Blog — Data Recovery and Cybersecurity
Technical analyses, prevention tips and data recovery news from the experts at SOS Data Recovery, Swiss laboratory since 2006.
How to Properly Erase Your Data Before Reselling or Discarding Hardware
Deleting a file, emptying the recycle bin or running a quick format only makes the index that points to your data disappear: the data itself remains physically present, and a simple free piece of software is often enough to restore it. In other words, everything a laboratory knows how to recover, a curious or ill-intentioned buyer can recover too. Before you resell or discard a computer, a phone, a drive or a USB stick, you must therefore either genuinely overwrite the entire medium or physically destroy it. The right choice depends on the type of medium.
What follows details, case by case, how to truly erase your data, and why a discarded medium is never as anonymous as people believe.
A discarded medium does not disappear
People readily imagine that a drive dropped off at the recycling centre goes straight to the shredder. The reality is more winding. Before it may eventually be destroyed, a medium passes through several hands, transits through companies that sort and dismantle, and nothing stops someone from spotting a still-recent drive and seeing it as an opportunity for resale. There it is, back on sale on a platform such as Anibis or Ricardo, with your data still on board.
The principle is simple and admits no exception: as long as the data has not been physically destroyed or genuinely overwritten, it remains accessible. A "discarded" drive is not an erased drive. This is why the question of erasure arises just as much for a medium you resell as for one you scrap.
What is not enough
Many people believe they have cleaned everything up when all they have done is tidy the surface. Three actions in particular give a false sense of security.
Deleting files and emptying the recycle bin does not touch the data itself. A simple, or quick, format does barely better: it overwrites the allocation table, that index which says where the files are, but leaves the content intact on the disk. With suitable recovery software, one then easily brings back a good portion of the data. Finally, resetting a PC guarantees nothing as long as you are not certain that every sector has indeed been overwritten.
In other words, these operations are fine for freeing up space or starting afresh on a clean system, but not for protecting your data before a third party gets hold of the medium.
Truly erasing, medium by medium
The right method depends on what you want to sell. Here are the most common cases.
| Medium | To resell it | To destroy it |
|---|---|---|
| Laptop | Remove the M.2 SSD, or overwrite every sector | Drill through the memory chips (after dismantling) |
| Hard drive | Overwrite every sector (zeros or random) | Sledgehammer blows to the platters |
| Phone | Factory reset (regenerates the encryption keys) | Dismantle and drill through the memory chips |
| SSD, USB stick | Full overwrite, or better, do not resell | Drill through the memory chips (after dismantling) |
| Magnetic tape | Degausser | Pull out the tape and cut it into pieces |
| CD, DVD | Do not resell | Break physically |
For a laptop, the safest solution is to remove the M.2 SSD and sell the device without it. You may as well keep that SSD at home, where it can serve as an additional backup. If you must nonetheless sell the drive, use suitable software that overwrites every sector, from the first to the last, with random characters or zeros. The medium is then genuinely wiped clean, but you must afterwards reinstall the entire operating system.
For a phone, you need to boot into the specific modes that allow a complete factory reset. A smartphone's data is encrypted in the memory chips, using electronic components and software keys. The factory reset resets these software keys, which makes access to the old data impossible, even if it physically persists, for want of a key to decrypt it.
For a magnetic tape, the resale value is low, and the wisest course is often not to sell it. If you insist, the only effective solution is a pass through the degausser, a device that erases data by means of an intense magnetic field. In our laboratory, ours works with two large perpendicular magnets: capacitors charge for about fifteen seconds, then deliver their energy into the magnets to magnetically erase the entire content of the tape. The tape is then ready to be initialised anew by a drive.
For a CD or a DVD, resale is of no interest: to get rid of it, break it physically.
Destroying physically, without injuring yourself
When a medium heads to the recycling centre or is no longer reliable, physical destruction remains the safest method. Each medium has its own technique.
A magnetic tape is unwound and cut into several pieces. A hard drive is neutralised by sledgehammer blows to the platters, to shatter them. A phone, an SSD or a USB stick are dismantled, and one drills through their memory chips.
A warning is called for here, because this action can be dangerous. Never drill through a phone without first having dismantled it and located, by eye, the motherboard and the chip to be drilled. If you drill at random, you risk piercing the battery and starting a fire. This precaution applies equally to SSDs and USB sticks. Drill, yes, but after seeing what you are drilling.
Encryption helps, but does not remove the need to destroy
An encrypted medium gives a real sense of security, and that is partly justified. A drive protected by BitLocker, FileVault or a phone's native encryption is not readable without the key. Many conclude that encryption is enough.
That overlooks one link. With BitLocker, for example, the recovery key is backed up to the user's Microsoft account. If someone manages to obtain both the drive and access to that recovery key, they can access the content. Encryption is therefore excellent protection day to day, but to have real peace of mind when parting with a sensitive medium, nothing replaces physical destruction.
Businesses: an obligation, not an option
For a business, erasing properly is not merely a reflex of caution, it is an obligation. The revised Data Protection Act (nLPD) in Switzerland, like the GDPR, require the controlled destruction of personal data, whether customer files, HR data or health data. This destruction can be accompanied by certificates attesting to the means employed, degaussing energies or shredders, and specialised companies do nothing else.
One example shows how far the chain can break, even among professionals. About fifteen years ago, we bought lots of several hundred kilograms of hard drives in bulk. These drives came from a French administration and were supposed to be destroyed. The reseller had evidently not followed the procedure through to the end: on examining them, we found that all the data was still accessible. We then did the work ourselves, fully formatting the still-functional media and physically destroying the rest. Official data, destined for destruction, thus ended up in outside hands, for want of a chain respected from end to end.
One should moreover keep one thing in mind: a medium that no longer works is not thereby unreadable. It can be repaired by a laboratory, especially if its content is valuable and of interest, for example, to a foreign state actor. For genuinely sensitive data, physical destruction is not an excessive precaution.
Frequently asked questions
Is a format enough to erase a drive before selling it?
No. A quick format only overwrites the allocation table; the data remains on the disk and can be restored with software. To truly erase, you must overwrite every sector (with zeros or random characters) using suitable software, or remove and keep the drive.
How do you truly erase an SSD or a USB stick?
By fully overwriting the medium with a suitable tool, or, safer still, by not reselling it. In case of doubt or with a medium at the end of its life, physical destruction of the memory chips remains the most reliable solution.
Does a factory reset really erase a phone?
Yes, on an encrypted phone. A factory reset regenerates the software encryption keys: even if the data physically persists in memory, it becomes unreadable for want of a key. That is why it is effective on modern smartphones.
How do you destroy a hard drive or a phone safely?
A hard drive is broken by sledgehammer blows to the platters; a phone, an SSD or a stick are dismantled and then drilled through at the memory chips. Caution: never drill through a device without having dismantled it and located the chip, or you risk piercing the battery and starting a fire.
Is BitLocker encryption enough before reselling a drive?
No, not on its own. BitLocker protects well day to day, but the recovery key is stored on the Microsoft account; anyone who obtains the drive and that key can access the data. For a sensitive medium, physical destruction remains the surest guarantee.
Must a business prove the destruction of its data?
Yes. The revised Data Protection Act (nLPD) in Switzerland and the GDPR require the controlled destruction of personal data (customers, HR, health). Destruction can be attested by a certificate specifying the means employed, and specialised providers, or a laboratory, can handle it.