Free tool · Nothing leaves your browser
Data Destruction
Policy
“Do you have a documented data destruction policy?” is on every ISO 27001 audit, every Cyber Essentials assessment and most public sector procurement questionnaires. This writes one.
The reason this exists: most templates still in circulation tell you to overwrite solid state drives. That does not reliably work — wear levelling means the controller writes to different physical cells than the ones addressed, so data survives in blocks no host-level tool can reach. A policy built on that is describing a control that does not do what it claims.
1. Whose policy is it
2. What media you hold
Each gets its own method. Untick anything you genuinely do not hold — a policy covering media you do not have is a policy nobody follows.
3. Records and third parties
Add the organisation name.
What this is not
It is a template, filled in. It is not certification, not legal advice, and not an assessment of your organisation. Adopting a policy is the easy half; the audit turns on whether you can produce the records it describes.
It is written against UK law — UK GDPR and the Data Protection Act 2018 — and against NIST SP 800-88 Rev. 1, which is the standard ISO 27001 assessors expect to see referenced for media sanitisation.
If you would rather we did it
We collect business IT across the UK, sanitise to NIST SP 800-88, and issue a certificate per device identified by serial number — not a certificate that says “40 items”, which is the one an auditor will not accept.