Financial services

Banks, insurers and payment companies retire devices that hold customer and transaction data. Auditors and supervisors expect a documented, verifiable disposal process.

What is asked

The GDPR applies to customer data, and financial institutions are also supervised on their information security and IT risk management. Card data falls under PCI DSS, which requires secure deletion of cardholder data that is no longer needed. Institutions with US activities meet the Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA), which requires procedures for the secure disposal of customer information.

What these frameworks have in common: a written procedure, a method that fits the media, and evidence per device.

Wiping or destroying

Overwriting software is suitable when devices are reused. When a device leaves the organisation for good, many institutions choose physical destruction, often after degaussing hard drives. For SSDs and phones, a shredder or the PD-5E with SSD-1E applies.

IRONCLAD records each item with serial number, operator, witness, result and photo, and exports certificates and spreadsheets for your audit file.

Need a verifiable disposal process?

We help you combine destruction and verification in one workflow.