Skip to content

United Kingdom · original

NIST SP 800-88 in a UK GDPR ITAD file

UK GDPR does not name NIST. Auditors do. RecyclicTech writes NIST SP 800-88 Rev. 1 on the certificate because it is the method we actually run: Clear, Purge or Destroy, chosen in the assessment, named per serial. IEEE 2883 exists for some flash media; we will name it when that is the method that ran. We will not print “DoD 3-pass” theatre or a factory reset dressed as Purge.

UK aisle through open racks — media sanitisation is specified per serial, not per hall

What to take from this page

  • NIST SP 800-88 is the named method on RecyclicTech UK certificates.
  • Clear / Purge keep residual value when reuse is allowed.
  • Destroy is for failed media or a no-reuse brief.
  • A recycling ticket does not name a sanitisation method.

Why a US publication sits on a UK file

Because UK GDPR asks for appropriate technical measures and proof, not a branded PDF. NIST SP 800-88 is the language UK ITAD buyers and auditors already use. RecyclicTech will not invent a “UK GDPR wipe standard” that does not exist.

What we will not certify

DBAN screenshots, BitLocker key deletion, a format, a three-pass myth, or a skip. If erase fails, that serial is destroyed and the exception is on the same file.

Official sources

Written 2026-08-28. Not a paraphrase of the pages currently ranking for this query.

Questions

Straight answers.

Is NIST 800-88 required by UK law?+

No statute names it. UK GDPR names accountability. RecyclicTech uses NIST because it is checkable. We do not pretend it is an ICO licence.

Do you also use IEEE 2883?+

When that is the method that ran on the media. The certificate names the method. We do not print both for show.

Is shredding more compliant?+

Not automatically. Documented Purge can be appropriate. Shredding saleable drives is waste, not extra GDPR.

Will you certify a factory reset?+

No.