Information regarding software based data destruction assurance policy: FOI release

Information request and response under the Freedom of Information (Scotland) Act 2002.


Information requested

You asked for a variety of information regarding software based data destruction assurance used by the Scottish Government. The questions are listed below with the responses directly below each numbered item.

Please note that the below response relates solely to software‑based data erasure of storage media associated with end‑of‑life IT equipment. Physical destruction methods are out of scope. This response covers the whole of core Scottish Government, we do not hold records of how non core organisations on how to dispose of their equipment

Response

1. Whether your organisation’s policies, contractual terms, or internal procedures require an explicit outcome based warranty or guarantee that personal data on a specific storage device has been rendered irrecoverable as a final data state following software based erasure.

No. Scottish Government policy and contractual terms require secure and compliant software‑based data sanitation, but they do not mandate a separate, explicit outcome‑based warranty or guarantee that personal data has been securely sanitised as a final data state.

2. Where software based erasure of storage media is undertaken internally, what recorded evidential assurance is relied upon to conclude that the final data state of the specific storage device is irrecoverable, as distinct from confirmation that an erasure process was executed.

Software‑based erasure of end‑of‑life storage media is not carried out internally by the Scottish Government. All such activity is undertaken by a contracted third‑party provider.

3. Where software based erasure is undertaken by a third party provider:

a. Do the certificates or contractual documents held constitute an explicit outcome based warranty or guarantee of irrecoverability for each specific storage device processed?

No. The device‑specific certificates held record that the supplier’s certified software‑based erasure process was applied and completed successfully. They do not constitute an explicit outcome‑based warranty or guarantee that personal data has been rendered inaccessible as a final data state for each specific storage device.

b. Beyond reliance on supplier accreditation or recognised standards including but not limited to ADISA certification, ISO accreditation, NIST alignment, HMG IA standards, or Data Security and Protection Toolkit assertions, and beyond confirmation that a wiping process was completed, does the organisation hold any recorded, device specific documentation evidencing independent verification, testing, or validation that the data on the storage media has been rendered irrecoverable in practice?

Beyond supplier accreditation and confirmation that the certified erasure process completed successfully, the Scottish Government does not hold device‑specific evidence or additional validation carried out by or on behalf of the Scottish Government to demonstrate Data has been securely sanitised in line with UK government guidance.

4. If no explicit outcome based warranty or device specific outcome evidence is held beyond certification, accreditation, or confirmation of process completion, please confirm what recorded form of evidential assurance is relied upon when concluding that personal data has been rendered irrecoverable.

In the absence of an explicit outcome‑based warranty or independent device‑specific forensic testing, the Scottish Government relies on recorded evidence that an accredited software‑based data sanitation process has been successfully executed and verified in line with UK government security guidance.

This assurance is based on device‑specific erasure reports and certificates produced by the contracted supplier’s certified erasure process, supported by audit records, asset tracking information, and the supplier’s certified information security management system.

The erasure records confirm that the approved software‑based sanitation process completed successfully for each item of storage media and that verification checks within the erasure tool were passed. These records are held as evidence that data has been sanitised in a manner consistent with UK government guidance for the secure disposal or reuse of storage media at OFFICIAL sensitivity.

About FOI

The Scottish Government is committed to publishing all information released in response to Freedom of Information requests. View all FOI responses at https://www.gov.scot/foi-responses.

Contact

Please quote the FOI reference
Central Correspondence Unit
Email: contactus@gov.scot
Phone: 0300 244 4000

The Scottish Government
St Andrew's House
Regent Road
Edinburgh
EH1 3DG

Back to top