Sensitive data on company devices: the hidden risk of improper disposal
Many companies underestimate the risks associated with the incomplete deletion of data from decommissioned devices, thereby exposing themselves to serious legal and operational consequences
Key points
No senior executive buying a new smartphone would ever throw their old one in the bin, because they know full well that their electronic device may contain a wealth of confidential information such as financial documents, business strategies, corporate documents, login credentials for servers and business accounts, confidential messages and other sensitive data, the accidental disclosure of which could have disastrous consequences.
Yet more than a third of companies that decommission or sell mobile phones and other devices provided to managers and staff for work purposes fail to take appropriate precautions to prevent the potential leakage of data contained in devices that leave the company’s premises.
This critical issue is highlighted in the “Blancco 2026 State of Data Sanitisation Report”, which highlights how the final stage of the digital asset lifecycle is still underestimated in cybersecurity and data governance strategies: although 89 per cent of organisations state that they have a policy for the secure erasure of data, in reality only 61 per cent say they actually implement it. Furthermore, 32% of organisations that have suffered data loss in the last twelve months attribute the incident to the redistribution of electronic devices that had not been properly sanitised.
The risk of unsafe disposal of IT assets
A smartphone returned by an employee, just like any other piece of company-owned electronic equipment intended for disposal, is therefore not simply electronic waste for which it is sufficient to merely comply with the WEEE regulations. The disposal of IT assets cannot be treated as a purely technical, logistical or environmental issue, as it entails operational and information security risks with potential financial, reputational, legal and competitive consequences, which fall squarely within the remit of enterprise risk management, on a par with cyber security and the protection of corporate know-how.
Despite this, many organisations continue to underestimate the problem, believing that, before disposing of an electronic device, it is sufficient to perform a quick format or restore it to its factory settings to permanently delete all the files and information it contains. Although the data is no longer visible after carrying out these operations, it actually remains in the device’s memory and can be easily recovered using technical tools or forensic analysis.

