Last updated:

30th December 2024

See answers to previous information requests

How to search

  • Select a year and/or a month from the drop down list
  • Type a subject into the 'Subject keyword(s):' search (Optional)
  • Click 'Search' button
     

Alternatively click 'View' to browse through all received requests. 

This search is for our information requests from September 2020 onward. 

Software Based Data Destruction Assurance

Request ID
21280
Date Received
Date Resolved
Details

See notes

Resolution
See notes
Notes
Date

Under the Freedom of Information Act 2000, please provide the following recorded information held by your department regarding assurance processes for software based data erasure of end of life IT equipment. For clarity, this request relates solely to software based data destruction. Please exclude physical destruction methods such as shredding, crushing, degaussing or disintegration.

1. Please confirm whether departmental policy, contractual terms or internal procedures require an explicit outcome based warranty or guarantee confirming that personal data has been rendered irretrievable through software based erasure, whether carried out internally or by an external provider.
Confirmed. All data sanitization is carried out to ISO27001 standards.

2. Where software based data destruction is performed internally, what recorded evidential assurance does the department rely upon to conclude that the final data state is irretrievable?
Not Applicable

3. Where software based data destruction is performed by a third party provider, does the department hold recorded information demonstrating that any warranty or assurance provided explicitly extends to the software erasure method used and its claimed effectiveness? If so, please confirm the recorded nature of that verification.
We hold Certificates of Data Destruction (COD) provided by third party. All data sanitization is carried out to ISO27001 standards.

4. Where no explicit outcome based warranty is required or provided, what recorded form of evidential assurance does the department rely upon to conclude that software based erasure has rendered personal data irretrievable?
Not Applicable

Give website feedback