A data-bearing device (DBD) is any asset that stores data - laptop, phone, drive, copier, firewall - and must be sanitised to a clear, purge, or destroy level, with per-serial evidence, before disposal.
A data-bearing device - shortened to DBD, or data-bearing asset (DBA) on disposal manifests and vendor quotes - is any piece of equipment that stores data, from a laptop, phone, or server to an office copier or a firewall, and therefore needs secure sanitisation or physical destruction before it is sold, donated, returned at end of lease, or recycled. The category exists because disposal is where data protection most often fails: an asset can leave the building looking like harmless e-waste while customer records, credentials, and company files are still perfectly readable on it.
The term matters operationally, not academically. It is the flag that decides whether a retired item can go straight to a recycler or has to pass through sanitisation, evidence, and a documented handover first. Get the flag wrong at purchase and you will get the disposal wrong three years later.
What you will learn
- What counts as a data-bearing device
- Data-bearing vs non-data-bearing: classifying by device class
- The data-bearing devices people forget
- Why the label matters
- Clear, purge, destroy: the NIST 800-88 sanitisation levels
- Which method actually works on which media
- Evidence: erasure certificates, destruction certificates, and chain of custody
- Who is accountable, and what the rules require
- Where data-bearing disposal usually goes wrong
- Tracking data-bearing devices from purchase to certificate
- A short data-bearing device disposal checklist
- FAQ
What counts as a data-bearing device
The obvious members are laptops, desktops, smartphones, tablets, servers, and loose storage: hard drives, SSDs, USB sticks, memory cards, and backup tapes. Those are the items every IT team already knows to wipe. The ones that catch organisations out are less obvious:
- Printers and copiers - most office multifunction devices have an internal drive that retains scanned, printed, and faxed documents.
- Networking equipment - routers, switches, and firewalls hold configurations, credentials, VPN keys, and sometimes an internal flash or CompactFlash card.
- Desk phones and meeting-room kit - call logs, directories, and stored account sign-ins.
- Smart screens and TVs - paired accounts and saved Wi-Fi credentials, unlike plain monitors, which generally store nothing.
- Drives left inside other equipment - the classic failure is a desktop sent for recycling with its drive still fitted.
“Data-bearing media” is the narrower phrase for the storage itself - the platters, the flash chips, the tape - as opposed to the chassis around it. The distinction is useful because sanitisation acts on the media, while your asset record usually tracks the device. When the two part company, as when a drive is pulled from a server and destroyed separately, both need their own line in the evidence.
Data-bearing vs non-data-bearing: classifying by device class
Decide at the device class, not the individual item. Every laptop is data-bearing; every patch cable is not. Arguing it out per item at the point of disposal is how mistakes get made, usually under time pressure and usually by whoever is standing next to the skip. Three practical buckets cover almost everything:
- Always data-bearing - computers, phones, tablets, servers, storage arrays, loose drives and cards, backup tape, copiers, network and security appliances, point-of-sale terminals.
- Sometimes data-bearing - depends on model or configuration. Smart displays, projectors and conferencing bars, docking stations with firmware storage, label printers, handheld scanners, some test and measurement instruments. Check the model once, write the answer down, and reuse it.
- Never data-bearing - cables, adapters, plain monitors, keyboards and mice without onboard memory, furniture, most passive kit.
The place for that decision is a field on the asset record, set when the item is booked in, not a judgement call at end of life. A data-bearing flag on the asset register is the single cheapest control on this whole page: it turns a retirement into a routed process instead of a question. Non-data-bearing equipment can leave under normal recycling rules. Data-bearing equipment cannot leave until it has been sanitised and evidenced.
The data-bearing devices people forget
This is where most real incidents come from - storage buried inside equipment nobody thinks of as a computer. A short, unglamorous list worth walking your own estate against:
- Inside servers and racks: RAID controllers and their battery-backed cache modules, TPM and HSM cards, NVDIMMs, IO-accelerator and PCIe/NVMe cards, boot microSD or internal SATA-DOM modules, and the SAN or NAS shelves behind them.
- Network and security appliances: firewalls and load balancers with internal CompactFlash, wireless LAN controllers, VPN concentrators, out-of-band management cards.
- Payment and access hardware: card terminals holding transaction logs and stored credentials, SIM and smart chip cards, electronic door locks, and the controllers behind access cards and key fobs.
- Cameras and recording kit: security cameras and their NVRs, body cameras, dashcams, and drones with SD cards still fitted.
- Media: LTO and DLT backup tape, optical discs, and legacy formats still sitting in an archive box.
- Non-IT equipment: vehicle infotainment and telematics units holding paired phones and address history, diagnostic and medical devices with patient data, building-management and HVAC controllers, digital signage players.
The pattern behind the list is organisational, not technical. This equipment is very often disposed of by facilities, finance, a fleet manager, or a landlord’s clearance contractor - people who had no reason to think of it as IT and no route into the ITAD process. Naming these classes in your disposal policy, and telling the teams that actually hold them, closes more risk than any tooling change.
Why the label matters
Marking an asset as data-bearing changes its disposal path. Non-data equipment can go straight to a recycler under normal e-waste rules. Data-bearing equipment must first be sanitised - and the organisation must be able to show it was. Under the WEEE Directive the recycling obligation is the same either way; the data obligation is extra, and it sits with you, not the recycler.
It also changes the route earlier in life. A data-bearing device that goes out for repair, gets loaned to a contractor, or is reassigned between departments carries its data with it, which is why asset decommissioning and reassignment deserve the same care as final disposal.
Clear, purge, destroy: the NIST 800-88 sanitisation levels
The reference nearly every auditor and disposal vendor works from is NIST Special Publication 800-88, Guidelines for Media Sanitization. It defines sanitisation as rendering data recovery infeasible for a given level of effort, and sets three escalating levels:
- Clear - logical techniques such as a full overwrite or a device reset that defeat simple, non-invasive recovery using standard system tools. Appropriate for low-classification data on media staying inside the organisation.
- Purge - techniques that make recovery infeasible even with laboratory equipment: firmware sanitize and secure-erase commands, verified cryptographic erase, or degaussing of magnetic media. The usual bar for anything leaving your control while still working.
- Destroy - the media can no longer store data at all: shredding, disintegration, incineration, or melting. Ends the asset’s residual value, so it is reserved for high-classification data or media that cannot be reliably purged.
Revision 2 of the guideline was published on 26 September 2025 and changed the shape of the document: it now focuses on running a media sanitisation policy and programme, and defers the per-media technical detail to IEEE 2883-2022, Standard for Sanitizing Storage. IEEE 2883.1-2025 sits alongside it as a recommended practice for choosing and applying those methods before reuse, resale, or disposal. In practice you cite 800-88 for the level and IEEE 2883 for the technique.
Which level you need comes from two questions: how the data on the device is classified, and what happens to the device next. Reuse inside the same trust boundary can often stop at clear; resale, donation, or return to a leasing company needs purge; the most sensitive material, or any media whose sanitisation cannot be verified, goes to destroy. Our fuller walkthrough of the process lives in data sanitization.
Which method actually works on which media
The single most common technical error on this topic is treating overwrite, crypto erase, and destruction as interchangeable. They are not, and what works on a spinning disk can be useless on flash.
| Media | Works | Does not work |
|---|---|---|
| Hard disk drive (HDD) | Full multi-pass overwrite; degaussing; shredding for high classification | Quick format; deleting partitions |
| SSD, NVMe, eMMC, USB, memory card | The drive’s own sanitize / secure-erase command; verified crypto erase; shredding to a small particle size | Ordinary overwrite tools; degaussing |
| Self-encrypting drive | Crypto erase (key destruction), verified and logged | Assuming encryption was on without checking |
| Phones and tablets | Factory reset on a device encrypted from first use, plus account and MDM release | Reset on an older unencrypted handset; leaving the SIM or eSIM in place |
| Backup tape, optical, legacy media | Physical destruction; degaussing for magnetic tape | Overwriting a tape you cannot verify |
| Copiers, appliances, embedded storage | Remove the drive or module and treat it as loose media; vendor sanitisation routine where documented | Returning the unit “as is” at end of lease |
Two warnings are worth spelling out. Overwrite is unreliable on flash: wear levelling and over-provisioning keep spare blocks out of reach of ordinary write commands, so data can survive a wipe that reports success. Use the device’s built-in sanitize command instead. And degaussing does nothing to an SSD - it disrupts magnetic fields, and flash memory stores charge, not magnetism. A degaussed SSD is an intact SSD.
Cryptographic erase only counts as a purge when three conditions hold: encryption was active from the drive’s very first write, the algorithm and key length are still considered strong, and the key destruction can be verified. It is not a rescue for a drive that spent three years unencrypted and was switched on last week. And to restate the point from the FAQ below: a factory reset or a format is not, by itself, sanitisation.
Evidence: erasure certificates, destruction certificates, and chain of custody
Sanitisation you cannot prove is, from an auditor’s point of view, sanitisation that did not happen. Two artefacts carry the proof, and they are not the same document.
A certificate of erasure covers logical sanitisation on a device that survives - it is what you get back when a laptop is wiped for resale, donation, or refurbishment. A certificate of destruction covers media that was physically destroyed. Both should be issued per serial number and should state the method applied, the standard and level (for example purge to NIST 800-88 using the drive’s sanitize command), the date, the operator or facility, and a device identifier you can match to your own records. “We sent a pallet to the recycler” is not evidence; “serial 5CD123 was purged on this date by this operator to this standard” is.
Chain of custody is the second half. It is the documented, unbroken record of who held each device between the desk it left and the shredder or the wipe bench, and it is what turns a certificate into something believable. A workable manifest records a unique identifier per item, the releasing and receiving party at each transfer, timestamps, and the condition or seal number of the container. Three checkpoints matter most: intake (the item is identified and logged as it leaves your control), transit (sealed, counted, and signed for), and destination (received count reconciled against the manifest before any processing). See chain of custody and custody log for the mechanics.
Two practical choices follow. On-site witnessed destruction removes the transit gap entirely, at higher cost - worth it for the most sensitive media, overkill for a batch of old monitors. And verification sampling of logically sanitised media, where a proportion of wiped drives is checked for recoverable data, is a normal thing to require of a vendor and a reasonable thing to do yourself.
Who is accountable, and what the rules require
Under the GDPR the controller stays accountable for personal data on hardware it failed to sanitise. Outsourcing disposal transfers the work, not the liability - and the accountability principle means it is not enough to have done the right thing, you must be able to demonstrate it. That single sentence is why per-serial certificates and custody records exist at all. In practice it also means diligence on the vendor: a written contract covering sanitisation standard and evidence, and a look at their certifications. Buyers commonly shortlist against R2v3, e-Stewards, NAID AAA, or ADISA; none is a legal requirement, and none removes your own duty to check the evidence that comes back.
If you run an ISO 27001 information security management system, the relevant Annex A controls cover secure disposal or reuse of equipment and the deletion of information - which is to say, the standard already expects the process described on this page, written down and evidenced. See ISO 27001 asset management for how that maps onto an asset register. WEEE, meanwhile, is a separate and parallel duty: it governs the recycling of the electrical equipment itself and says nothing about the data on it.
One question almost nobody answers: how long to keep the destruction evidence. Treat it like any other compliance record and set the period deliberately in your data retention policy. The realistic floor is long enough to answer a regulator’s question or a subject access request about a device you no longer hold, which for most organisations means keeping it well beyond the asset’s own life - and keeping it attached to the retired asset record rather than in a vendor’s portal you may lose access to.
Where data-bearing disposal usually goes wrong
- Deletion treated as erasure. Emptying a recycle bin or formatting a volume removes pointers, not data.
- The drive is still in it. A desktop or server sent out with its disks fitted, or a laptop that went for repair and never came back.
- Copier returned at end of lease untouched. The leasing company collects, the internal drive goes with it, and years of scanned documents leave the building on a truck.
- “Decommissioned” with no matching certificate. The register says retired, no evidence is attached, and the audit trail has a permanent hole exactly where the proof should be.
- Pallet-level paperwork. One certificate for a collection of forty devices, with no serial numbers, proves nothing about any individual device.
- Remote leavers. A device that never comes back at all is the modern version of this problem - see employee offboarding and hardware recovery for how to close that loop.
- Someone else disposed of it. Facilities clearing a floor, finance scrapping a fleet vehicle with its infotainment unit, a landlord’s contractor emptying a room - IT never informed.
- The drawer. Spare drives, old phones, and USB sticks that were never on the register in the first place, so nothing will ever flag them for disposal.
Tracking data-bearing devices from purchase to certificate
You cannot wipe what you cannot find, so the work starts long before disposal.
At goods-in, capture the serial number and set the data-bearing flag while the box is still open. Retrofitting that flag across an existing estate is a project; setting it at purchase is a checkbox.
In service, keep owner and location current through checkouts, returns, transfers, and offboarding, so that when a device goes missing you know whose data was on it - which is the question a breach assessment actually turns on, and one an IT department is usually asked under time pressure.
Periodically, run a physical inventory count. This is what surfaces the drawer of old phones, the cupboard of retired laptops, and the external drives nobody has thought about since a project ended.
At end of life, set the status to retired, attach the erasure or destruction certificate to the asset record itself, and let the audit trail hold the chain permanently. The point of attaching rather than filing is that the proof and the asset stay together for as long as either exists.
In AMPthilly, that maps onto ordinary product behaviour: a register record per asset with its serial number and a custom field for the data-bearing flag, checkouts and transfers that keep the current owner accurate, onboarding and offboarding templates so returns are a step someone owns, printable QR labels that open the asset in a phone browser during a count, a retired status, certificates attached as documents, and a filterable audit history you can export to CSV when an auditor asks.
A short data-bearing device disposal checklist
Method-neutral and vendor-neutral, short enough to lift straight into a policy:
- Identify and flag the item as data-bearing, using the device-class rule rather than a fresh argument.
- Classify the data on it, because the classification sets the sanitisation level.
- Decide the outcome - reuse, resale or donation, or destruction - since that decides erasure versus destruction.
- Revoke accounts, licences, and enrolments: account locks, MDM, certificates, SIM or eSIM, stored credentials on appliances.
- Sanitise to the right level, or remove the media and destroy it separately where the device cannot be sanitised in place.
- Capture per-serial evidence - certificate of erasure or destruction, naming method, standard, date, and operator - and the custody record behind it.
- Record the disposal against the asset, set the status to retired, attach the certificate, and close the record.
- Release the shell to a WEEE-compliant recycler under the normal e-waste route.
FAQ
Is a printer a data-bearing device?
Usually, yes. Most office multifunction printers and copiers contain an internal hard drive or flash storage that retains copies of scanned, printed, and faxed documents - sometimes years of them. Before one is sold, returned at end of lease, or recycled, that storage should be wiped or removed and destroyed, exactly as you would treat a laptop drive.
Is deleting files enough before disposing of a device?
No. Deleting files or formatting a drive removes the index entries, not the underlying data, which standard recovery tools can often reconstruct. Putting data properly beyond reach means a full overwrite with wiping software, cryptographic erasure where the device supports it, or physical destruction of the storage media - and a record of which method was used on which serial number.
What happens if a data-bearing device leaves without being wiped?
You have a potential data breach, not just a lost asset. Customer records, credentials, emails, and company files may be readable by whoever ends up with the device, and under data-protection rules such as GDPR the organisation remains accountable for personal data on hardware it failed to sanitise. This is why disposal needs serial-level records, not a skip and good intentions.
What does DBD stand for in IT asset disposal?
DBD stands for data-bearing device, and DBA for data-bearing asset. You will see both on disposal quotes, collection manifests, and destruction certificates, usually to separate items that need sanitising from plain recycling. They mean the same thing: equipment that holds data and must be dealt with before the shell is scrapped or resold.
Is a factory reset enough to wipe a phone or tablet before disposal?
On a modern handset that has been encrypted since first use, a factory reset destroys the encryption key and behaves much like a cryptographic erase. It is still not evidence. Confirm the device was encrypted, remove it from any account lock and mobile device management, handle the SIM or eSIM separately, and record the reset against the serial number. On older or unencrypted devices a reset is not sanitisation.
What is the difference between data erasure and data destruction?
Erasure is a logical process that overwrites or cryptographically invalidates the data while leaving the hardware usable, so the device can be reused, resold, or donated - evidenced by a certificate of erasure. Destruction physically renders the media incapable of storing data by shredding, disintegration, or melting, and is evidenced by a certificate of destruction. Erasure preserves value; destruction ends it.
Is a monitor a data-bearing device?
A plain monitor is not - it displays an image and stores nothing you would care about. Smart displays, conferencing screens, and monitors with built-in KVM switching or user-configurable firmware storage can be, because they may hold paired accounts, Wi-Fi credentials, or saved settings. Check the model once, record the answer, and treat the whole class consistently after that.
Are routers, switches, and firewalls data-bearing devices?
Yes, and they are among the most overlooked. Network kit stores running and saved configurations, local accounts and password hashes, SNMP strings, VPN keys and certificates, and log data - and some models add an internal flash or CompactFlash card. Reset the configuration to factory defaults, remove or destroy any removable storage, and evidence it like any other device.
Does NIST 800-88 apply outside the United States?
It is a US federal guideline, not EU or UK law, so nothing legally binds a European organisation to it. In practice it is the reference almost every disposal vendor and auditor uses, and citing a level from it is the clearest way to describe what you did. GDPR and ISO 27001 ask you to demonstrate the outcome was effective rather than to name a particular standard, so 800-88 and IEEE 2883 are how you evidence that, not a substitute for it.
Tools that make this easier
The hard part of data-bearing disposal is not the wiping - it is knowing what you have, who has it, and where the certificate ended up. AMPthilly gives each device one register record with its serial number, supplier, owner, location, and a custom field you can use as the data-bearing flag. Checkouts, returns, and transfers keep the current holder accurate; onboarding and offboarding templates make sure a leaver’s kit is actually chased; printable QR labels open an asset in any phone browser during a physical count, with no app to install. At end of life, set the status to retired and attach the erasure or destruction certificate to the record, where the audit history keeps the whole chain and exports to CSV for an auditor. The free plan covers 3 users and 25 assets with no card required.
The takeaway
A data-bearing device is any asset that stores data, and the label is an operational routing decision rather than a definition to memorise. Classify by device class at purchase and flag it on the record; go looking for the hidden storage in appliances, copiers, terminals, cameras, and vehicles that facilities or finance may dispose of without telling you; pick a sanitisation level - clear, purge, or destroy - from the data classification and the device’s next destination, using the method that actually works on that media rather than the one that is convenient. Then prove it, per serial number, with an erasure or destruction certificate and an unbroken custody record attached to the asset. The organisation stays accountable whatever the recycler does, so the evidence is the deliverable.
Related terms
- Data Sanitization - the process that puts data on a device beyond recovery
- Certificate of Destruction - the vendor document proving a device or drive was destroyed
- Chain of Custody - the unbroken record of who held a device on its way to disposal
- ITAD - the wider IT asset disposition process this sits inside
- Asset Decommissioning - retiring an asset cleanly from service
- Data Retention Policy - how long you keep the destruction evidence itself
- E-Waste - the disposal stream data-bearing devices enter once sanitised
- WEEE Directive - the EU rules governing electrical equipment disposal
- Audit Trail - the logged history that evidences each device’s disposal
- Physical Inventory Count - the check that finds forgotten devices before they leak