Secure Destruction: Proving You Deleted What You Said You Would — Herarx Blog

Secure Destruction: Proving You Deleted What You Said You Would

Deleting records on schedule is half the job. The other half is being able to prove it: what was destroyed, when, how, under which rule and by whom.

March 11, 2025
Secure Destruction: Proving You Deleted What You Said You Would
Back to blog

A retention schedule promises that records will be destroyed when their time is up. Sooner or later someone asks you to prove that promise was kept: an auditor, a client, a person exercising their privacy rights, or opposing counsel asking why a document no longer exists. The answer is a destruction record: a short, permanent entry that says what was destroyed, when, how, on whose authority and under which rule. The records go; the proof stays.

What a destruction record contains

  • What: a description precise enough to identify the records without reproducing their content. "Client file 2017-042, 3 boxes" or "Recruitment records, unsuccessful candidates, Q1 last year".
  • Why: the retention rule that applied and the date it expired.
  • Who approved it: the named person who checked that no reason to keep it remained.
  • How: shredding, pulping, secure deletion, overwrite, physical destruction of media.
  • When and by whom: the date and the person or contractor who carried it out.
  • Evidence: a certificate of destruction from the contractor, or a system log for digital deletion.

Notice what is missing: the content. A destruction log that quotes the data it destroyed defeats its own purpose.

The check before destruction

Before anything is destroyed, someone confirms that no reason to keep it has appeared since the retention date was set. The common reasons: a dispute or claim that is live or likely, a regulator's or court's request, an open access request, or a related matter still running. If any applies, the records are held and the hold is recorded. Build this check into the process rather than relying on memory; see the retention schedule template for how review dates are set in the first place.

Paper: certificates and chain of custody

If you use a shredding contractor, you are handing sensitive material to a third party, so treat it as a transfer. Record which boxes or bags left, when, and who collected them; keep the collection receipt; and get a certificate of destruction that references them. Locked consoles in the office are only as secure as their collection routine. Cross-cut shredding in-house is fine for small volumes, provided the person doing it records the batch.

Digital: harder than it looks

Pressing delete rarely destroys anything immediately. Copies live in backups, sync folders, email attachments, downloads folders and recycle bins. A realistic approach:

  1. Delete from the system of record, and let any trash or recovery period run out, or empty it deliberately.
  2. Know how long backups are kept, and note that the data will age out of them by a given date rather than pretending it is gone today.
  3. Search for obvious copies: shared drives, email, personal devices.
  4. For retired hardware, use proper wiping or physical destruction of the drive, and keep the certificate.

Be honest in the record: "deleted from the case system on 12 March; will expire from backups by 11 June" is more credible than a claim of instant, total erasure.

Make it routine

Destruction done once a year in a panic tends to be sloppy. Tie it to a regular review, such as the year-end records clean-up, work through what has fallen due, and file each destruction record in a permanent register. The register is small, contains no personal data beyond names of staff, and can be kept indefinitely. It is the one record you never destroy.