Our office has around 50 retired desktop hard drives that once held confidential client information and internal files. Some coworkers have suggested buying equipment to physically destroy the drives, while others would rather hire a reputable e-waste or data-destruction company. The priority is making the data genuinely unrecoverable without creating a burdensome process or taking on unnecessary liability. For a batch this size, would secure erasure, physical destruction, or both be the best approach? Is DIY destruction practical, and are certificates of destruction worth getting?
5 Answers
Don’t automatically destroy reusable equipment if the data can be securely erased and the drives are still useful. For ordinary confidentiality requirements, a verified erase may be enough and is more environmentally friendly. However, if the information is subject to strict client contracts, regulations, or a company retention policy, follow that policy rather than relying on informal advice. Legal, compliance, and IT should make that call.
DIY physical destruction is workable for one or two drives, but it becomes tedious and inconsistent at this scale. Opening cases, drilling through platters, or bending them is not the same as producing a documented destruction process, and it can create injuries or debris. If you choose an outside company, look for one that can destroy the drives on-site or lets you observe the process, tracks serial numbers, and provides a certificate listing what was destroyed.
Have your IT or security team decide what the company policy requires before touching anything. A common approach is to securely erase the drives first, then send them to a certified destruction provider. The wipe protects the data during transport and handling, while physical destruction provides the strongest end state and the vendor’s documentation gives you proof.
A small office probably shouldn’t buy a drive shredder for a one-time batch. Securely wiping 50 traditional hard drives can take a while, and drilling or hammering them creates safety, dust, and recycling problems without giving you much useful paperwork. If the drives are encrypted and your policy permits it, the process may be simpler, but the final choice should follow your organization’s legal, contractual, and compliance requirements.
For business drives containing client information, I’d use a reputable data-destruction vendor and require chain-of-custody documentation plus a certificate of destruction. That gives you an auditable process and shifts the physical handling to a company whose reputation depends on doing it correctly. For only a few drives, DIY can be reasonable, but 50 drives is enough that convenience, liability, and documentation matter more than saving a little money.
The certificate may sit in a filing cabinet forever, but if there is ever an audit or a data-leak investigation, having an independent destruction record can be extremely valuable.

If you do wipe them yourself, keep an inventory linking each drive to its erasure result. Don’t rely on formatting or deleting files; use a proper secure-erase tool and verify that it supports the drive type.