Over 68.34 million tons of electronic waste were generated worldwide in 2022. Every day, consumers and businesses stop using desktops, laptops, smartphones, and tablets and tuck them away in closets, drawers, or storage areas until it’s time to find them a new home or send them for recycling.
Your first step is to restore the device using a factory reset. You click the button, wait for the progress bar to reach 100%, and the device reboots. The welcome screen appears. The factory reset is done.
For many, a factory reset seems to be the best option for removing data before the device goes to a new user. Selling items on sites like eBay or Facebook Marketplace, donating to a local charity, or giving away for free seems easy, but it’s incredibly risky.
A simple factory reset isn’t the same as data destruction. It’s certainly not enough to protect you from potential loss or theft of your private data.
Deleted Data Isn’t Truly Gone
Factory resets are not enough because of the way storage drives work. They contain two parts.
- Data Blocks/Stacks: Also known as a physical record, a data block is a block of space where files are stored.
- File Table/Index: A master file table or index maintained by the drive. It keeps track of which data block a file (applications, documents, PDF, photos, etc.) is stored in.
When you move a file to the trash or execute a standard factory reset, the operating system doesn’t wipe physical data blocks clean. It takes too much time and power to do so. Instead, the OS deletes the file table and opens those data blocks up for future use.
Until new data replaces what was in the data blocks, the data is still out there. A person with the right tools and knowledge could scan the drive, skip the missing index, and combine the information into a readable document.
Aren’t Solid-State Drives (SSDs) and Flash Storage Safer?
While many older devices used hard disk drives (HDDs), most devices now use flash storage and SSDs instead of magnetic storage techniques. Both don’t work as HDDs did, but they still have vulnerabilities and aren’t completely safe.
SSDs use a process known as wear leveling to store files. With both that and flash memory, data is stored evenly across the storage chips to help them last.
Eventually, the data degrades, but there’s no specific pattern to the data storage. Plus, there are blocks saved for maintenance, and those blocks could contain personally identifiable information (PII) and sensitive personally identifiable information (SPII).
When you do a factory reset, those hidden maintenance areas aren’t always included in the wipe. This can leave some data behind for someone with hardware-level read tools to retrieve.
Cryptographic Erasure and Its Potential Flaws
Many of today’s encrypted laptops and smartphones perform factory resets that are different than in the past. They use cryptographic erasure. When completing a factory reset, the OS deletes the cryptographic key that’s stored in a secure area of the device. Without that key, the data becomes unreadable.
While this process is better at destroying access to data, it does have potential flaws.
- Flawed Implementation: Bugs in the firmware or software-based encryption implementation leave unencrypted data behind.
- Flawed Key Management: If an encryption key was backed up in a cloud account or IT server, any data on a factory reset laptop is still vulnerable. If a hacker accesses the encryption key from the cloud or IT server, the data can be retrieved.
- Weak Encryption: If the laptop or server used a default password or weak encryption, there’s a chance that an attacker will retrieve the master key.
NIST SP 800-88 Rev. 1 Is the Gold Standard for Data Destruction
True data destruction for consumers and companies involves the NIST SP 800-88 Rev. 1 protocol. These “Guidelines for Media Sanitization” provide clear steps for protecting data security. It covers three tiers of data destruction.
- Clear: Best for internal reuse
- Purge: Best for external resale
- Destroy: Best for recycling
Tier 1: Clear
When you plan to reuse the electronic device in another department or give it to another person in your household, Clear is the best protocol to follow. It involves overwriting sensitive data with random strings of 0s and 1s. Eventually, the data is covered with so much non-sensitive data that the old data is impossible to retrieve.
Tier 2: Purge
If you plan to donate or resell your electronics, Purge is the right option. It uses advanced techniques like low-level hardware commands or cryptographic erasure to eliminate the possibility of data recovery.
Tier 3: Destroy
Finally, if you cannot boot a laptop or know a device is only good for recycling, physical destruction is essential. It occurs by placing the item in specialized cross-cutting shredders that chop the device into tiny pieces. Those pieces are separated by glass, metal, and plastic and used to make new materials.
The Cost of Weak Data Destruction Processes
Clear, Purge, or Destroy protects your company or household from costly cases of identity theft. There’s more reason for a business owner to be very careful with data destruction. It comes down to state and federal laws.
If a consumer loses access to private photos or files like tax returns, the risk of identity theft is great. It’s worse if a U.S. business uses a factory reset over data destruction methods. You risk damage to your public reputation at the very least. Regulatory fines and lawsuits are other costs.
Most businesses must abide by the formal media sanitization outlined in specific regulatory frameworks like these:
- FACTA/FATCA Disposal Rule: Consumer report data handled by any business must be burned, overwritten, or pulverized.
- FTC Safeguards Rule: Secure data disposal of customer information must take place within two years of the last use. Applies to auto dealers, financial institutions, and lenders.
- HIPAA Security Rule: Electronic protected health information (ePHI) must be cleared, purged, or destroyed by all health care providers and their covered entities.
There are also state privacy laws that you need to follow. For example, California’s CCPA/CPRA provide consumers with the right to hold businesses liable for data breaches resulting from discarded, non-sanitized hardware. This means that if your data is breached because a California business opted to do a factory reset instead of a data destruction method, they’re negligent.
End-of-Usable-Life Management: A Practical Checklist for Businesses and Consumers
Before you give away, sell, or recycle any of your electronic devices, make sure you follow the steps on this checklist.
- Keep Records: Inventory what you’re planning to sell, donate, give away, or recycle. Keep a list of model numbers, serial numbers, and manufacturer.
- Wipe or Erase Data: Perform a disk wipe or cryptographic erase using drive-wiping tools that follow NIST SP 800-88 standards. If you cannot manage it on your own, choose an ITAD specialist to help you.
- Physically Destroy: If you’re unable to power up a device to wipe the data, physical destruction is essential. Remove the case and take a hammer to the hard drive or purchase a recycling box from a certified ITAD provider like ERI.
- Get Proof: Businesses need a Certificate of Destruction to protect them in the future. This is irrefutable proof that you followed regulations.
Data Destruction Is the First Step to Responsible End-of-Life Management
While factory resets are convenient, they’re not enough. You need to move to verified sanitization standards. Businesses must work with ITAD partners that provide you with certificates of destruction for each device. It’s the best way to protect your, your employees, your customers, and your shareholders’ PII and SPII.
ERI is the partner you need when it comes to retiring unused electronics. Not only do we provide data destruction services, but we also refurbish items when possible and recycle the rest. We do everything we can to support the circular economy and lessen the impact on the environment and the people in it.