A Global View of Data Destruction Standards

Data destruction is not just a local compliance matter. Organisations operating internationally, handling data from overseas clients, or seeking best-practice benchmarks need to understand how different global standards approach the challenge of securely eliminating data from IT equipment.

While Australia does not have a single national data destruction standard, Australian organisations commonly reference a range of international frameworks. Understanding the differences between these standards helps organisations select the right approach for their specific compliance requirements and risk profile.

NIST 800-88 (United States)

The National Institute of Standards and Technology’s Special Publication 800-88, “Guidelines for Media Sanitization,” is arguably the most widely referenced data destruction standard globally. Originally published in 2006 and revised in 2014, it provides a systematic framework for selecting sanitisation methods based on the confidentiality level of the data and the type of storage media.

NIST 800-88 defines three levels of sanitisation. Clear uses logical techniques to overwrite data in all user-addressable storage locations, protecting against simple non-invasive data recovery. Purge applies physical or logical techniques that make data recovery infeasible using state-of-the-art laboratory techniques. Destroy renders the media physically unusable and data recovery infeasible.

The standard’s strength lies in its decision framework, which guides organisations through selecting the appropriate sanitisation level based on a risk assessment. For a detailed exploration, see our guide to NIST 800-88.

DoD 5220.22-M (United States)

The Department of Defense Standard 5220.22-M was once the most commonly cited data destruction standard, particularly its three-pass overwrite procedure. However, it is important to understand that the DoD has largely moved away from overwriting as a primary sanitisation method and now references NIST 800-88 for media sanitisation guidance.

The original DoD 5220.22-M three-pass method involves writing a character, writing the complement of that character, and then writing a random character, with verification after each pass. While this method remains effective for traditional magnetic hard drives, it was not designed for modern storage technologies like SSDs, which use wear levelling and over-provisioning that can leave data remnants untouched by overwrite operations.

Organisations that still reference DoD 5220.22-M should be aware that it is no longer considered sufficient as a standalone standard for all media types and should be used in conjunction with NIST 800-88 guidance.

IEEE 2883 (International)

Published in 2022, IEEE Standard 2883 for Sanitizing Storage is the newest major standard in this space. It was developed specifically to address the limitations of older standards when applied to modern storage technologies, including SSDs, NVMe drives, and flash-based media.

IEEE 2883 defines three sanitisation categories: Clear, Purge, and Destruct, similar to NIST 800-88 but with updated technical guidance that accounts for the characteristics of modern storage devices. The standard includes specific methods for each media type and addresses technologies that did not exist when NIST 800-88 was last revised.

For organisations looking for the most current technical guidance on sanitisation methods, IEEE 2883 represents the leading edge of the field.

BSI/ADISA (United Kingdom)

The Asset Disposal and Information Security Alliance (ADISA) operates a certification scheme for IT asset disposal companies based in the United Kingdom and internationally. ADISA certification involves rigorous auditing of a provider’s processes, facilities, and staff, with a focus on the practical security of the entire disposal chain rather than just the destruction method itself.

The ADISA standard is complemented by the British Standards Institution’s PAS 141:2011 (Reuse of used and waste electrical and electronic equipment) and various BS EN standards related to data destruction. ADISA’s Claims Testing framework independently verifies whether claimed sanitisation methods actually achieve the stated level of data elimination.

For Australian organisations that work with UK clients or that want to benchmark against a rigorous international scheme, ADISA certification provides a high level of assurance.

DIN 66399 (Germany)

The German standard DIN 66399 takes a different approach by classifying data carriers into categories and defining specific particle sizes for physical destruction at different security levels. The standard defines seven security levels (P-1 through P-7) for paper and six corresponding levels for electronic media, with higher levels requiring smaller particle sizes.

For physical destruction of hard drives, DIN 66399 specifies maximum particle sizes ranging from 2,000 mm² at security level H-1 to 10 mm² at security level H-7. This granular approach provides clear, measurable benchmarks for physical destruction that are straightforward to verify.

DIN 66399 is widely used in Europe and is particularly relevant for organisations that process data subject to the GDPR, as European data protection authorities commonly reference this standard when assessing the adequacy of destruction methods.

AS/NZS 5377 (Australia/New Zealand)

Australia’s own AS/NZS 5377 standard covers the collection, storage, transport, and treatment of end-of-life electrical and electronic equipment. While it is primarily an e-waste management standard rather than a data destruction standard specifically, it includes requirements for data sanitisation as part of the treatment process.

AS/NZS 5377 is most relevant for organisations seeking an Australian-certified disposal provider and for demonstrating compliance with domestic e-waste regulations. For data destruction specifically, it is typically used in conjunction with NIST 800-88 or another dedicated data sanitisation standard.

The Australian Government Information Security Manual (ISM)

The ISM, maintained by the Australian Signals Directorate (ASD), provides guidance on media sanitisation and destruction for Australian government agencies. While not a formal standard in the same sense as NIST 800-88, the ISM specifies destruction requirements based on the classification level of the data (OFFICIAL, PROTECTED, SECRET, TOP SECRET).

For higher classification levels, the ISM requires physical destruction methods that render the media irrecoverable. The specific requirements vary by media type and classification level, and they are regularly updated to reflect changes in technology and threat landscape.

Choosing the Right Standard

Selection guidance: For most Australian organisations, NIST 800-88 provides the most practical and widely accepted framework for data destruction. Supplement this with AS/NZS 5377 for e-waste handling compliance, DIN 66399 for physical destruction benchmarks if you process GDPR-subject data, and the ISM if you handle government-classified information. Where clients or contracts specify a particular standard, that requirement takes precedence.

No single standard covers every scenario, and many organisations reference multiple standards depending on the data type, media type, and compliance context. The key is to document which standards you follow, apply them consistently, and maintain records that demonstrate compliance. For more on how different destruction methods compare, see our detailed guide.

EWV provides NIST 800-88 certified data destruction for Victorian businesses, covering software-based erasure and physical destruction with full chain-of-custody documentation. Request a quote to discuss your requirements.