Secure, documented destruction of personal data is required under UK GDPR and the Data Protection Act 2018. For paper records, that means certified cross-cut or micro-cut shredding; for devices, secure wiping, degaussing, or physical destruction. Always keep the certificate of destruction, and check any outsourced provider holds a proper processor agreement before you hand over a single box.
TL;DR:
- Most businesses should use certified cross-cut or micro-cut shredding to prevent reconstruction, especially for sensitive or special category data, and always retain a certificate of destruction.
- Outsourcing destruction to a licensed provider with proper chain-of-custody evidence and a processor agreement ensures legal compliance and mitigates liability risks.
- Electronic records, including backups and cloud copies, should be securely wiped, degaussed, or physically destroyed, with detailed logs of the process for each device.
- Implementing a documented retention schedule, legal holds, and a responsible owner for disposal reduces risks of accidental destruction or regulatory fines.
- Regular audits, staff training, and clear responsibilities improve compliance and prevent security gaps during the disposal process.
Table of Contents
- What UK GDPR requires for gdpr document disposal
- How should you destroy paper records securely?
- Secure disposal of electronic devices and digital records
- Should you shred in-house or outsource it?
- What contract terms and evidence should you demand?
- When should you pause document destruction?
- Checklist: choosing a GDPR-compliant shredding partner
- Why Secure Shred meets the compliance checks described
- Your compliance checklist for document disposal
- How long should document disposal actually take?
- How should special category data be handled differently?
- Who should be responsible for document disposal at work?
- The real gap in most GDPR disposal advice
- Get compliant disposal sorted with Secure Shred
- Sources
- FAQ
What UK GDPR requires for gdpr document disposal
Article 5 of the UK GDPR sets out the storage limitation principle: you cannot keep personal data longer than necessary for the purpose you collected it for. Once that purpose ends, whether it’s a completed job application, a closed customer file, or an old invoice, you have an obligation to dispose of it securely, not just delete it from view.
Article 32 adds the security layer. It requires “appropriate technical and organisational measures” to protect personal data, and that duty doesn’t stop when a document reaches the end of its life. Throwing sensitive files into a general recycling bin fails this test outright. The ICO is explicit that personal data should never go into general waste or recycling, and that organisations should use destruction methods that prevent reconstruction, backed by evidence such as a certificate of destruction.
If you outsource destruction to a shredding company, you remain the data controller and you remain liable. Using a processor doesn’t transfer responsibility; it just adds a layer you need to manage under Article 28. That means a written agreement covering security measures and audit rights, not a handshake and an invoice.
In practice, the ICO expects to see:
- Secure destruction methods that leave no realistic chance of reconstruction
- Evidence of destruction, such as certificates with dates, weights, and standards applied
- A logging system showing what was destroyed, when, and by whom
- A retention schedule that ties destruction timing to a documented purpose, not guesswork
Documentation isn’t bureaucratic box-ticking. If the ICO ever investigates a breach, your paper trail is what separates a minor finding from a significant enforcement action.
How should you destroy paper records securely?
Not all shredding is equal, and the security level you choose should match the sensitivity of what’s being destroyed. The DIN 66399 standard grades destruction from P-1 (strip-cut, minimal security) through to P-7 (used for top-secret material). For most business records, cross-cut shredding sits comfortably in the middle bands and produces particles small enough to resist reassembly. Highly sensitive files, medical records, or anything touching special category data, warrant a higher grade, often P-4 or above.
You have several practical routes to get there:
- On-site mobile shredding, where a vehicle-mounted shredder destroys documents at your premises while you watch
- Off-site certified shredding, where sealed containers are collected and destroyed at a secure facility
- Pay-as-you-go sacks, useful for one-off clear-outs without a recurring contract
- Locked collection bins, which let staff dispose of confidential waste safely between scheduled collections
Recycling shredded paper is generally fine once destruction has actually happened, because cross-cut particles can’t be pieced back together the way a torn sheet can. The risk isn’t recycling itself; it’s recycling material that was never properly shredded in the first place.
Whatever method you choose, the controls around it matter as much as the shredder itself. Documents awaiting destruction should sit in locked consoles, not open boxes by a photocopier. Collection bags or bins should carry tamper-evident seals, and every collection should be logged with a reference number that ties back to your records.
Pro Tip: Ask any shredding provider for their seal numbers on collection day and match them against the certificate of destruction you receive afterwards. If the numbers don’t line up, you have a genuine chain-of-custody gap worth querying.
Secure disposal of electronic devices and digital records
Paper isn’t the only place personal data lives, and hard drives, laptops, and USB sticks need their own disposal route. The ICO’s guidance on disposal and deletion requires electronic records to be destroyed in line with your retention schedule, using methods that prevent disclosure before, during, and after disposal.
Three methods cover most situations:
- Secure wiping or overwriting, suitable for drives being reused or resold, following a recognised standard such as NIST 800-88
- Degaussing, which uses magnetic fields to erase data on traditional hard drives (not effective on solid-state drives)
- Physical hardware destruction, the safest route when data cannot be reliably wiped, particularly for SSDs where standard overwriting sometimes misses hidden storage areas
Backups complicate all of this. Wiping a laptop means little if the same files sit in a cloud backup or a shadow copy nobody accounted for. Before you certify a device as “clean,” check where its data has been replicated.
For anything involving special categories of data or media that resists reliable wiping, physical destruction through a specialist IT destruction provider is the safer default. Whichever method you use, log the device’s serial number, the method applied, and the date, and keep that record alongside your other destruction evidence.
Should you shred in-house or outsource it?
The right answer depends on volume, sensitivity, and how much staff time you’re willing to spend policing the process yourself.
- Low volume, low sensitivity: A decent office shredder rated to a reasonable DIN 66399 security level can handle occasional destruction for a very small operation, provided someone actually uses it consistently.
- Growing volume or mixed sensitivity: Once you’re generating regular confidential waste, staff time spent shredding becomes a hidden cost, and an unattended office shredder rarely produces the audit trail an ICO investigation would want to see.
- Special category data or high sensitivity: Outsourcing to a certificated provider becomes the more defensible option, because you get a certificate of destruction and a chain-of-custody record rather than an internal log nobody checks.
In-house shredding puts the evidence burden entirely on you. If a breach occurs, your only proof is whatever log you kept, if you kept one at all. Outsourced destruction gives you third-party certification, which carries more weight with regulators and insurers alike. There are also hidden costs on the in-house side: bin storage before shredding, machine maintenance, staff hours, and the risk exposure of documents sitting around waiting to be dealt with. For most SMEs handling anything beyond the occasional page, outsourcing to a provider with proper documentation is the more cost-effective, lower-risk route.
What contract terms and evidence should you demand?
An Article 28 processor agreement isn’t optional paperwork; it’s the legal mechanism that makes outsourcing lawful. At minimum, the agreement should specify the subject matter, duration, nature, and purpose of processing, the security measures in place, breach notification obligations, and your right to audit the provider.
After every job, your certificate of destruction should show:
- The date of destruction
- The weight or unit count destroyed
- The security standard applied
- The destruction location
- A unique order or job reference number
Keep these certificates for as long as your own retention policy requires, and treat them as part of your compliance file, not a receipt to be filed and forgotten. Roughly a third of ICO enforcement cases involving data disposal failures trace back to missing or inadequate evidence rather than the destruction method itself, which tells you where the real risk sits.
Store items awaiting destruction in access-controlled areas, log who authorised each collection, and periodically audit your provider’s paperwork against what actually arrived.
When should you pause document destruction?
A retention schedule tells you when destruction should happen. A legal hold tells you when it must stop, regardless of what the schedule says.
- Set the retention schedule first: tie each document category to a defined retention period linked to its original purpose, following the storage limitation principle.
- Identify triggers for a hold: litigation, a regulatory investigation, or even a credible threat of either should immediately suspend destruction for relevant records.
- Document the hold in writing: note what’s covered, who authorised the pause, and when it took effect, so nobody accidentally shreds evidence three weeks later.
- Build an approval workflow: destruction should require sign-off from someone senior enough to know whether a hold applies before any batch goes to the shredder.
Legal practitioners are blunt about the consequences here. Guidance on document retention policy warns that failing to suspend destruction once litigation is reasonably anticipated risks sanctions for spoliation of evidence. Audits should check that holds were applied correctly, not just that the retention schedule exists on paper.
Checklist: choosing a GDPR-compliant shredding partner
Before signing with any provider, or trusting an internal process, work through a short set of questions that separate a compliant setup from a liability waiting to surface.
- Does the provider issue a certificate of destruction with date, weight, standard, and reference number?
- Is there a written processor agreement covering security measures, audit rights, and breach notification?
- Can they confirm insurance cover appropriate to the volume and sensitivity of your material?
- Are staff vetted, and can the provider explain their vetting process on request?
- Do they offer both on-site and off-site options, and can they explain which suits your data?
- What security level (cross-cut, micro-cut, DIN 66399 grade) do they apply, and does it match your risk?
- Can they show chain-of-custody evidence, such as seal numbers matched to collection logs?
- What’s their recycling policy for shredded material, and is destruction verified before recycling?
Red flags include vague answers about security levels, no written agreement at all, or a refusal to provide sample paperwork before you commit. A provider confident in its process will hand over a sample certificate without hesitation.
Pro Tip: Ask a prospective provider for a redacted sample certificate before your first collection. If they hesitate or can’t produce one, that tells you more than any sales pitch will.
Why Secure Shred meets the compliance checks described
Everything covered above points to the same conclusion: compliant disposal needs traceable evidence, not just a shredder. Secure Shred’s approach is built around exactly that. GPS-tracked vehicles and CCTV monitoring provide the chain-of-custody detail an Article 28 audit would want to see, and every job comes with a certificate of destruction covering the specifics regulators expect.
That maps directly onto what this guide has set out. GPS tracking and CCTV support the security measures Article 32 requires. Certificates of destruction give you the evidence trail Article 5 and Article 28 both depend on. For businesses and households across Cardiff needing paper shredding, hard drive destruction, or scheduled collections, the documentation Secure Shred provides is designed to match what an ICO investigation would ask to inspect first.
Your compliance checklist for document disposal
Pulling everything together, a GDPR-compliant disposal process rests on a handful of documented steps, repeated consistently rather than done once and forgotten.
Start with a retention schedule that names each document category and its destruction trigger point. Pair it with a classification step, so anyone handling records knows which files are ordinary business data and which are special category or otherwise higher risk.
Before destruction, confirm storage security: locked consoles or bins, not open boxes, for anything awaiting shredding. Confirm the destruction method matches sensitivity, cross-cut or higher for paper, wiping or physical destruction for devices.
After destruction, collect and file the certificate of destruction, checking it includes date, weight or unit count, standard applied, and a reference number. Cross-check chain-of-custody evidence, such as seal numbers, against what your provider logged.
Review your processor agreement annually to confirm it still covers current security measures and audit rights. Finally, build in a legal hold check as a standing step before any batch destruction, so nobody destroys material connected to a live or anticipated dispute.
Treat this as a recurring cycle rather than a one-off audit. Businesses that revisit their retention schedule annually and destroy on a defined rhythm report fewer ad hoc compliance gaps than those relying on occasional clear-outs.
How long should document disposal actually take?
Disposal timelines vary by document type, but a workable rhythm looks roughly like this from identification to final destruction.

Identification and review typically takes a day to a week for routine files, once a record hits its retention trigger, someone should flag it within that window rather than letting it sit indefinitely in a “sort later” pile.
Classification and hold check should be near-immediate, a quick confirmation that nothing under legal hold has been swept into the destruction batch. This is a five-minute check, not a project.
Storage pending destruction should be short by design: days, not months. The longer sensitive material sits in a collection bin, the more exposure risk builds, so most businesses aim for weekly or fortnightly collection cycles rather than letting bins fill for a quarter.
Destruction itself happens in minutes for on-site mobile shredding, since the vehicle destroys material at your premises during the visit. Off-site destruction typically completes within 24 to 48 hours of collection, depending on the provider’s schedule.
Certificate issuance should follow shortly after destruction, ideally within a few working days, so you have documentary evidence close to the actual event rather than a certificate arriving weeks later with vague dates.
End to end, a well-run process moves from flagged record to certified destruction within one to two weeks for routine batches. Anything dragging on for months usually signals a storage or scheduling problem worth fixing before it becomes a security gap.
How should special category data be handled differently?
Special category data, health records, biometric information, trade union membership, sexual orientation, and similar sensitive classes, carries a higher bar under Article 9 of the UK GDPR, and disposal should reflect that.
Practically, this means defaulting to the higher end of the DIN 66399 security scale for paper, often P-4 or above rather than a general-purpose cut. For electronic media holding special category data, physical destruction is the safer default over wiping alone, particularly where the storage medium is an SSD that may retain data in areas standard overwriting doesn’t reach. NIST 800-88 guidance is the recognised reference point here, and providers should be able to confirm they follow it.
Storage before destruction also warrants tighter controls. Special category files shouldn’t sit in the same general confidential waste console as routine invoices; a separate, more restricted collection point reduces the chance of mishandling or unauthorised access before destruction happens.
Access logging matters more here too. Record who handled the material before destruction, not just who authorised the final job, since special category breaches tend to carry higher regulatory scrutiny and higher potential fines. If your organisation handles this kind of data regularly, HR files, medical information, safeguarding records, build a separate destruction pathway with its own schedule, its own storage rules, and its own sign-off step, rather than folding it into general office waste procedures.

Who should be responsible for document disposal at work?
Compliance breaks down fastest when everyone assumes someone else is handling it. Assign a named person, often whoever holds the data protection or office manager role, as the accountable owner for disposal procedures, even if the physical shredding is outsourced.
Staff training doesn’t need to be elaborate, but it does need to cover the basics consistently: what counts as confidential waste, where it goes before destruction, and what never goes in general bins. A short induction session for new starters, refreshed annually for existing staff, closes most of the gap between policy and practice.
Give staff a simple decision rule they can apply without escalating every time: if a document contains a name, date of birth, financial detail, or health information, it goes in the confidential console, not the recycling bin. Complicated flowcharts get ignored under time pressure; a one-line rule gets followed.
Build accountability into the process itself. Whoever authorises a destruction batch should sign or log that authorisation, creating a record that ties back to your certificates of destruction. That way, if a batch goes missing or a hold gets breached, you can trace exactly where the process broke down.
Review responsibilities annually alongside your retention schedule. Staff turnover means the person who understood the process last year may not be the person managing it now, and an outdated ownership chart is almost as risky as having no process at all.
The real gap in most GDPR disposal advice
Most guidance on document disposal fixates on the shredder, cross-cut versus micro-cut, on-site versus off-site, and treats that choice as the whole compliance problem. It isn’t. The method matters less than the paper trail behind it. A business with a mediocre shredder but airtight certificates, logs, and a processor agreement is in a stronger position during an ICO enquiry than one with a top-tier machine and no evidence at all.
The conventional advice also underplays legal holds. Retention schedules get plenty of attention; the discipline to pause destruction the moment litigation looks plausible gets almost none, and that’s precisely where spoliation risk lives.
If you take one thing from this guide, prioritise evidence over equipment. Get the certificate, check the Article 28 clauses, confirm the chain of custody. The shredding itself is the easy part; proving you did it properly is where most businesses fall short.
— Dan
Get compliant disposal sorted with Secure Shred
A professional shredding service can handle the practical side of everything covered above, including on-site and off-site paper shredding, hard drive and electronic media destruction, and both one-off and scheduled collections, so you’re not left assembling compliance evidence from scratch. Every job comes with a certificate of destruction, and secure transport and monitoring give you the traceability an Article 28 audit would expect to see.

Whether you need a single archive clear-out or regular collections for an office generating confidential waste every week, getting a quote is straightforward: describe your volume and frequency, and you’ll get pricing and a collection slot without committing to a long-term contract. Businesses across Cardiff and South Wales can check local collection details on the Cardiff shredding service page, and homes or offices further out can find coverage details for Cwmbran and surrounding areas too. If you’re ready to stop worrying about where confidential waste goes, book a collection or request a quote today.
Sources
- Practical methods for destroying documents that are no longer needed | ICO
- Disposal and deletion | ICO
- Legislation
- Document retention policy guidance | Practical Law
FAQ
How do you dispose of confidential documents in the UK?
Use certified cross-cut or micro-cut shredding for paper, following DIN 66399 security levels appropriate to sensitivity, and always obtain a certificate of destruction as evidence. Secure Shred provides both on-site and off-site options with documented chain of custody for exactly this purpose.
Does GDPR apply to the United Kingdom?
Yes. The UK operates its own version, UK GDPR, alongside the Data Protection Act 2018, which together set the legal requirements for how personal data, including its disposal, must be handled.
What are the GDPR changes expected in 2026?
Specific regulatory changes vary and businesses should monitor ICO guidance directly rather than relying on informal summaries, since disposal obligations under the Data Protection Act 2018 and UK GDPR remain the current statutory baseline.
Is it okay to dispose of confidential documents in regular bins?
No. The ICO is explicit that personal data should never go into general waste or recycling bins; it must be destroyed through secure methods that prevent reconstruction, with evidence retained afterwards.
