AUDIT EVIDENCE, EXPLAINED

What a Data Destruction Certificate Contains & Proves

The short answer:

A Certificate of Destruction (CoD) is the serialised document that proves specific devices were securely erased or physically destroyed. It lists every device by serial number, the method applied, and the standards followed — so you can evidence GDPR-compliant destruction in an audit, not just claim it.

If a provider offers data destruction but cannot show you a real, serialised certificate up front, treat that as a procurement risk.

Last reviewed: 31 August 2026 • For: compliance, IT, procurement, and audit teams • Methodology

Certificate Anatomy

What's On the Certificate

Every TFix CoD is structured for auditor use — not a one-line "we shredded your stuff" letter.

FieldWhat it showsWhy it matters
Chain-of-Custody IDOne reference linking every device in an orderFull traceability from collection to final destruction.
Device serial numbersEvery asset listed individuallyDevice-level proof, not a generic batch letter.
Applied methodClear, Purge, or Destroy per deviceShows the exact sanitisation or destruction route used.
Pass / fail statusVerification outcome per deviceFailed devices are diverted to controlled physical destruction.
Standards referencedNIST SP 800-88 Rev.2, BS EN 15713, NCSC guidanceDemonstrates recognised standards were followed.
Processing date & sign-offWhen and by whom destruction was completedDated, authorised evidence your auditor can rely on.
Example Certificate of Destruction for secure data destruction showing serialised device records
Real Sample

See the Certificate Before You Commit

We publish a real sample Certificate of Destruction. Compare it against what any other supplier will show you — most will not show you one at all.

The sample shows the full layout: Chain-of-Custody ID, per-device serial numbers, the applied method for each device, and the standards the process was carried out to.

Download Sample CoD PDF
Audit Alignment

What the Certificate Proves

UK GDPR & DPA 2018

Evidence that personal data has been irreversibly destroyed — the document organisations rely on to demonstrate destruction of personal data when regulators or data subjects ask.

NIST SP 800-88 Rev.2

The media-sanitisation standard that defines Clear, Purge and Destroy — and what counts as verified sanitisation of HDDs, SSDs, and NVMe media.

BS EN 15713

The secure-destruction standard that governs physical shredding particle size and chain-of-custody requirements for unrecoverable media.

Serialisation

Serial-Linked, Not a Batch Letter

Each device is logged by serial number at collection, tracked through chain of custody, and listed individually on the CoD.

We also sample 5% of sanitised data-bearing devices per Chain-of-Custody ID for professional-grade recovery attempts. A pass requires no mountable file system and no recoverable user data — if anything is found, the whole batch is quarantined and the certificates are suspended until resolved.

Any device that fails sanitisation or verification is diverted straight to controlled physical destruction.

  • One Chain-of-Custody ID per order
  • Per-device serial numbers throughout
  • Method recorded per device (Clear / Purge / Destroy)
  • Pass / fail status per device
  • 5% forensic recovery sampling on sanitised media
  • Failed devices diverted to physical destruction
Questions

Certificate of Destruction FAQ

What is a Certificate of Destruction (CoD)?

A serialised document issued after data-bearing media has been securely erased or physically destroyed. It lists every device, its serial number and the method applied, so the destruction of personal data can be evidenced in an audit.

What information is on a TFix Certificate of Destruction?

Chain-of-Custody ID, organisation name, processing date, per-device serial numbers, applied method (Clear, Purge or Destroy), pass/fail status, the referenced standards (NIST SP 800-88 Rev.2, BS EN 15713), and an authorised sign-off.

Do I get one certificate per device or per order?

One Certificate of Destruction per Chain-of-Custody order. Every device in that order is serial-linked in a single audit-ready document, so each device traces back to one order reference.

What standards does the certificate support?

NIST SP 800-88 Rev.2 for media sanitisation, NCSC secure sanitisation guidance, BS EN 15713 for physical destruction, and UK GDPR / Data Protection Act 2018 for the audit trail.

Is a Certificate of Destruction enough to evidence GDPR compliance?

It is the core evidence, but not the only one. Together with the Waste Transfer Note and chain-of-custody records, it demonstrates that personal data has been destroyed and provides the audit trail regulators and auditors expect.

Can I see a sample before committing?

Yes. Download a sample Certificate of Destruction PDF to see the full certificate layout, fields, and serialisation before you commit to a project.

Certifications & Compliance

Compliance You Can Verify

We lead with paperwork, not promises. Every registration below is independently checkable, and every project is delivered against recognised UK standards.

CredentialReferenceIssued / recognised byWhat it proves
Waste Carrier RegistrationCBDU351026Environment AgencyLegal authority to transport and carry controlled waste and end-of-life IT across the UK.
WEEE Treatment Exemption (T11)EXP/UP3043JDEnvironment AgencyAuthorised to treat waste electrical and electronic equipment for reuse and recycling.
ICO Data Protection RegistrationZB787416Information Commissioner's OfficeRegistered to process personal data in line with UK GDPR and the Data Protection Act 2018.
Cyber EssentialsCertifiedIASME (NCSC scheme)Independently verified baseline cyber-security controls protecting your data while in our custody.
ADR 1.3 Dangerous Goods Awareness (Driver Training)CertifiedEcoStar (Dangerous Goods Training Online)Collection drivers are trained to handle and transport equipment containing lithium batteries (UN3481, Class 9) in line with ADR dangerous goods rules.

Standards we work to

  • NIST SP 800-88 Rev.2Media sanitisation standard governing secure erase and physical destruction.
  • NCSC Secure Sanitisation GuidanceCurrent UK government guidance on secure sanitisation and disposal of storage media (replaces the withdrawn HMG IA Standard 5).
  • UK GDPR & Data Protection Act 2018Legal basis for evidenced, auditable destruction of personal data.
  • WEEE RegulationsEnvironmental compliance for waste electrical and electronic equipment.

Need our paperwork for an RFP or audit?

We can supply our registrations, insurance certificates, and sample destruction outputs as part of your supplier due diligence.

Get serialised destruction certificates with your next project

Certified erasure or physical destruction with one serial-linked Certificate of Destruction per Chain-of-Custody order — from £10 per drive or £495 per 100 loose drives.