
Complying with the DPDP Act 2023 During Physical Storage Media Disposal
Legal and technical requirements for DPOs, CISOs, and IT security teams under the DPDP Act 2023 during corporate storage decommissioning.
Corporate data protection does not end when a computer is switched off. Hard drives, SSDs, backup tapes, USB drives, servers and other physical storage devices can continue to contain personal data long after the equipment has been removed from active use.
This creates an important responsibility for companies decommissioning IT assets: what happens to personal data when the physical storage device leaves the organisation?
India's Digital Personal Data Protection Act, 2023 (DPDP Act) establishes obligations around the processing and protection of digital personal data. The Act received presidential assent on 11 August 2023. (MeitY) The final Digital Personal Data Protection Rules, 2025 were notified by the Ministry of Electronics and Information Technology (MeitY) in November 2025, with a phased commencement schedule. (MeitY)
For organisations, this means physical IT asset disposal should increasingly be considered part of the broader data-protection and information-security lifecycle, rather than simply an e-waste activity.
Important: The DPDP Act and Rules have a phased commencement framework. Organisations should verify which provisions are in force for their specific disposal activity and date, and should not treat this article as legal advice.
What Is Physical Storage Media Disposal?
Physical storage media includes any device capable of storing digital information.
Examples include:
-
Hard disk drives
-
Solid-state drives
-
Server drives
-
External hard drives
-
USB drives
-
Memory cards
-
Backup media
-
Storage arrays
-
NAS devices
-
Certain printer storage devices
-
Older magnetic tapes
When these devices are retired, they may be:
-
Reused
-
Refurbished
-
Resold
-
Returned to a vendor
-
Donated
-
Physically destroyed
-
Sent for e-waste recycling
The important question is whether personal data remains on them when they leave the organisation's control.
What Does the DPDP Act Have to Do With E-Waste?
The DPDP Act is primarily a data-protection law, not an e-waste recycling law.
It does not prescribe a simple rule saying:
"Destroy every hard drive."
Instead, the Act places obligations on a Data Fiduciary concerning personal data it processes.
Section 8 of the Act establishes general obligations for Data Fiduciaries, including implementing appropriate technical and organisational measures and taking reasonable security safeguards to prevent personal-data breaches. It also addresses erasure when personal data is no longer required, subject to legal-retention requirements. (Indian Kanoon)
This becomes relevant to physical disposal because a retired hard drive can still contain personal data.
If the organisation gives that drive to another party without appropriately securing or erasing the information, the physical disposal process can become a data-security risk.
Understand the Difference Between Data Erasure and Hardware Disposal
These are two separate processes.
Data Erasure
This concerns making the information stored on a device inaccessible according to the organisation's approved sanitisation requirements.
Hardware Disposal
This concerns what happens to the physical device after it is retired.
For example:
Laptop → Secure data sanitisation → Refurbishment → New user
Or:
Failed SSD → Physical destruction → E-waste processing
The company should make the data-security decision before the equipment enters the normal recycling stream.
Identify Personal-Data-Bearing Assets
Not every piece of electronic waste presents the same data risk.
A damaged keyboard normally does not contain a large amount of personal data.
A laptop SSD potentially can.
Companies should therefore classify retired assets according to their data-storage capabilities.
A basic classification could be:
Category A – Data-bearing
-
Laptops
-
Desktops
-
Servers
-
SSDs
-
Hard drives
-
Backup devices
Category B – Potentially data-bearing
-
Multifunction printers
-
Network appliances
-
Smart devices
-
CCTV/NVR equipment
-
Certain access-control systems
Category C – Normally non-data-bearing
-
Keyboards
-
Mice
-
Passive cables
-
Basic monitors
The exact classification should be based on the actual equipment.
Don't Assume Deleted Files Are Gone
One of the biggest mistakes in IT asset disposal is confusing normal deletion with secure sanitisation.
Deleting files generally removes their references from the operating system.
A quick format can also leave underlying information potentially recoverable depending on the device and method used.
SSDs create additional complexity because their internal controllers use mechanisms such as wear levelling and logical-to-physical mapping.
Therefore, organisations should use an appropriate sanitisation process based on the storage technology.
Create a Formal Media Sanitisation Policy
Companies should have a written procedure explaining what happens when storage devices are retired.
The policy can define:
-
Which devices require sanitisation
-
Who approves disposal
-
Who performs sanitisation
-
Which methods are approved
-
How failed drives are handled
-
When physical destruction is required
-
How results are verified
-
What records are maintained
-
When equipment can be released to a recycler
This turns data protection from an informal IT task into a repeatable business process.
Retain Required Data Before Erasing
Data protection does not mean deleting everything immediately.
An organisation may have legal, regulatory, contractual or operational reasons to retain certain information.
Before sanitising a storage device, the responsible team should determine:
-
Is the information still required?
-
Has it been backed up?
-
Is there a retention obligation?
-
Is the device associated with an ongoing investigation?
-
Does another department need the information?
Only after the retention decision is completed should the storage media be sanitised.
Section 8 of the DPDP Act specifically recognises that erasure obligations are subject to situations where retention is necessary to comply with applicable law. (Indian Kanoon)
Security Safeguards Are Broader Than Data Wiping
The DPDP framework is not limited to deleting information.
The notified 2025 Rules provide a broader security-safeguard framework. Rule 6 includes measures such as encryption, access controls, logging and monitoring, backup arrangements and appropriate technical and organisational measures. It also requires appropriate contractual provisions with Data Processors concerning security safeguards. (DPDP Guide)
This is important because physical media disposal is only one part of the overall security lifecycle.
A company should protect data:
While in use → During storage → During transfer → During decommissioning → During final disposal
Data Processors Need Attention
Companies frequently use external vendors for IT asset disposal.
The vendor may:
-
Collect equipment
-
Transport it
-
Sanitise storage devices
-
Destroy drives
-
Refurbish equipment
-
Resell hardware
-
Recycle e-waste
Where a vendor processes personal data on behalf of the organisation, contractual and security responsibilities need to be considered.
The DPDP framework requires appropriate security provisions in contracts with Data Processors. (DPDP Guide)
Therefore, companies should not simply hand over a truckload of computers to an unknown recycler.
Choose the Disposal Partner Carefully
Before selecting an ITAD or e-waste partner, companies should evaluate:
-
Data sanitisation capability
-
Physical destruction capability
-
Asset tracking
-
Secure transportation
-
Chain of custody
-
Storage-device identification
-
E-waste processing capability
-
Applicable regulatory registrations or authorisations
-
Documentation
The organisation should understand exactly what happens after collection.
Maintain Chain of Custody
A strong disposal process should make the movement of data-bearing assets traceable.
For example:
Department
↓
IT Asset Management
↓
Secure Decommissioning
↓
Data Sanitisation
↓
Verification
↓
Secure Storage
↓
Collection
↓
ITAD/E-Waste Partner
↓
Reuse or Destruction
This allows the organisation to demonstrate that the device did not simply disappear into an uncontrolled waste stream.
Record Storage Device Identifiers
Asset-level records make the process much stronger.
For example:
| Field | Example |
|---|---|
| Asset ID | LAP-2045 |
| Device | Corporate laptop |
| Storage | NVMe SSD |
| Drive Serial | Recorded internally |
| Data Action | Approved sanitisation |
| Verification | Completed |
| Final Route | Refurbishment |
| Collection Date | Recorded internally |
For physical destruction, the record can show the destruction event and final disposition.
For large projects, batch processing can be used where the organisation can reliably reconcile the devices included in the batch.
Failed Storage Devices Need Special Treatment
A failed hard drive or SSD can create a difficult situation.
Normal sanitisation software may not be able to access the device.
The wrong response is:
"It doesn't work, so the data is gone."
A failed drive may still contain recoverable information.
If secure sanitisation cannot be reliably completed, the organisation should keep the device under controlled custody until an approved alternative, potentially physical destruction, is completed.
Certificate of Destruction Can Support Evidence
When physical destruction is used, a Certificate of Destruction (CoD) can provide useful supporting evidence.
The certificate may include:
-
Asset identifiers
-
Serial numbers
-
Quantity
-
Destruction date
-
Destruction method
-
Processing facility
-
Service provider
-
Batch number
However, a certificate is only useful when it can be connected to the actual assets.
A document saying:
"500 drives destroyed"
is much weaker than a record that identifies the 500 drives covered by the destruction event.
Sanitisation Certificates Are Different
If a working SSD is securely sanitised and then refurbished, the SSD itself has not been destroyed.
The appropriate documentation should therefore indicate data sanitisation or erasure, rather than physical destruction.
For example:
SSD → Secure Sanitisation → Verification → Refurbishment
is different from:
SSD → Physical Destruction → Recycling
The documentation should accurately describe the action performed.
Printers and Photocopiers Should Not Be Forgotten
Physical media disposal should not focus exclusively on computers.
Modern multifunction printers can contain internal storage.
Depending on the device, they may store:
-
Scanned documents
-
Print jobs
-
Address books
-
Network settings
-
Email configurations
-
User information
Before disposing of such equipment, the organisation should check its storage capabilities and follow an appropriate manufacturer-supported reset or sanitisation process.
The same principle can apply to certain:
-
CCTV systems
-
NVRs
-
Network appliances
-
Access-control systems
-
Smart displays
Secure Network Configurations
Not every network device contains large amounts of personal data, but some devices can contain sensitive corporate information.
Retired:
-
Firewalls
-
Routers
-
Network controllers
-
Security appliances
may contain credentials, IP addresses, VPN settings and network configurations.
These should be decommissioned according to the company's security procedures before the equipment leaves corporate control.
Physical Destruction Is Not Always Necessary
The goal should not be to destroy every storage device.
A working corporate laptop could potentially have several years of useful life remaining.
After appropriate sanitisation, it may be:
-
Redeployed
-
Refurbished
-
Donated
-
Resold
This is preferable to unnecessary destruction where the organisation's security requirements permit reuse.
A sensible hierarchy is:
Reuse → Refurbish → Resell/Return → Recycle
with physical destruction reserved for situations where sanitisation is not reliable or the security policy requires destruction.
Keep DPDP Compliance and E-Waste Compliance Separate
This distinction is important.
The DPDP framework addresses the protection and processing of digital personal data.
E-waste and battery regulations address the environmentally responsible handling and processing of physical waste.
A company may therefore have two separate obligations:
Data protection
→ Secure personal data before equipment leaves corporate control.
Waste management
→ Ensure obsolete electronics are routed through an appropriate recycling/disposal channel.
One does not replace the other.
What Should Security Teams Add to Their Disposal Checklist?
A practical checklist can include:
Before Disposal
-
Identify data-bearing equipment.
-
Confirm data-retention requirements.
-
Back up required information.
-
Identify storage technology.
-
Check ownership and lease arrangements.
During Decommissioning
-
Remove equipment from corporate systems.
-
Disable accounts and credentials.
-
Securely sanitise storage.
-
Physically destroy media where required.
-
Verify the sanitisation result.
Before Collection
-
Record asset and serial numbers.
-
Separate data-bearing media.
-
Secure the equipment.
-
Confirm the recycler/ITAD partner.
-
Prepare chain-of-custody documentation.
After Collection
-
Reconcile collected assets.
-
Obtain sanitisation/destruction records.
-
Obtain recycling documentation where applicable.
-
Update the asset register.
-
Retain records according to company policy.
DPDP Compliance Should Be Built Into ITAD
The strongest approach is to avoid treating data protection as an extra step added just before recycling.
Instead, build it into the complete IT asset lifecycle:
Procurement → Use → Storage → Backup → Retirement → Sanitisation → Reuse/Recycling
When the organisation knows from the beginning how a device will eventually be retired, disposal becomes much easier to control.
Conclusion
Physical storage media disposal is increasingly connected to corporate data protection.
A retired laptop, server, SSD, hard drive or multifunction printer can still contain personal data after it has been removed from everyday use. Simply formatting the device or handing it to an e-waste collector does not provide a reliable governance process.
The DPDP Act, 2023 places obligations on Data Fiduciaries around appropriate technical and organisational measures, reasonable security safeguards and erasure of personal data when applicable, subject to legal-retention requirements. (Indian Kanoon) The notified DPDP Rules, 2025 further describe reasonable security safeguards, including access controls, encryption-related measures, monitoring, backups and security provisions involving Data Processors. (DPDP Guide)
For corporate IT and security teams, the practical approach is:
Identify → Retain Required Data → Sanitise or Destroy → Verify → Document → Release → Reuse/Recycle
The important point is that data security should be completed before physical disposal.
When organisations connect their DPDP compliance programme with IT asset management, data sanitisation, ITAD and responsible e-waste recycling, they can reduce the risk of personal-data exposure while maintaining a clear and auditable path for retired technology.
Categories
- Battery & Industrial Recycling 1
- Compliance & Corporate E-Waste Management 6
- Computer Recycling & E-Waste Management 1
- Corporate E-Waste Management 1
- Data Center Decommissioning 1
- Data Security & E-Waste Recycling 1
- Data Security & IT Asset Disposal 4
- Data Security & Media Destruction 5
- E-Waste Compliance & Regulations 1
- Enterprise ITAD Strategy 5
- EWaste 3
- Industrial & Real Estate Decommissioning 1
- Industrial E-Waste Management 3
- Regional Industrial Logistics 1
- Renewable Energy & E-Waste Recycling 1
- Resource Recovery & Recycling 1
- Workplace Safety & E-Waste Management 1
