documentation for the specific asset processed.

On-Site & Controlled-Facility Workflows

Use on-site processing when media should not leave the customer's location or controlled transfer when transport is required.

Multiple Storage Types

Support workflows across HDD, SSD, NVMe, servers, laptops, removable media and other supported storage.

Failed-Media Tracking

Keep failed or unresolved assets visible instead of allowing them to disappear from the process.

Audit-Friendly Documentation

Create a clearer evidence trail for internal reviews, customers and auditors.

ITAD Ready

Connect custody records with reuse, resale, refurbishment, recycling and retirement workflows.

Frequently Asked Questions

What is a chain of custody in data destruction?

A chain of custody in data destruction is the documented history of a data-bearing asset from collection through transfer, processing, verification and final disposition.

Why is chain of custody important for data erasure?

It connects the physical asset with the people, locations and processing events associated with it. This makes it easier to prove what happened to a specific device.

What information is recorded in a chain-of-custody record?

It can include asset identification, serial number, collection details, locations, custodians, handovers, timestamps, seal numbers, processing results and final disposition.

Does chain of custody mean the data is securely erased?

No. Chain of custody tracks the asset. A separate sanitization or destruction process is required to address the data itself.

What is the difference between chain of custody and a data erasure certificate?

The chain-of-custody record documents the asset's movement and responsibility.

The data erasure certificate documents the sanitization operation and its result.

Can chain of custody be maintained for on-site data erasure?

Yes. Even when the asset never leaves the customer's premises, internal handovers, operator responsibility, asset identification and final release can still be documented.

Can you track hard drive serial numbers?

Yes, where serial information is available and readable, it can be associated with the asset record and resulting documentation.

What happens if a drive fails data erasure verification?

The failed result should be recorded. The drive can then be routed for further assessment or an approved destruction/disposition process.

How is chain of custody handled during transport?

Relevant transfer information such as asset identification, sender, receiver, date, time, location and seal information can be recorded according to the agreed workflow.

What happens if a security seal is broken?

The discrepancy should be recorded and the affected consignment can be quarantined pending review and resolution, rather than being processed as normal.

Can chain-of-custody records be used for ITAD?

Yes. They are particularly useful for ITAD because assets often pass through collection, transport, processing, refurbishment, resale and recycling stages.

Can you provide certificates for every processed asset?

Data Sanitization Pro supports asset-level certificates and reports for completed processing workflows. The certificate can be connected to the relevant device and processing result.

How long should chain-of-custody records be retained?

Retention should follow the organization's policy, contractual requirements and applicable legal or regulatory obligations.

Tell us what you need

Know Where Your Data-Bearing Assets Are

A secure data-erasure program should answer two questions:

Goes straight to our engineers. No newsletter, no call centre.