Physical destruction of data and media, with custody and records
When the policy says 'destroy, no reuse', there is no middle ground: the media must die — and its death needs a record. Ecobraz physically destroys HDDs, SSDs, tapes and media with chain of custody through to destruction and per-media records, and consigns the residues with documentation.
If your safe tells this story, it is time to close it out
Is even one item on this list true for you? Then this page was written for you — describe your situation in one minute and get a technical reply, not a sales call.
- There is a room or safe piling up HDDs 'to be destroyed one day' — and that day never comes
- The security policy requires physical destruction, no exception and no reuse
- The audit asked for evidence of destruction per media and there is only a generic declaration
- Failed or encrypted media that will not accept sanitisation
- The previous supplier took whole disks away — and no one saw how they ended
Media kept 'to destroy later' is risk in storage
Every month of waiting adds data to the liability — and the blind link of transport can be worse than the wait.
The safe that became a liability
Years of accumulated disks are years of sensitive data in a single point of failure. A loss there is not an incident — it is an entire history exposed.
Real cost: an event with the potential to affect data from every accumulated year — and the LGPD does not expire with shelf time.The blind link: the media that travels whole
A supplier that takes the disk intact to 'destroy later' creates the perfect window for loss. Between your door and the shredder, you are the one answerable.
Real cost: a chain of custody broken at exactly the most vulnerable stretch — and indefensible in an audit.A generic declaration is not evidence
'We certify the destruction of a batch of media' does not answer the auditor's question: which media? The evidence must be traceable to the unit.
Real cost: an audit finding and rework to reconstruct a history that should have been complete from the start.From a full safe to a closed liability
Destruction becomes a documented event — not a promise.
How it is today
- Media piling up for years 'awaiting a decision'
- Disks leaving whole with third parties
- A generic declaration in place of evidence
- No one can say how many media items exist
- Compliance repeating the same question each cycle
With Ecobraz
- Inventory of the media before destruction
- Custody recorded through to destruction
- Per-media record, as per scope
- Residues consigned with applicable MTR and CDF
- The compliance question closed out in writing
What ends together with the media
A liability accumulated over years leaves the map in a single operation.
Emptied safe
The single point of failure ceases to exist — along with the years of data that lived in it.
Evidence per unit
A traceable record per media item, in the standard that audit and compliance require.
Blind link eliminated
Custody recorded from collection to destruction — with no window for loss.
Closed loop
The residue from destruction goes on to documented consignment — nothing is left in limbo.
What is included — and what is not
Scope declared before scheduling reduces rework and surprises. Each batch is assessed technically.
In scope
- HDDs, SSDs and storage units
- Backup tapes, cards and removable media
- Damaged media or encrypted media without a key
- Disks removed from servers, ATMs and sensitive equipment
- Accumulated collections — from dozens to thousands of units
Method, execution location and level of record are defined at the assessment, according to the volume, media type and policy requirement.
Out of scope
- A need to reuse the equipment — see secure data sanitisation
- Household batteries, toner, lamps and other standard exclusions
- Chemical, biological, radioactive or contaminated waste
- Paper documents and non-electronic collections
Physical destruction and sanitisation are distinct services, each with its own methods and deliverables — this page covers definitive destruction.
How it works, from contact to final destination
No collection is confirmed without a technical assessment. That is what keeps the operation predictable and documentable.
Describe the media
Types, estimated quantity, origin and the policy or audit requirement.
Technical assessment
We define the method, execution location and the level of record required.
Scope defined
Responsibilities, custody and evidence agreed in writing.
Collection with custody
The media leaves inventoried and under a recorded chain of custody.
Destruction and consignment
Recorded destruction and consignment of the residues with documentation.
The death certificate for your media
The documentation reflects what was actually carried out in each batch — no generic promises.
Prior inventory
A list of the media before destruction — the basis of traceability.
Destruction record
Evidence of destruction per media item, as per the contracted scope.
Chain of custody
The recorded journey from your door through to destruction.
MTR and CDF
Consignment of the residues from destruction, where applicable to the material.
Consolidated report
The complete package for the operation, ready to attach to the audit.
Documented scope
Method, location and responsibilities defined before execution.
Why destroy with Ecobraz
Destruction is the service where 'almost' does not exist: either there is evidence, or there is risk.
Custody without a gap
From collection to destruction, the media stays under recorded control — the blind link of transport does not exist in our flow.
Traceable evidence
A record per media item as per scope — not a generic batch declaration.
15 years of operation
An association founded in 2011, with recognition on EU and UN platforms — scope declared on the public evidence page.
Technical precision
Destruction and sanitisation treated as distinct services — as good practice requires, with no technically imprecise offer.
What security and compliance ask
Can the destruction be carried out on my premises?
The execution location — on your premises or in a controlled environment — is defined at the technical assessment, according to volume, media type and policy requirement.
Do I receive evidence per media item?
Yes, as per scope: the media is inventoried beforehand and the destruction is recorded in a traceable way — the exact format of the record is agreed when the scope is defined.
What is the difference from sanitisation?
In sanitisation, the data dies and the media survives (reuse, return, donation). In physical destruction, media and data die together — it is the route for policies that forbid reuse and for media that will not accept sanitisation.
What happens to the destroyed material?
The residues go on to documented consignment as electronic waste, with MTR and CDF where applicable — the loop closes with proof.
Do you handle small volumes?
From a safe with dozens of disks to collections with thousands of media items — the assessment defines the logistics and the conditions for each case.
Could also be part of your operation
Secure data sanitisation
When the equipment must survive: logical erasure with a report.
View solution →ATM and banking equipment
Decommissioning with media destruction in a financial environment.
View solution →Decommissioned IT assets
Planned removal from the estate with inventory and custody.
View solution →Published basis, with a persistent identifier
This subject is developed in an original technical report by Ecobraz Emigre, published with a DOI on the open Zenodo repository.
VILLANOVA, Marcio. Risco Residual de Dados em Equipamentos Desativados: Governança de Mídias, Sanitização e Prestação de Contas. Zenodo, 2026. doi.org/10.5281/zenodo.21398306 · All publications →
How many years of data are stored in your safe right now?
Describe the media, the volume and the policy requirement. The team replies with method, custody and the evidence model — in writing.