Skip to main content
Chain of Custody

A hard drive can ultimately be securely erased or destroyed. But what happened to it in the hours or days leading up to that? Where was it stored? Who had access to it? And at what point did the data processing partner take over responsibility for the data destruction?

When it comes to secure data destruction, it is not just the end result that counts. The process that a laptop, server or data storage device goes through beforehand must also be properly monitored.

This is where the Chain of Custody comes into play.

What is a Chain of Custody? 

A Chain of Custody is the traceable path that IT equipment and data storage media follow during their processing.

The principle is simple: points of transfer, responsibilities and the processing operations carried out must be clearly documented.

This reduces the risk of data storage media disappearing or becoming accessible to unauthorised persons during storage, transport or processing.

A Chain of Custody is therefore more than just administration. It is part of a controlled process for data security.

Why is a Chain of Custody important?

A great deal of attention is paid to the technique used to ultimately delete data. However, risks can arise even before the data is actually destroyed.

Consider, for example, laptops left unattended in storage or a box of hard drives where it is unclear when and to whom they were handed over. Even if these data carriers are subsequently processed correctly, there may have been a period beforehand during which controls were inadequate.

A sound Chain of Custody minimises this risk by establishing clear agreements regarding handover, transport, access, processing and responsibility.

When does a data processor assume responsibility?

Not every organisation has the same security requirements. That is why not every process needs to follow the same procedure.

For example, an organisation may choose to carry out the data erasure itself before the equipment is handed over. Another option is for Out of Use to carry out the data erasure once the equipment has been received at the processing centre.

Organisations wishing to exercise greater control during transport can opt for a process whereby Out of Use assumes responsibility for data destruction from the moment the equipment leaves the customer’s premises, for example via sealed transport.

For sensitive environments, data destruction can also take place directly at the customer’s premises. In such cases, the data storage media do not need to leave the premises before the data has been processed.

It is important that it is clearly agreed in advance who assumes which responsibilities, from what point in time, and what security measures are involved.

Traceability must be verifiable

A controlled process is important, but it must also be possible to demonstrate afterwards what happened to the equipment.

Reporting and a certificate of destruction can help with this. Where more detail is required, devices or data storage media can be indexed. Serial numbers are then linked to the report, so that individual devices or data storage media can be identified.

For IT managers, security teams and DPOs, this provides valuable documentation of the processing carried out.

The right approach depends on the risk

A sound Chain of Custody does not mean that every organisation must automatically opt for the most stringent security measures.

The correct approach depends on the sensitivity of the data, internal procedures, the type of equipment and the desired level of control. This principle is also in line with the risk-based approach of both the GDPR and current guidelines on secure data erasure, such as NIST SP 800-88 Rev. 2.

Out of Use tailors the process to the organisation’s security requirements and internal procedures. This enables clear agreements to be made regarding the handover, transport, data destruction and reporting.

Would you like to find out more about Out of Use’s Chain of Custody approach? Please get in touch for a no-obligation consultation.

Stay up to date

Subscribe and receive our latest news in your mailbox.