Equipment categories that may retain data requiring secure destruction or verified erasure.
Every internal drive counts — and some units have several.
The core data-bearing category — destruction or verified wiping matters most here.
Often overlooked at decommission — and they hold the densest personal/business data.
The category most checklists miss. Stores configs, credentials, logs, and VPN keys in nonvolatile memory.
A classic audit gotcha. MFPs since the mid-2000s typically store an image of every document scanned, copied, faxed, or printed.
Small, easy to misplace, and frequently still loaded with data on arrival.
PCI-DSS scope. Card terminals and POS systems can retain cardholder data, transaction logs, and stored credentials — treat as high-sensitivity and never resell without verified data destruction.
Items with storage buried inside that clients rarely flag.
The most common compliance error is degaussing flash media — it does not work. Match method to media type.
| Media Type | Found In | Approved Methods | Verification |
|---|---|---|---|
| Magnetic (HDD) | Desktops, laptops, servers, NAS, external drives | Degauss, shred, or NIST 800-88 overwrite | Serial scan + destruction log / overwrite report |
| Magnetic tape | LTO / DLT backups | Degauss or shred | Serial scan + destruction log |
| Flash / NAND | SSD, NVMe, M.2, USB, SD, phones, tablets | Crypto-erase or physical shred — NOT degauss | Erase certificate or shred log |
| Embedded flash | MFPs/copiers, networking gear, POS terminals, IoT, infotainment | Factory reset + remove/destroy drive where present | Reset confirmation + drive destruction log |
| Payment / PCI | Card terminals, PIN pads, POS systems | Crypto-erase + physical destruction of storage; follow PCI-DSS device disposal | Destruction log + chain of custody |
| Optical | CD, DVD, Blu-ray | Shred or disintegrate | Destruction log |