Certificate of Destruction vs Certificate of Erasure vs Waste Transfer Note: Which Audit Document Do You Need?

Ask three people in an IT team what paperwork they need after disposing of old equipment and you will get three different answers: "a certificate of destruction", "a certificate of erasure", and "a waste transfer note". They are not interchangeable. Each document proves a different thing, at a different point in the process — and an auditor who knows what they are looking at will ask for specific ones.

Here is what each document actually is, what it proves, and when you need it.
The short answer
- Waste Transfer Note (WTN) — a legal record that waste changed hands. Proves your equipment left your custody legally.
- Certificate of Erasure (CoE) — evidence that specific devices were wiped to a recognised standard and kept intact for reuse.
- Certificate of Destruction (CoD) — evidence that specific devices or media were physically destroyed (shredded, crushed, or incinerated).
One practical note before the detail: at TFix the CoD doubles as the CoE. A single Certificate of Destruction is issued per Chain-of-Custody order regardless of route, and for devices that are wiped rather than shredded the data destruction methods are outlined on the certificate itself — the sanitisation standard applied (for example NIST SP 800-88 Rev.2 Clear or Purge) is recorded per device, alongside the serial numbers. So if a provider hands you separate certificates for "erasure" and "destruction" on the same job, or a CoD that says nothing about method, ask why — the method line is the evidence.
If your devices are being wiped and reused, the erasure evidence on the certificate is your data proof. If they are being shredded, the destruction line is. The WTN covers the waste legality either way. Most real audit packs contain the certificate and the WTN together.
Waste Transfer Note: the legal baseline
A WTN is required under UK waste duty-of-care rules whenever non-hazardous waste moves from one party to another. For IT disposal, it records what was collected, from where, by whom (including the carrier's waste carrier licence number), and where it is going. Hazardous items — lithium batteries, CRT monitors — move on a Hazardous Waste Consignment Note instead.
What it proves: your organisation met its legal duty of care for the waste transfer. What it does not prove: anything about your data. A WTN says nothing about whether the data on those drives was wiped, shredded, or still readable. Treating a WTN as data-destruction evidence is one of the most common audit failures we see.

Certificate of Erasure: data gone, hardware kept
A Certificate of Erasure (also called a data erasure certificate, data wipe certificate, or certificate of sanitisation) is issued when media is sanitised to a recognised standard — typically NIST SP 800-88 Rev.2 Clear or Purge — and the hardware stays intact for resale, redeployment, or donation. It should list every device by serial number, the sanitisation method and standard applied, the date, and the verification result.
This is the certificate that supports the circular-economy route: data provably gone, value recovered. If your old laptops are being refurbished and resold, the erasure certificate is the document that makes that GDPR-defensible rather than just hopeful. See what NIST 800-88 Clear, Purge and Destroy actually mean for the standard behind it.
Certificate of Destruction: data gone, hardware gone
A Certificate of Destruction is issued when media is physically destroyed — shredded to a defined particle size (for example BS EN 15713 / DIN 66399 H-5 for hard drives), crushed, or incinerated. Same evidentiary core: serial numbers, method, date, standard, authorised sign-off.
And where a job mixes routes — some devices wiped for reuse, others shredded — a properly written CoD covers both: the destruction methods are outlined per device or per batch on the certificate, so the same document serves as your Certificate of Erasure for the wiped pool and your Certificate of Destruction for the shredded pool. That is exactly how the TFix certificate works, which is why we treat "CoD" and "CoE" as two names for the same audit document rather than two separate deliverables.
You need the physical-destruction route when drives are faulty, when policy forbids reuse, when the residual data risk is high enough that only physical destruction is acceptable, or when the hardware has no residual value. We have written separately about what a certificate of data destruction proves — and the three things it cannot prove, and you can see exactly what a TFix Certificate of Destruction contains field by field.
Which one does an auditor ask for?
For GDPR accountability, the auditor wants to see that personal data on end-of-life devices was rendered unrecoverable — and that you can prove it per device. That means:
- The erasure or destruction certificate, with serial numbers matching your asset register. A certificate that says "one pallet of IT equipment" without serials is decoration, not evidence.
- The WTN, to show the equipment reached the processor legally and never left controlled custody in between.
- Ideally, a chain-of-custody record tying the two together — collection manifest on one end, certificate on the other.
For an environmental audit (WEEE compliance, ESG reporting), the emphasis flips: the WTN and downstream treatment evidence matter most, and the certificates support the data-handling narrative.
Common gaps to check in your current paperwork
- No serial numbers on the certificate — the single biggest weakness. If the serials are not listed, the certificate cannot be matched to your assets.
- No named standard — "securely wiped" is a claim; "NIST SP 800-88 Rev.2 Purge, verified" is evidence.
- WTN filed as data evidence — it proves waste legality only.
- Erasure certificate for devices that were actually shredded (or vice versa) — the method on paper must match what physically happened.
TFix issues a serialised certificate per device — erasure or destruction depending on route — alongside the WTN and a full chain-of-custody audit pack as standard. If you want to sanity-check what your current provider gives you, compare it against our certificate breakdown or the definitions in the ITAD glossary, and see how our certified data destruction service works end to end.
Ready to act on this?
Book a free ITAD assessment, compare your destruction options, or review provider-selection guidance before choosing a partner.
Need help with this in your organisation?
Book the matching service directly based on this article topic.


