Data wiping vs hard drive shredding: which does your organisation actually need?
Once an organisation has decided it needs certified data destruction, the next question is rarely asked early enough: wipe it, or shred it? Both are valid, both are certifiable, and both satisfy GDPR and most compliance frameworks. But they’re not interchangeable, and choosing the wrong one for your situation either wastes money or introduces risk you didn’t need to take. This article walks through how to decide.
The short answer
If the device is going to be reused, resold or redeployed, you need certified data wiping. If the device is being permanently retired, damaged, or your policy requires physical destruction regardless of reuse value, you need hard drive shredding. Most organisations end up needing both, applied selectively across their estate, not one method applied universally.
What certified data wiping actually does
Certified data wiping uses approved software to overwrite every sector of a drive, multiple times in most cases, following a recognised standard. Once complete, the drive is functionally and physically intact. It can be reused, redeployed internally, donated, or resold. The data that was on it is not recoverable by any standard means, including most forensic recovery tools.
Ego Technology’s data wiping is carried out to NCSC guidance, the UK’s recognised standard for software-based sanitisation, with a serial-level erasure report issued for every device.
What hard drive shredding actually does
Hard drive shredding is the physical, mechanical destruction of the storage media itself. The drive is broken down into fragments small enough that data recovery is not just unlikely, it’s physically impossible, since the platters or memory chips holding the data no longer exist in a coherent form. See our full hard drive destruction page for the shred sizes and on-site/off-site options available.
The trade-off is permanent: a shredded drive cannot be reused, resold, or recovered for any purpose. Whatever resale value the device held is gone.
What hard drive shredding actually does
The device is being redeployed internally, for example a laptop moving from one department to another.
The device has resale value and you want to recover some of that value through technology buyback.
The device is functioning normally and there’s no physical damage or degradation affecting drive reliability.
Your policy doesn’t mandate physical destruction, many compliance frameworks accept certified wiping as sufficient evidence of secure disposal.
When shredding is the right call
The device is being permanently retired with no reuse intended.
The drive is damaged or unreliable, wiping software can fail to complete a full pass on a degraded drive, leaving uncertainty about whether the process actually worked.
Your sector or contract mandates physical destruction, common in defence, government, financial services and some healthcare contexts.
You need the highest possible level of assurance that data is unrecoverable under any circumstances, including future advances in forensic recovery techniques.
A note on cost and value
Wiping is generally the lower-cost option per device when factoring in the resale value recovered, since the device retains worth after the process. Shredding has no offsetting value recovery, the device is gone, but it removes any ongoing uncertainty about whether the drive could theoretically be recovered, which matters more to some organisations than the cost difference.
Neither method is inherently more secure than the other when carried out properly and certified. The right choice depends on your policy, your sector, and what you intend to do with the device afterward, not which method sounds more thorough.
Most organisations need a mixed approach
In practice, very few organisations apply a single method across their entire estate. A typical IT hardware refresh programme might wipe and resell 70% of devices that are still in good working condition, while shredding the remainder that are damaged, outdated, or fall under stricter internal policy. Ego Technology assesses each device on intake and recommends the appropriate method, rather than applying a blanket policy that either wastes resale value or under-delivers on security assurance.
Frequently asked questions
Is data wiping as secure as physical destruction?
Yes, when carried out to a recognised standard such as NCSC guidance, certified data wiping is considered equally secure to physical destruction for compliance purposes. Both methods result in formal certification. The choice between them depends on whether the device needs to be reused, not which is more secure.
Can a hard drive be wiped if it's already damaged?
Not reliably. Wiping software needs to complete a full pass across the drive to guarantee data is unrecoverable, and damaged or degraded drives can fail partway through this process without clear confirmation. For damaged or unreliable drives, physical destruction is the safer and more certain option.
Does my organisation need to choose one method for all devices?
No. Most organisations use a mixed approach, wiping devices that are functional and suitable for reuse or resale, and shredding devices that are damaged, outdated, or fall under a policy requiring physical destruction. Ego Technology assesses each device individually and recommends the appropriate method rather than applying a single approach across the whole estate.
Which method is required for ISO 27001 or GDPR compliance?
Neither GDPR nor ISO 27001 mandates a specific destruction method. Both require that data is rendered irrecoverable and that the process is documented and auditable. Certified data wiping and certified physical destruction both satisfy this requirement, provided they are carried out to a recognised standard and certified accordingly.
Recent articles
- What Happens If You Don’t Destroy Data Properly
Most organisations assume the risk of improper data destruction is theoretical, something that happens to other people, in other industries, after some unlikely chain of events. - Data Wiping vs Hard Drive Shredding
Once an organisation has decided it needs certified data destruction, the next question is rarely asked early enough: wipe it, or shred it? - What an enterprise IT lifecycle partner should be able to prove
A strong IT lifecycle partner should be able to provide clear evidence across the whole process, from collection and data handling through to reuse, recycling, material recovery, ESG reporting and final outcome. - From IT Disposal to ESG Evidence. What Large Organisations Could be Missing
As ESG reporting becomes more detailed and evidence-led, organisations are increasingly expected to demonstrate how technology has been managed throughout its lifecycle.
