Risk management

Sensitive data on company devices: the hidden risk of improper disposal

Many companies underestimate the risks associated with the incomplete deletion of data from decommissioned devices, thereby exposing themselves to serious legal and operational consequences

 (AdobeStock)

5' min read

Translated by AI
Versione italiana

5' min read

Translated by AI
Versione italiana

No senior executive buying a new smartphone would ever throw their old one in the bin, because they know full well that their electronic device may contain a wealth of confidential information such as financial documents, business strategies, corporate documents, login credentials for servers and business accounts, confidential messages and other sensitive data, the accidental disclosure of which could have disastrous consequences.

Yet more than a third of companies that decommission or sell mobile phones and other devices provided to managers and staff for work purposes fail to take appropriate precautions to prevent the potential leakage of data contained in devices that leave the company’s premises.

Loading...

This critical issue is highlighted in the “Blancco 2026 State of Data Sanitisation Report”, which highlights how the final stage of the digital asset lifecycle is still underestimated in cybersecurity and data governance strategies: although 89 per cent of organisations state that they have a policy for the secure erasure of data, in reality only 61 per cent say they actually implement it. Furthermore, 32% of organisations that have suffered data loss in the last twelve months attribute the incident to the redistribution of electronic devices that had not been properly sanitised.

The risk of unsafe disposal of IT assets

A smartphone returned by an employee, just like any other piece of company-owned electronic equipment intended for disposal, is therefore not simply electronic waste for which it is sufficient to merely comply with the WEEE regulations. The disposal of IT assets cannot be treated as a purely technical, logistical or environmental issue, as it entails operational and information security risks with potential financial, reputational, legal and competitive consequences, which fall squarely within the remit of enterprise risk management, on a par with cyber security and the protection of corporate know-how.

Despite this, many organisations continue to underestimate the problem, believing that, before disposing of an electronic device, it is sufficient to perform a quick format or restore it to its factory settings to permanently delete all the files and information it contains. Although the data is no longer visible after carrying out these operations, it actually remains in the device’s memory and can be easily recovered using technical tools or forensic analysis.

And the problem does not only concern smartphones, but also hard drives, tablets, photocopiers and multifunction printers, CCTV systems, IoT devices and USB sticks, on whose internal memory data may remain even after they have been decommissioned. Just consider that a study published on arXiv, which examined 614 second-hand USB devices, found that data was recoverable in more than 12 per cent of cases.

WEEE collection centres and data responsibility 

It is important to bear in mind that the correct disposal of waste electrical and electronic equipment is essential for reducing environmental impact and promoting the recovery of materials; however, the treatment of WEEE and the secure erasure of data are two very different activities, serving different purposes that cannot be conflated.

A WEEE collection centre is, in fact, set up to receive, store and send electronic equipment for recovery or disposal, but it is not responsible for ensuring that the internal memory of the devices it receives has been wiped in such a way as to make it impossible to recover any information.

Guidance from the Data Protection Authority

In the past, the Data Protection Authority had already drawn attention to this sensitive issue in its decision of 13 October 2008, concerning the security measures applicable to data contained in waste electrical and electronic equipment. The Data Protection Authority had clarified that compliance with the environmental regulations governing WEEE does not exempt the data controller from its obligations regarding data protection. In other words, handing over a device to an authorised electronic waste management operator does not relieve the company of its responsibility to permanently erase all data stored on it.

The Authority had also clarified that manufacturers, distributors and service centres, by virtue of simply operating within the WEEE supply chain, are not obliged to erase or destroy any personal data that may be present on the devices handed over, but rather it is the responsibility of the organisation disposing of the equipment to ensure that the data has been effectively erased or rendered unreadable prior to handover, or to entrust the data erasure to specialist organisations capable of certifying the activities carried out.

Loading...

The implications for businesses

The careless disposal of an electronic device can have effects similar to those of an external cyber-attack. For a company, the uncontrolled leakage of data contained in devices that are disposed of can, in fact, facilitate fraud, extortion, targeted attacks, the theft of know-how, unfair competition, the compromise of company accounts, and the disclosure of other information subject to specific confidentiality restrictions, which often also jeopardise employees’ privacy.

From the perspective of data protection legislation, a device handed over to a third party or disposed of without being properly wiped may constitute a “data breach”. Even if the disposed data storage medium does not end up in the hands of a cybercriminal, the mere fact that unauthorised persons could potentially access information that is still recoverable is sufficient to trigger the obligation under the GDPR to notify the Data Protection Authority of the breach within 72 hours of its discovery, and, in the most serious cases, also to inform the data subjects concerned to give them the opportunity to protect themselves.

However, the disposal of a company-owned electronic device on which no secure data erasure procedure has been carried out does not merely give rise to cybersecurity and regulatory compliance issues.

If business plans, projects, commercial proposals, financial data or information on market strategies were to be recovered, the damage could, in fact, result in an advantage for competitors, or in the loss of value of intangible assets built up over time.

Divestment as a risk management tool 

The solution is obviously not to abandon the reuse, sale or refurbishment of devices, as these can yield significant economic and environmental benefits. Rather, data protection must be integrated into the asset’s life cycle, from its allocation right through to its decommissioning, making data erasure a standard part of risk management. To achieve this, it is necessary to accurately map all electronic devices in use, and then establish procedures integrated into risk management processes to apply the most appropriate secure data erasure techniques based on established reference standards such as those set out in NIST SP 800-88, whilst also defining clear and coordinated responsibilities across IT, cybersecurity, privacy, procurement, ESG and asset management functions.

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti