Software based data destruction procedures: FOI release

Information request and response under the Freedom of Information (Scotland) Act 2002.


Information requested

You asked for a variety of information regarding clarifications on the software based data destruction assurance used by the Scottish Government. The questions are listed below with the responses directly below each numbered item.

Response

1. Regarding point 1 ("Device specific erasure certificates... confirming that erasure was successfully completed and validated"): What does "validated" refer to in the recorded information held? For example, is this validation performed by the contractor's tool/software self-check, by independent post-erasure forensic sampling/recovery testing, by a third-party auditor, or by another method? Please describe the recorded nature of this validation step.

"Validated” refers to the successful verification outcome recorded within the contractor’s certified erasure process. This is reflected in the device‑specific erasure reports, the wiping certificate and the audit records produced as part of that process. The Scottish Government holds these as the recorded evidence that erasure completed successfully for each relevant item of storage media.

2. Do the device-specific erasure certificates (or any related contractual terms) include any explicit outcome-based warranty or guarantee from the contractor that personal data has been rendered irretrievable, or do they primarily confirm that a certified process was followed?

The Scottish Government does not hold separate evidence of independent forensic recovery testing, third‑party post‑erasure sampling or media‑type‑specific testing (e.g. SSD/NVMe) carried out by or for the Scottish Government, nor does it hold an explicit outcome‑based warranty guaranteeing irretrievability. The certificates primarily record that the contractor’s certified erasure process was applied and completed.

3. In light of the ISO 27001 requirement for auditable procedures (point 4), does the department hold any recorded risk assessment or testing evidence demonstrating that the erasure methods (and their validation) remain effective for the specific types of storage media encountered (e.g. modern SSDs/NVMe), rather than relying solely on general certification?

While the supplier operates an ISO 27001‑certified information security management system, the Scottish Government does not hold additional risk assessments or testing evidence beyond the certificates and audit records already described.

About FOI

The Scottish Government is committed to publishing all information released in response to Freedom of Information requests. View all FOI responses at https://www.gov.scot/foi-responses.

Contact

Please quote the FOI reference
Central Correspondence Unit
Email: contactus@gov.scot
Phone: 0300 244 4000

The Scottish Government
St Andrew's House
Regent Road
Edinburgh
EH1 3DG

Back to top