Disposing of Old Computers Securely: the Data Destruction and e-Waste Guide

TL;DR: Deleting and formatting do not destroy data; recovery tools bring it back. The right method follows the disk type: overwrite-based secure wipe on mechanical disks, the manufacturer's secure-erase command on SSDs, key destruction on encrypted disks — and certified physical destruction as the definitive answer. A destruction record is kept per device (data-protection law expects it), and the chassis goes to a licensed e-waste channel.
Almost every office has the same corner: stacked old towers, laptops waiting in drawers, disks kept "just in case". That corner is not innocent clutter — those disks hold customer lists, proposals, HR files, saved passwords. A computer sold second-hand, given to the scrap dealer or thrown away changes hands together with its data; studies extracting company data from second-hand disks have repeated the same picture for years. A device's exit is as much a process as its purchase, and the process is called secure destruction.
Why "We Deleted It, We Formatted It" Is Not Enough
The operating system's delete removes the file's index entry, not the file — the book stays on the shelf; only the library card is torn up. Quick formatting likewise resets the table of contents; the data sits on the disk until new data overwrites it, and returns even with free recovery tools. The "but it was ancient, it wouldn't even boot" defence fails too: the disk from a computer that will not boot reads perfectly well in another chassis.
The Right Method per Disk Type
| Situation | Correct method | Note |
|---|---|---|
| Mechanical disk (HDD) | Overwrite-based secure wipe | At least one full pass over the entire disk; keep the tool's report |
| SSD / NVMe | The manufacturer's secure-erase command | Classic overwriting gives no guarantee on SSDs; the right tool is essential |
| Encrypted disk (BitLocker etc.) | Cryptographic erasure: destroy the key + reset | A fleet encrypted from day one reduces destruction to minutes |
| Failed/unreadable disk | Physical destruction | A disk that cannot be wiped leaves broken |
| Highly sensitive data | Certified physical destruction (shredder) | Take the serial-numbered certificate from the destruction firm |
The practical rule: a disk that will be reused is securely wiped; a disk that will not is physically destroyed. In every case of doubt, physical destruction is cheap and final — a disk's scrap value bears no comparison to the risk its data carries.
Not Just Computers: the Forgotten Data Carriers
- Copiers and printers: most corporate printers hold storage with scanned/printed jobs; clean it before return or sale.
- Phones and tablets: remove corporate accounts, then factory-reset; on modern devices, encryption makes the reset effectively cryptographic erasure.
- NAS units, external disks, USB sticks: the most forgotten group — especially disks that took a backup years ago and have waited in a drawer since.
- Network devices: firewall and router configurations (VPN keys, passwords) are wiped before any device leaves.
The Compliance Dimension: Destruction Is a Record-Keeping Job
Under data-protection law, deletion and destruction of personal data follow the retention-and-destruction policy and must run on the record. The practical form: a destruction log showing which device, on which date, by which method — with the destruction firm's serial-numbered certificate attached where certified destruction was used. In an audit or a data incident, the answer to "what happened to those old computers?" comes out of a folder.
The Chassis's Journey: e-Waste and Donation
The device whose data is destroyed does not go in the bin; electronic waste carries heavy metals and is handed to licensed e-waste firms, with the handover certificate filed. For working devices, donation is a fine alternative — still valuable to schools and charities — but donation's precondition is the same: a clean install over a securely wiped disk, and company licences separated from the device. "Giving it away with everything on it" is a data leak performed with good intentions.
Bind the Process to Policy
Rather than chasing devices one by one, make disposal the standard final step of the asset lifecycle: when the refresh policy retires a device, it automatically enters the "migrate data → destroy → certify → e-waste/donate → strike from inventory" line. The store-room corner never forms; every device's story closes with a record.
Yamanlar Bilişim's Disposal Service
For customers under a maintenance agreement, device retirement is a packaged process: data moved to the new device and verified, destruction applied per disk type, a destruction record issued per device, chassis delivered to the licensed e-waste channel, inventory updated. In high-sensitivity scenarios we work with certified physical-destruction firms and file the certificates into your compliance folder.
FAQ
Frequently Asked Questions
Is drilling the disk enough?
A single hole leaves most of the platters readable; it is no obstacle to a determined attacker. Amateur physical destruction, if attempted, must compromise the platters comprehensively; at corporate level the right answer is a certified destruction service using a shredder.
We want to recover value by selling the computers second-hand — is that safe?
With proper wiping, yes: a reported overwrite on mechanical disks, or the manufacturer's secure-erase on SSDs, followed by a clean install — then sell. The risk is not the sale; it is the "we formatted it, that's enough" assumption.
We have no idea what is on disks that have sat for years — must we examine them all?
No, and it is rarely economic. The practical approach: old disks of unknown content are presumed to hold sensitive data and go straight to the destruction line. Examination is reserved for disks suspected of archive value.
What about leased devices being returned?
Pre-return secure wiping is your responsibility — "the leasing company will surely wipe it" leaves your data to someone else's mercy. In fleets used encrypted, this is minutes of key destruction in practice; note "data destruction performed by us" on the return record.
What should we obtain for the e-waste handover?
A handover/recycling certificate from the licensed firm listing the devices. It is proof of both the environmental obligation and the inventory write-off; file it in the same folder as the destruction records.
Author
Serdar YAMAN
Yamanlar Bilişim Expert
Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.
Professional Support
Get help on this topic
Let's design the Compliance and Data Protection solution you need together. Our experts get back to you within 1 business day.
support@yamanlarbilisim.com · Response time: 1 business day
Keep Reading
Related Articles

Turkey's KVKK and Cross-Border Data Transfers: a Cloud Reality Check
If your company email or files are hosted in a data centre outside Turkey, the KVKK's cross-border transfer rules apply to you. The standard-contract regime introduced in 2024, the cloud service inventory, and the concrete IT-side steps — in plain language.

NIS2 and Turkish Suppliers: What Will Your EU Customer Ask of You?
Europe's NIS2 directive obliges in-scope companies to secure their supply chains too. Turkish SMBs selling into the EU are now receiving security questionnaires and contract clauses — here is what will be asked, and how to be ready before it arrives.

A Free DLP Start with Microsoft 365 and Google Workspace's Built-In Rules
Data loss prevention is assumed to be an expensive enterprise product; yet the office suite most SMBs already pay for ships with built-in DLP rules. Stop ID numbers, IBANs and card numbers leaking out by email with a three-stage plan — watch first, then warn, block last.