19°C

clear sky

TFL Updates
London Daily News

Hard drive shredding services: How to decide between on-site and off-site destruction

Partner Content
Hard drive shredding services: How to decide between on-site and off-site destruction

A colocation contract ends on the last day of the quarter. There are 1,400 drives sitting on four pallets in a caged area off the loading bay, most of them pulled from arrays that held customer records, and the security team has asked a single question: does somebody from our side need to be standing there when they get shredded?

That question can shape the whole project. It affects the budget, the schedule, the transport arrangements, whether the drives leave the building intact, and what the audit file looks like later when somebody asks for evidence.

It is also a question that teams can answer with instinct rather than analysis. Instinct says watch it happen. But witnessing is only one control in the wider disposal process, and it does not by itself prove that every asset was accounted for or that the destruction process met the required standard.

The stakes are real enough to justify the analysis. IBM’s 2026 Cost of a Data Breach Report puts the global average cost of a data breach at US$4.99 million, a record high in its research. That is a global benchmark rather than a UK hard-drive disposal figure, but it illustrates why organisations need to treat retired storage media as part of their wider information-security controls.

For a UK organisation, the regulatory picture is also different from the one often used in US-focused data-destruction articles. Where personal data is involved, the UK GDPR and Data Protection Act 2018 are relevant. The ICO also sets requirements around controllers, processors and contractual arrangements. NCSC guidance addresses secure sanitisation and disposal of storage media, while BS EN 15713:2023 provides a UK/European industry standard covering the secure destruction of confidential and sensitive material. Where the media has become waste, environmental and waste-management requirements also come into play.

What follows is the decision framework I use, built around the operational trade-offs that actually differ between the two models rather than around how the machines work.

The Question Behind the Question: Where Does Your Risk Transfer?

Strip away the marketing on both sides, and there is one structural difference between on-site and off-site hard-drive destruction. It is the point at which intact media moves from your direct physical control into another stage of the disposal process.

With on-site destruction, that point largely stays on your property. The drives can remain under your control until they are fed into the destruction equipment. There is no separate transport journey carrying intact drives to a third-party destruction facility.

With off-site destruction, the drives are collected and transported to another location before destruction. That introduces an additional custody period during which the media remains intact.

That does not automatically make off-site destruction less secure.

The relevant question is how that custody period is controlled and documented. BS EN 15713:2023 covers collection, storage, transportation, destruction methods and certification for confidential and sensitive material, and its scope includes hard drives and other data-bearing media.

Where personal data is involved, the UK GDPR also matters. If a destruction provider is acting as a processor, the ICO says there must be a written contract containing required provisions, including appropriate security measures, controls around sub-processors, end-of-contract provisions and audit and inspection arrangements.

That means outsourcing the physical destruction does not remove the organisation’s need to assess and control the supplier.

Here is the part teams tend to miss. Moving custody does not make the organisation’s data-protection obligations disappear. If a provider is processing personal data on the organisation’s behalf, the controller still needs appropriate contractual and oversight arrangements. The ICO specifically says processor contracts must include provisions covering security, sub-processors, deletion or return of personal data and audits.

Read those requirements alongside the physical-security standards and you get the actual rule of thumb. The location of the shredder is only one part of the control environment. What matters is whether you selected the provider properly, controlled the custody chain and can produce appropriate records afterward.

On-site destruction does not remove those responsibilities. It simply removes one physical transport stage.

What the Two Models Look Like on the Day

Short version, because the mechanics are not the interesting part of this decision.

On-site, also called mobile destruction, means a vehicle or mobile destruction unit arrives at your address. Drives are staged, identified, and fed into the destruction equipment on your premises. Your people may be able to observe the process directly, depending on the equipment and service arrangement. The resulting material then leaves the site for appropriate downstream treatment or recycling.

Off-site, also called facility destruction, means the drives are collected into secure containers, transported to a processing or destruction facility, recorded at the appropriate control point, and destroyed using fixed equipment. Documentation follows within the agreed service process.

There is a third route that belongs in this conversation even though it is not shredding. Secure sanitisation can leave the drive intact and potentially suitable for reuse.

NIST SP 800-88 Rev. 2 is the current version of NIST’s media-sanitisation guidance, published in September 2025, and supersedes Rev. 1. It provides a framework for selecting sanitisation methods based on the media and the sensitivity of the information. It is useful as a technical reference, but it is not UK legislation.

The NCSC provides UK-specific guidance on secure sanitisation and disposal of electronic storage media. For situations where physical destruction is required under its guidance, it specifies reducing the media to particles of 6mm or less and verifying the resulting particle size. It also states that, in those scenarios, the data should still be erased before destruction.

Shredding is therefore one possible disposal outcome. It is not automatically the correct outcome for every retired drive.

What Witnessing Actually Buys You

Witnessed destruction is the emotional core of the on-site pitch, so it deserves a plain assessment.

What witnessing gives you:

A named person from your organisation who can directly observe the destruction of the assets presented for processing. That can be useful evidence for an internal audit, customer requirement or contractual control where witnessing is specifically required.

A shorter physical custody chain before destruction. There is no transport leg during which intact drives are being moved from your premises to an external destruction facility.

A workable answer when a customer contract or internal policy says destruction must be witnessed. Some organisations genuinely impose that requirement. When yours does, the analysis for those particular assets may be straightforward.

What witnessing does not give you:

Better destruction. The level of destruction depends on the equipment, method and specification, not simply on whether the shredder is located at your premises. Ask the provider what particle size and destruction standard applies to the media being processed.

Independent verification. A member of your staff watching a vendor’s operator run a vendor’s machine is direct observation, not independent technical verification. It is useful, but it should not be treated as proof that every aspect of the destruction process has been independently verified.

Protection from the risk that actually causes many asset-disposal problems: incomplete inventory reconciliation. The drives that go missing may not be the ones on the truck. They may be the ones left in a desk drawer, a maintenance cupboard or a storage room. Reconciliation against an asset inventory is what identifies those gaps. A viewing port does not.

If I sound sceptical of witnessing, it is because it is easy to spend money on a visible control while leaving the less visible controls incomplete. The better approach is to identify the actual gap first and then pay for the control that closes it.

Custody and Verification: Where the Paperwork Diverges

Both models can produce a Certificate of Destruction. The certificate itself is not the control. The important question is what evidence sits behind it.

For a UK organisation, the useful record should connect the destruction event to identifiable assets and document the relevant stages of collection, custody and destruction.

BS EN 15713:2023 covers procedures and controls for the physical destruction of confidential and sensitive material, including collection, storage, transportation, destruction methods and certification.

Where a processor is involved in handling personal data, the ICO also says the contract should provide for information demonstrating compliance and allow the controller to carry out or contribute to audits and inspections.

Hold a certificate up against those requirements. A certificate without an asset-level record may confirm that a quantity of material was destroyed, but it may not give you enough evidence to reconcile that destruction against your own asset register.

The custody question splits the two models cleanly:

On-site: the physical chain can be shorter. Assets can be reconciled at your premises and recorded as they enter the destruction process. Fewer physical handovers can mean fewer opportunities for a count to drift.

Off-site: the chain has additional stages, and every one of them needs to be reconciled. What you handed over, what was collected, what arrived at the facility and what was destroyed should be capable of being reconciled. If the provider records the assets at multiple control points, that can create a richer audit trail. If the provider records them only once, ask exactly where and when that record is created.

That is the practical test to put to a vendor, and it works for either model: show me the asset-level record, tell me at which physical points it is captured, explain how discrepancies are handled, and tell me who is responsible for verification.

Providers that run both models should be able to explain how their custody and reporting controls remain consistent between them.

Big Data Supply, for example, states that it provides both on-site and off-site data destruction, serial-level Certificates of Destruction, and chain-of-custody documentation. It also states that it is R2v3 and RIOS certified and offers both data destruction and recovery or resale of qualifying IT assets. Those are vendor claims, so they should be checked against the provider’s current certification scope and service documentation before being relied upon in a procurement decision.

The commercially useful detail is what happens to drives that do not need physical destruction. A provider that can separate assets for secure sanitisation, destruction and recovery can potentially change the economics of the project.

Throughput, and What It Does to Your Calendar

This is the trade-off that gets ignored in the security discussion and then dominates the project.

A mobile shredder is a machine that fits on or in a vehicle. Its practical throughput is constrained by the equipment, operator, available staging area, access to the site and the amount of time allocated to the job.

A fixed facility can operate dedicated industrial equipment and may be able to process larger volumes without tying the equipment to one customer’s site.

The scheduling consequences follow directly:

On-site work is a scheduled event. You get a window. Everything must be staged, reconciled and ready before the vehicle arrives because the service is tied to the vehicle, operator and agreed site time. Under-preparation can create additional cost or delay.

Off-site work is a pipeline. Containers can be collected as racks come down, transported and processed according to an agreed schedule. Nobody in your organisation necessarily needs to be available for a destruction event on a particular day.

A phased decommission that runs over several weeks can fit the pipeline model naturally. A single-day building exit with a landlord waiting for keys can favour the event model.

Multi-site programmes change the logic. Mobilising a destruction vehicle to nine offices, several of which hold only a small number of drives, introduces additional travel and scheduling requirements. Consolidating material through a controlled collection process may be more practical.

That does not mean off-site is automatically better for every distributed estate. The collection route, security requirements, volumes and provider network still need to be considered.

Cost per Drive Does Not Tell the Whole Story

I am going to be careful here, because published per-drive pricing in this market is thin and largely vendor-supplied. There is no reliable universal price threshold at which on-site becomes cheaper than off-site.

What follows is the cost structure rather than a claim about a fixed market price.

On-site pricing can include a mobilisation or call-out charge covering the vehicle, operator and travel, plus a processing or per-drive rate. The mobilisation element means the effective cost per drive can be high when only a small number of drives are processed.

Off-site pricing can include collection, secure containers, transport, processing and per-drive or weight-based charges, depending on the provider and material.

The practical shape of the comparison is therefore:

Small quantities, single location, on-site: the mobilisation component can dominate the bill.

Large quantities, single location, on-site: the mobilisation cost is spread across more drives, potentially making the model more competitive.

Multiple locations, off-site: consolidation can reduce the need for repeated mobile visits, although collection and transport costs still need to be included.

Anything where a portion of the fleet still has resale value: separate those assets from the destruction stream and assess whether secure sanitisation and recovery are appropriate.

Ask for the components separately when you get a quote. A single blended per-drive number for on-site work can hide the mobilisation charge and make comparison difficult.

The Value You Destroy by Destroying Everything

The default decommission plan is “shred everything, it is simpler.”

Simpler, yes. It is also a decision to give up any residual value in the equipment.

NCSC guidance recognises that sanitisation can allow storage media to be reused, while physical destruction may be appropriate where a higher level of protection is required.

NIST SP 800-88 Rev. 2 likewise treats media sanitisation as a process that should be selected according to the information and media involved rather than assuming physical destruction is necessary for every device.

Destruction may therefore be appropriate where the media cannot be reliably sanitised, where the organisation’s risk assessment or policy requires physical destruction, or where the media is unsuitable for reuse.

The relevant point for this decision is that secure sanitisation and physical destruction are different processes. A healthy drive that can be appropriately sanitised may retain reuse or resale value. A failed drive that cannot be reliably sanitised may need a destructive route.

That is a legitimate distinction. It should be a deliberate one.

Putting It Together: A Working Decision Framework

Decision factor On-site (mobile) Off-site (facility)
Risk transfer point Destruction takes place at your premises Intact media is transported to the receiving facility before destruction
Witnessed by your staff Usually possible, depending on the service Normally evidenced through provider records, reporting or agreed controls
Cost driver Mobilisation, vehicle/operator time and processing Collection, transport and processing
Economical at Can make sense for larger volumes at one site or where on-site destruction is specifically required Can make sense for phased programmes, multiple sites or facility-based processing
Throughput ceiling Constrained by mobile equipment, operator and site time Dedicated facility equipment can provide greater processing capacity
Custody record Potentially shorter physical chain Longer chain with additional handover and intake points
Value recovery Destruction removes resale value from the destroyed assets Facility model can more easily combine destruction with sanitisation and recovery workflows
UK industry reference BS EN 15713:2023 BS EN 15713:2023
Waste controls Relevant when the material is waste Relevant to collection, transport, storage and treatment of waste
Best fit Fixed-site deadlines, specific contractual or policy requirements, or situations where removing the transport stage is important Phased decommissions, distributed estates, larger programmes and mixed fleets

Work through it in this order:

Check for a mandate first. If a customer contract or your own information-security policy requires witnessed destruction for a particular class of media, apply that requirement to the assets it actually covers. Do not assume UK data-protection law itself generally requires witnessed destruction. The legal requirements are broader and focus on appropriate security, accountability and contractual controls.

Reconcile your inventory before you price anything. You cannot make a rational choice about a fleet you have not counted, and the reconciliation exercise is where missing or unidentified drives can turn up.

Segment the fleet. Failed or unsuitable media may require destruction. Healthy drives may be candidates for secure sanitisation and reuse where the risk assessment and policy allow it. Do not treat every retired drive as automatically destined for the shredder.

Price the destruction portion both ways, with the mobilisation charge broken out. For off-site work, include collection, transport and any container or processing charges.

Apply the same evidence standard to whichever model you choose. Asset-level record, documented method, custody information, verification where applicable and a clear Certificate of Destruction. If a vendor cannot provide adequate evidence on-site, being in the room did not solve the underlying documentation problem.

Check the waste-management arrangements. Once the media is waste, the organisation also needs to consider the applicable waste rules and ensure that waste is transferred to appropriately authorised parties. In England and Wales, the waste duty of care requires reasonable steps to prevent unauthorised treatment or disposal and to ensure waste is transferred only to appropriately authorised parties.

For England specifically, the Environment Agency’s RPS 309 addresses the storage and shredding of electronic data-storage media containing confidential or sensitive material for data-security purposes. The current position statement applies to storing and shredding up to 5 tonnes of electronic data-storage media at any one site in any 12-month period. It covers fixed and mobile equipment but is subject to specific conditions, including requirements concerning the shredded output, record keeping and notification to the Environment Agency. It is not a blanket exemption from environmental permitting requirements.

Most programmes should therefore be assessed asset by asset and site by site. A mobile shredder may make sense for particular assets or deadlines, while a controlled facility route may make more sense for other assets, particularly where secure sanitisation and recovery are also part of the programme.

Where This Usually Lands

The on-site versus off-site question gets framed as a security question, and framed that way it is too simple. Both models can be controlled properly, and neither becomes secure merely because the shredder is located at your premises.

For a UK organisation, the decision sits across information security, data protection, physical custody, operations, waste management and asset recovery.

You are choosing where intact media remains under your direct control, how much custody you are prepared to outsource, how much throughput you need, how much of your fleet still has value, and what evidence you will need to produce later when nobody involved in the project remembers exactly what happened.

Answer those questions, and the truck-or-plant decision becomes much easier.

Get the inventory reconciliation right first, because every other control in the chain assumes you know what you had.


Feature image by Markus Spiske from Pexels 

Pin It on Pinterest