Data Erasure vs Data Destruction: Which Standard Fits Your Business
Data erasure and simply wiping a drive aren't automatically the same thing. Two international standards determine when data erasure is demonstrably irreversible, and which one applies to your equipment.
Data erasure sounds like a simple step: run a quick format and you're done. In practice, that's often exactly where it goes wrong.
A factory reset, formatting a drive, or deleting files all do one thing: they make data invisible to an everyday user. They do not make data unrecoverable for anyone searching with the right tools.
Correct data erasure requires a method that closes that gap, and that method is set out in two international standards.

NIST 800-88: data erasure on working storage media
NIST 800-88 is the international reference for data erasure on hard drives, SSDs and other storage media. The standard covers several levels (clear, purge, destroy), depending on how sensitive the data is and how high the risk of the device is assessed to be. For the vast majority of business equipment (smartphones, laptops, tablets, servers) this is the standard that applies as long as the storage medium still functions. Erasing data this way also preserves the residual value of the device.
DIN 66399: when data erasure isn't enough
DIN 66399 covers the other case: physical destruction, such as shredding, when erasure isn't possible or isn't sufficient, for example with a faulty device or when the sensitivity of the data requires it. The standard sets exact particle sizes per security level, so that destruction itself also remains measurable and verifiable.
The difference with NIST 800-88 is fundamental: destruction preserves no residual value, and is therefore only the right choice when data erasure through wiping is no longer an option.
Why "erased" is not proof of correct data erasure
A factory reset, a quick format, or manually deleting files gives the impression that the data is gone. For anyone searching with the right tools, that's often not the case. This distinction is exactly what GDPR's requirements around data erasure rest on: an organisation must not only erase data, but also be able to demonstrate that this happened irreversibly and in line with a recognised standard.
Data erasure at Brainscape: the right standard for every project
At Brainscape, we determine per project which standard applies to data erasure: NIST 800-88 when the device still holds value for reuse, DIN 66399 when physical destruction is the only responsible option. Every project is closed with a certificate per device, so your organisation doesn't just know that erasure took place, but can also show how.
Wondering which standard applies to your equipment? Get in touch with Brainscape for a tailored data erasure project.
Sources:
NIST Special Publication 800-88 Rev. 1, "Guidelines for Media Sanitization" — NIST Computer Security Resource Center
Frequently asked questions
What's the difference between data erasure and data destruction?
Data erasure means data is irreversibly overwritten while the device itself remains usable. Data destruction means the device itself is physically destroyed, along with everything stored on it.
Is a factory reset enough for data erasure?
No. A factory reset or formatting a drive makes data invisible to an everyday user, but not unrecoverable for anyone searching with specialised tools.
Which standard applies to data erasure for business equipment?
For working storage media such as hard drives, SSDs and smartphones, that's usually NIST 800-88. The standard sets the level of erasure based on the risk of the data and the device.
When is data destruction needed instead of data erasure?
When erasure isn't possible, for example with a faulty device, or when the sensitivity of the data requires physical destruction. DIN 66399 sets out how that destruction must take place.
Is a certificate required for data erasure under GDPR?
GDPR requires an organisation to be able to demonstrate that personal data has been erased correctly and irreversibly. A certificate per device is the standard way to prove this during an audit.