Science and Advice for Scottish Agriculture (SASA) - Assurance process information for software-based data erasure of end of life IT equipment: FOI release

Information request and response under the Freedom of Information (Scotland) Act 2002.


Information requested

The following recorded information held by your department regarding assurance processes for software based data erasure of end of life IT equipment.

For clarity, this request relates solely to software based data destruction. Please exclude physical destruction methods such as shredding, crushing, degaussing or disintegration.

1. Please confirm whether departmental policy, contractual terms or internal procedures require an explicit outcome based warranty or guarantee confirming that personal data has been rendered irretrievable through software based erasure, whether carried out internally or by an external provider.

2. Where software based data destruction is performed internally, what recorded evidential assurance does the department rely upon to conclude that the final data state is irretrievable?

3. Where software based data destruction is performed by a third party provider, does the department hold recorded information demonstrating that any warranty or assurance provided explicitly extends to the software erasure method used and its claimed effectiveness? If so, please confirm the recorded nature of that verification.

4. Where no explicit outcome based warranty is required or provided, what recorded form of evidential assurance does the department rely upon to conclude that software based erasure has rendered personal data irretrievable?

I am not requesting technical configuration detail, security sensitive information or supplier specific vulnerabilities. I am seeking confirmation of the assurance model relied upon for software based data destruction.

Response

I enclose a copy of all the information you requested.

Q1. Departmental policy requires compliance with the current HMG Secure Sanitisation requirements. These requirements do not mandate an explicit outcome-based warranty or guarantee confirming that personal data has been rendered irretrievable through software-based erasure. SASA performs sanitisation internally.

Q2. For Active Directory–joined devices, the recorded evidential assurance is the deletion of the device’s computer object in Active Directory, which removes the associated BitLocker recovery key and logs the action.

For Intune-managed devices, deletion of the device in Intune/Entra ID removes the associated cloud-stored BitLocker recovery key, and this action is logged in Intune/Entra ID.

Q3. SASA does not use third-party providers for software-based data erasure and therefore holds no recorded information relating to warranties or assurances for such methods.

Q4. For Active Directory–joined devices, evidential assurance is provided by the deletion of the computer object in Active Directory, which removes the associated BitLocker recovery key and logs the action.

For Intune-managed devices, evidential assurance is provided by deletion of the device in Intune/Entra ID, which removes the associated cloud-stored BitLocker recovery key and is recorded in the Intune/Entra ID audit logs.

About FOI

The Scottish Government is committed to publishing all information released in response to Freedom of Information requests. View all FOI responses at https://www.gov.scot/foi-responses.

Contact

Please quote the FOI reference
Central Correspondence Unit
Email: contactus@gov.scot
Phone: 0300 244 4000

The Scottish Government
St Andrew's House
Regent Road
Edinburgh
EH1 3DG

Back to top