Data sanitisation for HDDs and SSDs: how to do it with documented assurance

Documented data sanitisation of HDDs and SSDs permanently removes information and helps prevent leaks, with methods varying by device type.

What is data sanitisation?

Data sanitisation is an essential process for protecting the information stored on devices such as HDDs (hard disk drives) and SSDs (solid-state drives). The procedure permanently removes all data, preventing recovery and misuse.

Why documented sanitisation matters

Confirming that data has been completely removed requires methods that follow recognised protocols. Documented sanitisation provides a formal record attesting that the information was erased, which supports data-protection requirements and helps reduce the risk of leaks. Such records support the accountability obligations under the LGPD, but they are not conclusive proof before any regulator.

Differences between HDDs and SSDs in sanitisation

HDDs traditionally use magnetic techniques to write data, whereas SSDs operate through flash memory. These differences have a direct impact on the sanitisation methods used:

  • HDDs: can be handled through magnetic overwriting, encryption or physical destruction;
  • SSDs: require specific procedures because of their memory architecture and block wear, such as ATA Secure Erase commands and secure physical destruction.

Recognised methods for sanitising HDDs

Several established methods support the effective sanitisation of HDDs:

  • Multiple overwriting: filling the disk with random data several times to erase the original information;
  • Degaussing: using magnetic fields to destroy the data held on the disk;
  • Physical destruction: shredding or crushing the disk so that the data cannot be recovered.

These methods should be carried out by trained personnel to support their effectiveness and the issuing of the corresponding records.

Recognised methods for sanitising SSDs

For SSDs, the most suitable methods are:

  • ATA Secure Erase: an internal command that fully erases all data on the SSD;
  • Full encryption followed by destruction of the key: rendering the data inaccessible;
  • Physical destruction: shredding or pulverising the device to prevent recovery.

The validity of the process also depends on issuing a record documenting how the procedure was carried out.

Step by step for documented sanitisation

  1. Identify the type of device (HDD or SSD) in order to choose the appropriate method.
  2. Choose methods aligned with international standards, such as NIST 800-88, or applicable national standards.
  3. Use suitable tools and equipment to carry out the sanitisation.
  4. Request a record documenting the removal of the data.
  5. Store and manage the documentation for audits and legal compliance.

Relevant standards and regulations

Several standards address data sanitisation, notably:

  • NIST 800-88: guidance from the US National Institute of Standards and Technology on secure data disposal;
  • LGPD: Brazil's General Data Protection Law, which requires rigorous care in the handling and disposal of personal information;
  • ISO/IEC 27040: an international standard for information security and the protection of stored data.

Conclusion

Sanitising the data held on HDDs and SSDs with documented assurance is fundamental to protecting sensitive information, reducing legal risk and supporting compliance with security standards. Adopting methods suited to each type of device and securing the corresponding records are indispensable steps towards secure and responsible management of stored data.

Informative content. Classifications, obligations, documents and operating conditions should be confirmed according to the material, the location and the applicable legislation.