Compliant erasure of electronic lost property
Recording and maintaining the safe custody of electronic lost property (ELP) is a responsibility that comes with significant overheads.
Not least of which is the obligation to ensure the secure disposal of data bearing devices that remain unclaimed after mandated holding periods.
Items handed into or recovered by operators or their representatives must be stored for a minimum of one month or a maximum of three months, in accordance with corresponding regulations such as;
The British Airports Authority (Lost Property) Regulations 1972
The London Transport (Lost Property) (Amendment) Regulations 1978
The Public Service Vehicles (Lost Property (Amendment) Regulations 1995
This means that deploying specialist certified erasure services can no longer be overlooked because:
Responsibility for data privacy compliance rests with both the Data Controller and the Data Processor.
Contractual obligations relating to the sanitisation of personal data & PII present on equipment earmarked for redeployment or retirement should be documented.
End-to-end transparency via an audit trail is required throughout the process of retirement for reuse and/or recycling of faulty/damaged and redundant data bearing assets.
1
2
3
3
Hard reset is not traditionally regarded as a reliable method of proving that data has been successfully removed from device memory.
Erasure via Mobile Device Management (MDM) software does not provide the evidential audit trail that is delivered as standard by purpose built certified data erasure software.
It is no longer deemed acceptable to leave old data bearing equipment in storage to be disposed of ‘at a later date’ or be donated to a local charity due to data security risks. Nor is automatic device destruction given the environmental implications.
1
2
Ready Set Recycle ensures full compliance with current EU and UK data privacy regulations with comprehensive audit reports detailing:
-
Manufacturer ID
-
Model Name
-
IMEI/Serial Number
-
Device Lock Status
-
Legal Status
-
Erasure Method, Duration & Outcome
-
Time & Date of Erasure
-
Physical Condition
Governance, risk & compliance
We take no chances with personal data and we cut no corners.
We use erasure platforms that are ADISA certified and compliant with mission-critical data privacy and data protection regulations and standards, including UK Data Protection Act 2018, NIST and current GDPR stipulations. This helps ensure that personal and sensitive data never reaches the wrong hands.
Only in the event of an unsatisfactory attempt to erase recoverable data from a device is it processed for secure disposal, where it is shredded and broken down to its core materials for reuse.
Abandoned electronic devices can be easily compromised by those intent on exploiting them
Failure to ensure the safe & reliable erasure of personal and business data represents a risk of data breach.
Traditional recycling approaches to data deletion such as ‘hard reset’ do not reliably remove personal information from a device.
More importantly, these methods do not present the evidential audit trail required to prove that data has been sanitised beyond forensic recovery - a crucial part of the lost property management process.
Forensic recovery & identity theft
Commercially available forensic software makes it possible for miscreants to easily recover the digital footprints of original device owners, in the event that data has not been properly sanitised as part of the disposal process. We take no chances with personal data and we cut no corners, as the implications of not doing so can be far-reaching.
Data erasure
In today’s governance, risk, and compliance climate, it is essential for ALL custodians of electronic lost property to ensure demonstrable, secure, and reliable erasure of personal and business data, and PII (Personally Identifiable Information).
Contact us
Contact us today to discuss how we can help, organise a Client Portal demonstration or arrange a FREE* collection.
* Minimum quantity of 10 electronic items for FREE pick up. Book before 10am Monday-Friday for same working day collection. Collections booked after 10am will be scheduled for pick up the following day (Monday-Friday 8am-6pm)