The short answer:
A Certificate of Destruction (CoD) is the serialised document that proves specific devices were securely erased or physically destroyed. It lists every device by serial number, the method applied, and the standards followed — so you can evidence GDPR-compliant destruction in an audit, not just claim it.
If a provider offers data destruction but cannot show you a real, serialised certificate up front, treat that as a procurement risk.
Last reviewed: 31 August 2026 • For: compliance, IT, procurement, and audit teams • Methodology
Every TFix CoD is structured for auditor use — not a one-line "we shredded your stuff" letter.
| Field | What it shows | Why it matters |
|---|---|---|
| Chain-of-Custody ID | One reference linking every device in an order | Full traceability from collection to final destruction. |
| Device serial numbers | Every asset listed individually | Device-level proof, not a generic batch letter. |
| Applied method | Clear, Purge, or Destroy per device | Shows the exact sanitisation or destruction route used. |
| Pass / fail status | Verification outcome per device | Failed devices are diverted to controlled physical destruction. |
| Standards referenced | NIST SP 800-88 Rev.2, BS EN 15713, NCSC guidance | Demonstrates recognised standards were followed. |
| Processing date & sign-off | When and by whom destruction was completed | Dated, authorised evidence your auditor can rely on. |

We publish a real sample Certificate of Destruction. Compare it against what any other supplier will show you — most will not show you one at all.
The sample shows the full layout: Chain-of-Custody ID, per-device serial numbers, the applied method for each device, and the standards the process was carried out to.
Download Sample CoD PDFEvidence that personal data has been irreversibly destroyed — the document organisations rely on to demonstrate destruction of personal data when regulators or data subjects ask.
The media-sanitisation standard that defines Clear, Purge and Destroy — and what counts as verified sanitisation of HDDs, SSDs, and NVMe media.
The secure-destruction standard that governs physical shredding particle size and chain-of-custody requirements for unrecoverable media.
Each device is logged by serial number at collection, tracked through chain of custody, and listed individually on the CoD.
We also sample 5% of sanitised data-bearing devices per Chain-of-Custody ID for professional-grade recovery attempts. A pass requires no mountable file system and no recoverable user data — if anything is found, the whole batch is quarantined and the certificates are suspended until resolved.
Any device that fails sanitisation or verification is diverted straight to controlled physical destruction.
A serialised document issued after data-bearing media has been securely erased or physically destroyed. It lists every device, its serial number and the method applied, so the destruction of personal data can be evidenced in an audit.
Chain-of-Custody ID, organisation name, processing date, per-device serial numbers, applied method (Clear, Purge or Destroy), pass/fail status, the referenced standards (NIST SP 800-88 Rev.2, BS EN 15713), and an authorised sign-off.
One Certificate of Destruction per Chain-of-Custody order. Every device in that order is serial-linked in a single audit-ready document, so each device traces back to one order reference.
NIST SP 800-88 Rev.2 for media sanitisation, NCSC secure sanitisation guidance, BS EN 15713 for physical destruction, and UK GDPR / Data Protection Act 2018 for the audit trail.
It is the core evidence, but not the only one. Together with the Waste Transfer Note and chain-of-custody records, it demonstrates that personal data has been destroyed and provides the audit trail regulators and auditors expect.
Yes. Download a sample Certificate of Destruction PDF to see the full certificate layout, fields, and serialisation before you commit to a project.
We lead with paperwork, not promises. Every registration below is independently checkable, and every project is delivered against recognised UK standards.
| Credential | Reference | Issued / recognised by | What it proves |
|---|---|---|---|
| Waste Carrier Registration | CBDU351026 | Environment Agency | Legal authority to transport and carry controlled waste and end-of-life IT across the UK. |
| WEEE Treatment Exemption (T11) | EXP/UP3043JD | Environment Agency | Authorised to treat waste electrical and electronic equipment for reuse and recycling. |
| ICO Data Protection Registration | ZB787416 | Information Commissioner's Office | Registered to process personal data in line with UK GDPR and the Data Protection Act 2018. |
| Cyber Essentials | Certified | IASME (NCSC scheme) | Independently verified baseline cyber-security controls protecting your data while in our custody. |
| ADR 1.3 Dangerous Goods Awareness (Driver Training) | Certified | EcoStar (Dangerous Goods Training Online) | Collection drivers are trained to handle and transport equipment containing lithium batteries (UN3481, Class 9) in line with ADR dangerous goods rules. |
Standards we work to
We can supply our registrations, insurance certificates, and sample destruction outputs as part of your supplier due diligence.
Certified erasure or physical destruction with one serial-linked Certificate of Destruction per Chain-of-Custody order — from £10 per drive or £495 per 100 loose drives.