Jakub Wolanski, Founder, CirculaTech
When a drive fails erasure, it must not simply be re-run until it passes. A defensible process quarantines the device, records the failure against its serial number, and routes it to verified physical destruction — with both the failure and its resolution visible in the same audit trail you receive for every other device.
Why would a drive fail erasure in the first place?
Failures are normal. In any fleet of a few hundred retired machines, some proportion will not sanitise cleanly on the first pass. The common causes are mechanical and technical rather than procedural:
A drive may be physically failing — bad sectors or a degrading read/write head mean the software cannot confirm every addressable block was overwritten. A SATA drive may be in a frozen security state, where the host controller has locked the ATA security feature set and the sanitise command cannot be issued. Hidden areas such as a Host Protected Area or Device Configuration Overlay may not be reachable by a standard overwrite. A self-encrypting drive may not surrender its key, making cryptographic erase impossible to confirm. Or a controller may simply stop responding mid-process.
Flash storage adds its own difficulty. On SSDs and other flash media, wear-levelling and over-provisioning mean a portion of the physical NAND is not addressable by the host at all, so a host-issued overwrite cannot be verified across the full physical medium. This is why the standards treat flash differently from magnetic media, and why “we wrote zeroes over it” is not a sanitisation claim.
None of this is a problem. The problem is what happens next.
What should happen when a device fails?
The failure needs to become a recorded event with a defined outcome, not a silent retry.
The device is removed from the resale stream immediately and held in a controlled area. It does not re-enter the pass queue.
Serial number, method attempted, technician, date, result: fail. The failed attempt stays in the record permanently.
Where sanitisation cannot be verified, the medium is physically destroyed by a method appropriate to its type.
Physical inspection, documented — the only verification method available once a medium has been destroyed.
The destruction record is issued against the same serial number as the failure. No orphan devices.
The step most often missed is the fifth. A provider will happily send a clean certificate pack covering the 480 devices that passed, and quietly omit the twenty that did not. From your side, the count reconciles against nothing — and twenty unaccounted devices is precisely the shape of an incident nobody notices until it becomes one.
Ask for the reconciliation, not the certificate pack. Devices collected should equal devices sanitised plus devices destroyed, by serial number, with no remainder.
Isn’t degaussing the standard answer for a failed drive?
For a magnetic hard disk, degaussing remains a recognised purge technique. For flash media it is not.
NIST SP 800-88 Revision 2, published on 26 September 2025, discourages degaussing on non-magnetic media such as SSDs and flash storage, because it is ineffective — flash cells store charge rather than magnetic states, so a magnetic field does nothing to the stored data. Worse, degaussing can damage the device enough to make it unusable while leaving the data intact and recoverable by a laboratory. The organisation ends up with a destroyed asset and an unsanitised one.
Physical destruction of flash media also requires more than a coarse shred. A single intact NAND package can retain recoverable data, so destruction methods for flash must reduce the medium far more finely than is necessary for a hard disk platter. If a provider quotes one shredding process for every media type, that is worth a question.
We covered the wider set of Revision 2 changes in our breakdown of NIST SP 800-88 Revision 2.
What counts as verified, and who verifies it?
IEEE 2883-2022 — the storage sanitisation standard that Revision 2 aligns with — sets out distinct verification techniques for each outcome. For Clear, verification is by representative sampling, reading random locations covering at least 5% of the addressable space. For Purge, verification is full: the entire addressable space is read and compared against expected sanitised values. For Destruct, physical inspection is the only available verification method.
That last point is the one to hold onto. Once a drive has been destroyed, no software can confirm anything about it. The only evidence available is a record made by a person, at a known place and time, describing what was destroyed and how. Which means the credibility of a destruction claim rests entirely on the documentation discipline of the provider making it.
CirculaTech uses Blancco software-based erasure, which issues a digitally signed report per device recording the hardware details, the method used and the pass or fail result. Blancco Drive Eraser is independently certified by ADISA against both NIST SP 800-88 Revision 2 and IEEE 2883. Devices that cannot be verifiably sanitised are quarantined and destroyed, and the destruction is recorded against the same serial number — so the reconciliation always closes.
How does this connect to your obligations under APP 11?
Australian Privacy Principle 11.2 requires an entity to take reasonable steps to destroy or de-identify personal information it no longer needs. Since December 2024, APP 11.3 has made explicit that reasonable steps include both technical and organisational measures.
An exception path is an organisational measure. Having erasure software is technical; having a documented, followed process for what happens when the software says “fail” is organisational — and it is the part that demonstrates the steps were reasonable rather than merely attempted. We have written in more detail on what “reasonable steps” means under APP 11.
If your current provider cannot describe their exception path without checking, you do not have one.
Three questions to ask before your next collection
Ask what the failure rate was on your last batch, and what happened to those devices. A provider who has never had a failure is either not testing or not telling.
Ask whether the failure appears in the report you receive, or only the eventual pass. Failures that are erased from the record are not failures that have been managed.
Ask what destruction method is used for flash versus magnetic media, and how the destruction is verified and evidenced. One answer for both media types is a warning sign.
You can read more about how CirculaTech documents the chain from collection to certified disposition on our security and compliance page.
FAQ
Is a failed data erasure a sign of a bad provider?
No. Failures happen in every fleet — drives fail mechanically, security states lock, controllers stop responding. What distinguishes a good provider is whether the failure is recorded and resolved, not whether it occurred.
Can a drive that fails erasure be safely resold?
Not unless it is subsequently sanitised by a verified method. If sanitisation cannot be verified, the medium must be physically destroyed. Residual value never justifies an unverified device leaving the chain.
Why can’t you just degauss an SSD?
Degaussing works by disrupting magnetic domains. SSDs and flash media store data as trapped charge in cells, not magnetically, so degaussing does not remove the data. NIST SP 800-88 Revision 2 discourages it on non-magnetic media, and it can render the device unusable while leaving data recoverable.
How is physical destruction verified?
By physical inspection, documented at the time. Under IEEE 2883-2022, inspection is the only verification method available for the Destruct outcome — software verification is impossible once a medium is destroyed, so the record made by the technician is the evidence.
What should the final report show?
Every device collected should be accounted for by serial number, with its method, technician, date and outcome — sanitised or destroyed — and no remainder between devices collected and devices resolved.