waste.org.uk
Back to blog
Data Security

Data Destruction Standards Explained (NCSC and DIN 66399)

Published by Ewaste.org.ukNovember 10, 2025 12 min read

Key takeaways

  • Standards make destruction measurable, verifiable and defensible in an audit.
  • NCSC guidance is the UK government authority on data sanitisation.
  • DIN 66399 defines material classes, security levels and shred particle sizes.
  • ISO 27001 covers information security; ISO 14001 covers environmental management.
  • Higher security levels mean smaller particle sizes and stronger assurance.
  • Match the standard to your data's sensitivity, not just to the lowest cost.

Data destruction standards are the published benchmarks that turn a vague promise of secure disposal into a measurable, auditable outcome. For UK businesses, the most relevant are NCSC guidance, the DIN 66399 standard and the ISO certifications that govern how a provider operates. This guide explains what each one means, how the security levels and material classes work, how data sanitisation standards verify the result, and how to use them when choosing a destruction method.

Why standards matter at all

Without a standard, 'secure destruction' is just a marketing phrase. Standards define exactly what must happen for data to be considered unrecoverable — how many overwrite passes, what particle size a shredder must achieve, or what process a provider must follow. That precision is what lets you prove compliance after the event.

When a provider tells you they destroy to a named standard, you can verify their claim against a published reference rather than taking it on trust. That is the whole point of an audit trail, and it is why your Certificate of Destruction should name the standard achieved.

NCSC guidance: the UK government reference

The National Cyber Security Centre (NCSC) is the UK's authority on cyber and information security, and its guidance on sanitisation and secure disposal is widely referenced in public-sector and regulated contracts. It covers when to overwrite, when to destroy, and how to handle different media types securely.

When NCSC alignment matters most

If you work with central government, the wider public sector, or supply chains that serve them, NCSC-aligned destruction is often a contractual requirement. Even where it is not mandated, following NCSC guidance is a sensible default for any organisation handling sensitive data.

How NCSC guidance treats different media

NCSC guidance recognises that magnetic hard drives, solid-state drives and other media need different treatment. It is the reason a credible provider will not apply a single blanket method to everything, but instead matches the technique — overwriting, destruction or cryptographic erase — to the media type and sensitivity.

DIN 66399: security levels and particle sizes

DIN 66399 is an internationally used standard that defines how thoroughly media must be destroyed. It classifies media into categories and sets graded security levels, with higher levels requiring progressively smaller fragment sizes.

Material classes

The standard separates media into classes so that, for example, paper, optical media, magnetic hard drives and electronic chips each have appropriate destruction requirements rather than a one-size-fits-all rule. This is why SSDs, which fall into the electronic-media class, require a finer particle size than spinning hard drives.

Security levels in practice

Security levels run from lower tiers suitable for general internal data up to the highest tiers for top-secret information, where particles must be extremely small. The more sensitive your data, the higher the level — and the smaller the resulting fragments — you should specify.

ISO certifications: how the provider operates

  • ISO 27001 — information security management; shows the provider's handling of your data is independently audited.
  • ISO 14001 — environmental management; supports a credible zero-to-landfill claim.
  • Together they cover both the security and the sustainability of the destruction process.

How the standards fit together

These standards are complementary rather than competing. NCSC guidance tells you the right approach for the media and sensitivity in a UK context. DIN 66399 gives the technical specification — the class and security level — for how thoroughly destruction must be carried out.

ISO 27001 and ISO 14001, meanwhile, are about the provider's organisation: that their information security and environmental processes are independently audited rather than self-declared. A strong provider can speak to all of them, mapping your data sensitivity to a recognised method, a DIN security level and a documented, certified process.

Matching the standard to your data

There is no need to destroy routine internal data to the highest possible level, nor should you destroy classified data to a minimal one. The skill is matching the standard to the sensitivity of the information.

  • General business data — certified overwriting to a recognised standard.
  • Confidential commercial or personal data — higher DIN 66399 levels or shredding.
  • Highly sensitive or regulated data — NCSC-aligned destruction at high security levels.

How standards appear on your certificate

A good Certificate of Destruction names the standard the destruction met, turning an abstract benchmark into concrete evidence. When the certificate states the method and the standard — and ideally the serial numbers — you have a complete, auditable record. Our secure data destruction service destroys to recognised standards and documents them clearly so the proof is unambiguous.

Questions to ask a provider about standards

  • Which standard do you destroy to, and can you evidence it?
  • What DIN 66399 security level do you achieve for hard drives?
  • Is your destruction aligned with NCSC guidance?
  • Are you certified to ISO 27001 and ISO 14001?
  • Will the standard be stated on my Certificate of Destruction?

How the DIN 66399 material classes work

One of the most useful features of the DIN 66399 standard is that it does not treat all media the same. It groups information carriers into material classes, then applies graded security levels within each, so the destruction requirement always matches the way the data is physically stored. This is why a single shred size cannot be correct for every device.

Paper and optical media

Printed records and optical discs fall into their own classes, with progressively smaller particle sizes at higher security levels. For businesses retiring IT this matters because confidential paper records and backup discs often leave the building alongside drives, and they should be destroyed to an appropriate level rather than simply binned.

Magnetic drives and electronic chips

Magnetic hard drives and electronic media such as SSD memory chips sit in separate DIN 66399 classes. The electronic-media class demands a finer particle size because data lives on tiny chips that a coarse shred could leave intact — the technical reason SSDs need more thorough destruction than spinning hard drives at the same security level.

How overwriting standards verify the result

Where physical destruction is measured by particle size, certified data erasure is measured by the overwrite process and, crucially, by verification. Recognised data sanitisation standards in the UK do not just specify that a drive is overwritten; they require the result to be checked and recorded, which is what separates a defensible certified data destruction standard from simply running a free utility.

Modern guidance has moved away from prescribing large numbers of overwrite passes towards verified single-pass or hardware-based methods, reflecting how today's drives store data. The principle that matters for an audit is the same: every addressable sector is overwritten, the overwrite is verified, and a per-drive record ties the result to a serial number so the outcome can be proven later.

How Ewaste.org.uk applies these standards

We match the method and standard to the sensitivity of your data rather than applying a blanket approach. Healthy drives can be erased to a recognised standard with a verified, per-drive record, while sensitive media and SSDs are physically destroyed to an appropriate DIN 66399 security level. As a registered upper-tier waste carrier certified to recognised information-security and environmental management standards, we name the standard achieved on your Certificate of Destruction and recycle the residue through a zero-to-landfill process.

If you are unsure which security level your data warrants, our team can advise before collection so the right standard is specified from the outset — you can reach us on 020 4524 7964.

Need help with this? Learn more about our secure data destruction service or arrange a free, no-obligation collection today.

Ready to book a free collection?

Free, compliant, nationwide WEEE collection for UK businesses — with full documentation as standard.

Frequently asked questions

What is the difference between NCSC guidance and DIN 66399?

NCSC guidance is the UK government's authority on secure data sanitisation and disposal, often referenced in public-sector contracts. DIN 66399 is a technical standard that defines media classes, security levels and shred particle sizes. They complement each other.

What DIN 66399 level do I need for hard drives?

It depends on data sensitivity. General business data may need a lower level, while confidential, personal or regulated data calls for higher levels with smaller particle sizes. A provider can advise the right level for your risk profile.

Do I need a provider certified to ISO 27001?

It is strongly recommended. ISO 27001 shows the provider's information security processes are independently audited rather than merely claimed, which gives you confidence your data is handled correctly throughout destruction.

Should the standard appear on my destruction certificate?

Yes. A good Certificate of Destruction names the method and the standard met, so the document itself proves the destruction reached the required benchmark. Ask for serial-level detail for sensitive equipment.

Is overwriting to a standard as good as shredding?

For working hard disk drives, certified overwriting to a recognised standard is highly secure. For SSDs, failed drives and the most sensitive data, physical shredding to a high DIN 66399 level is the safer choice.

Why do SSDs need a higher DIN 66399 level than hard drives?

SSDs fall into the electronic-media class, where data is held on small memory chips. A coarse shred could leave a chip intact, so the standard requires a finer particle size to ensure no chip survives in a readable state.

Are these standards a legal requirement in the UK?

The standards themselves are not statutes, but UK GDPR requires appropriate technical and organisational measures, and public-sector contracts often mandate NCSC alignment. Destroying to a recognised standard is the practical way to evidence that you met those obligations.

Related articles