FOI Release: Software Based Data Destruction Assurance
Published: 16 March 2026Freedom of information class: How we manage our resources
Information request under the Freedom of Information (Scotland) Act 2002 (FOISA).
FOI reference: CW-2026-102
Date received: 12 February 2026
Date responded: 11 March 2026
Information requested:
Please provide the following recorded information held by your department regarding assurance processes for software-based data erasure of end-of-life IT equipment.
For clarity, this request relates solely to software-based data destruction.
Please exclude physical destruction methods such as shredding, crushing, degaussing or disintegration.
- Please confirm whether departmental policy, contractual terms or internal procedures require an explicit outcome-based warranty or guarantee confirming that personal data has been rendered irretrievable through software-based erasure, whether carried out internally or by an external provider.
- Where software-based data destruction is performed internally, what recorded evidential assurance does the department rely upon to conclude that the final data state is irretrievable?
- Where software-based data destruction is performed by a third-party provider, does the department hold recorded information demonstrating that any warranty or assurance provided explicitly extends to the software erasure method used and its claimed effectiveness? If so, please confirm the recorded nature of that verification.
- Where no explicit outcome-based warranty is required or provided, what recorded form of evidential assurance does the department rely upon to conclude that software-based erasure has rendered personal data irretrievable?
I am not requesting technical configuration detail, security sensitive information or supplier specific vulnerabilities. I am seeking confirmation of the assurance model relied upon for software-based data destruction.
Response:
The answers to your questions are as follows:
- There is no requirement in departmental policy, contractual terms, or internal procedures for an explicit outcome-based warranty or guarantee confirming that personal data has been rendered irretrievable following software-based erasure. Assurance is obtained through compliance with recognised standards and certification requirements, rather than through an explicit warranty or guarantee. We require activities to be carried out by a supplier certified under the NCSC Commodity Information Assurance scheme and ISO27001, and in accordance with the NCSC guidance on Secure Sanitisation and Disposal of Storage Media.
- Data destruction is not carried out internally.
- The department does not hold recorded information demonstrating that an explicit warranty or guarantee extends to the effectiveness of the specific software-based erasure method used or its claimed effectiveness. Where a third-party supplier is used, the department retains supplier provided data erasure or destruction reports as evidence of compliance with relevant standards, rather than an outcome-based warranty or guarantee. These reports evidence that erasure activities have been completed in line with the relevant standards and certification requirements. Storage media that cannot be erased in an assured manner are physically destroyed.
- N/A
Find out more
Read more about our FOI releases.
Contact
If you have a question or query about FOI requests, you can email the information governance team at: FOI.Requests@ros.gov.uk.
