Why PCI DSS Extends to Equipment Disposal

Any organisation that processes, stores, or transmits credit card data is subject to the Payment Card Industry Data Security Standard (PCI DSS). Most businesses understand this applies to their active payment systems, but PCI DSS requirements follow cardholder data throughout its entire lifecycle, including when the equipment holding that data is decommissioned.

If your point-of-sale terminals, payment servers, workstations, or any other equipment has ever processed or stored cardholder data, PCI DSS dictates how that equipment must be handled when it reaches end of life.

The Relevant PCI DSS Requirements

PCI DSS version 4.0, which became mandatory in March 2025, contains several requirements directly relevant to IT equipment disposal:

Requirement 3: Protect Stored Account Data. This requirement mandates that stored cardholder data be rendered unrecoverable when no longer needed for business, legal, or regulatory purposes. “Unrecoverable” means the data cannot be retrieved by any known method. This directly applies to data on decommissioned equipment.

Requirement 9: Restrict Physical Access to Cardholder Data. This covers the physical security of systems that store cardholder data, including during the disposal process. Equipment awaiting destruction must be stored securely, and the destruction process itself must be controlled and documented.

Requirement 12: Support Information Security with Organisational Policies and Programs. This requires documented policies covering all aspects of cardholder data protection, including disposal procedures. Your organisation’s information security policy must explicitly address how equipment containing cardholder data is decommissioned and destroyed.

PCI DSS 4.0 disposal-related requirements:

  • Req. 3.1: Minimise data storage; destroy when no longer needed
  • Req. 3.2: Do not store sensitive authentication data after authorisation
  • Req. 9.4: Protect media containing cardholder data against physical threats
  • Req. 9.4.7: Destroy media when no longer needed for business or legal reasons
  • Req. 12.1: Establish documented security policy covering disposal

What Equipment Is in Scope

Many organisations underestimate the range of equipment that falls within PCI DSS scope for disposal. Any device that processes, stores, or transmits cardholder data is in scope, including:

Point-of-sale (POS) terminals and payment terminals. Payment processing servers and databases. Workstations used to access payment systems. Network equipment in the cardholder data environment (routers, switches, firewalls). Backup storage containing cardholder data. Printers and multifunction devices used to print receipts or reports containing card data. Mobile devices used for payment processing. USB drives or external storage used to transfer cardholder data. Call recording systems if they capture card numbers read aloud.

Devices in the “connected to” or “security-impacting” categories (those that share a network segment with cardholder data systems) may also require secure disposal, depending on your segmentation and scope definition.

Approved Destruction Methods

PCI DSS requires that cardholder data be rendered unrecoverable. The standard doesn’t prescribe specific technical methods but references industry standards and best practices. The PCI Security Standards Council (PCI SSC) guidance points to several accepted approaches.

For electronic media: Overwriting with a program that meets industry-recognised standards (NIST 800-88 is the most commonly referenced). Degaussing for magnetic media. Physical destruction (shredding, disintegration, incineration, or pulverisation) that renders the media physically incapable of storing data.

For paper media: Cross-cut shredding, incineration, or pulping. Strip-cut shredding alone is generally not considered sufficient for sensitive data.

The chosen method must be appropriate for the media type. Software overwriting works for HDDs but may not be sufficient for SSDs due to wear levelling and over-provisioned areas. For SSDs, cryptographic erasure (if the drive was encrypted from the start) or physical destruction is typically recommended.

Documentation and Verification

PCI DSS places significant emphasis on documentation throughout the disposal process. A QSA (Qualified Security Assessor) conducting your PCI audit will expect to see:

A documented data destruction policy that specifically addresses cardholder data. An inventory of all equipment in the PCI scope. Records of each disposal event including the date, method used, individual asset identifiers (serial numbers), the name of the person or organisation performing the destruction, and verification that destruction was successful.

Certificates of destruction from your disposal provider should include enough detail to demonstrate compliance. Vague certificates that say “equipment was destroyed” without specifics are insufficient. Each certificate should list individual assets by serial number, the destruction method applied to each, the standard followed, and the date and location of destruction.

Retain destruction records for as long as your PCI compliance documentation requires, typically a minimum of one year for operational records, though many organisations retain them longer.

Third-Party Disposal Providers

If you outsource equipment disposal, your PCI DSS compliance obligations extend to managing that third-party relationship. PCI DSS Requirement 12.8 specifically addresses service provider management and requires that you maintain a list of all service providers with whom cardholder data is shared, maintain a written agreement acknowledging their responsibility for data security, establish a process for due diligence before engaging them, and monitor their compliance status at least annually.

For disposal providers specifically, this means conducting due diligence before engaging them (checking certifications, facilities, processes, and references), including PCI-specific requirements in your contract, requiring detailed certificates of destruction, verifying they maintain appropriate certifications (ADISA, ISO 27001, etc.), and conducting periodic reviews of their compliance.

If your disposal provider is processing cardholder data as part of the destruction process (for example, by handling equipment that still contains active cardholder data), they may need to be PCI DSS compliant themselves, or you need to have appropriate controls in place to manage the risk.

Common Audit Findings

These disposal-related issues frequently appear in PCI DSS assessments:

Incomplete scope identification: Organisations miss devices that were in the cardholder data environment. An old POS terminal that was replaced but not formally decommissioned still appears on the network diagram but has no disposal record.

Inadequate destruction methods: Using simple formatting or factory resets instead of industry-standard overwriting or physical destruction. SSDs wiped using HDD-oriented methods that don’t address SSD-specific data persistence.

Missing documentation: Disposal happened but there’s no certificate, no record of method, or no way to link a specific destruction record to a specific asset in the inventory.

Unmanaged service providers: Disposal vendors used without a formal agreement, without due diligence, or without ongoing monitoring of their practices.

Delayed destruction: Equipment containing cardholder data sitting in storage rooms or warehouses for extended periods awaiting disposal, without adequate physical security controls during the waiting period.

Best Practices for PCI-Compliant Disposal

PCI DSS disposal best practices:

  • Maintain a current inventory of all equipment in PCI scope
  • Destroy cardholder data promptly when no longer needed
  • Use destruction methods appropriate to the media type and data sensitivity
  • Verify destruction through testing or provider certification
  • Document every disposal with asset-level detail
  • Secure equipment physically from decommission to destruction
  • Vet disposal providers and include PCI requirements in contracts
  • Include disposal processes in your regular PCI internal audits

PCI DSS compliance doesn’t end when you stop using a device for payment processing. It ends when the cardholder data on that device has been verifiably destroyed. Building robust disposal processes into your PCI compliance program prevents audit findings, reduces breach risk, and demonstrates the kind of comprehensive data protection that card brands and acquirers expect.

For more on data destruction methods and standards, see our NIST 800-88 guide and our complete guide to data destruction.

EWV handles IT asset disposition (ITAD) end-to-end for Victorian businesses — from collection and data destruction through to certified recycling or refurbishment for resale. Get in touch for a tailored ITAD quote.