ITAD e valorizzazione degli asset IT aziendali
Secure data erasure is a professional service for companies that need to decommission, transfer or reuse IT devices while ensuring that the information stored on them cannot be recovered. MGK Tech, operating in the Parma and Fidenza area, provides the service with device collection throughout Italy and manages the entire process: from IT asset inventory to certified erasure of hard drives, SSDs and storage media, through to the remarketing of devices that are still functional. For an initial assessment of the assets to be processed, you can contact the technical team and request an evaluation.
Secure data erasure applies to every stage in the lifecycle of a corporate IT device: hardware refreshes, server decommissioning, the return of end-of-lease notebooks and the disposal of removable media. In all these situations, the data stored on the media must be made unrecoverable before the device leaves the company environment, regardless of the hardware's final destination.
Secure erasure is required whenever a corporate IT asset changes status: technology refreshes involving the transfer of replaced devices, decommissioning of end-of-life servers or storage systems, return of notebooks at the end of an operating lease, sale or donation of used hardware, or disposal of equipment that is no longer functional. In each of these cases, corporate and personal data stored on the media may remain accessible through standard data recovery tools even after conventional formatting.
The risk concerns not only strategic company information but also the personal data of employees, customers and suppliers. The management of this information falls within GDPR obligations and, in the event of a personal data breach, may involve specific notification obligations to the Italian Data Protection Authority. A device that is transferred, disposed of or reused without verified erasure may therefore expose the company to legal liability, reputational damage and potential disputes concerning data protection.
Standard formatting of a hard drive or SSD does not erase the data: it removes the logical references to files while leaving the underlying content on the storage medium. Publicly available data recovery software can restore deleted files or formatted partitions on mechanical hard drives in a matter of minutes and, in many cases, can also recover data from SSDs whose firmware has not been properly managed.
Secure erasure instead requires a certified data-wiping process that overwrites each sector of the storage medium with random or predefined data sequences, making previously stored information unrecoverable. For SSDs, overwriting must take account of flash-memory architecture and wear-levelling mechanisms, which distribute writes across cells other than those that appear to be directly addressed. For physically damaged or unusable media, data wiping is replaced by degaussing or physical destruction.
MGK Tech provides a structured service covering every stage, from taking custody of IT assets to delivering the final documentation. The service is designed for companies with hardware estates of any size, from individual batches to hundreds of devices, and adapts to operational requirements through on-site service, device collection or a combination of the two.
MGK Tech records devices, serial numbers, storage media and functional status, creating a verifiable basis for processing.
The service can include device collection throughout Italy, on-site work or a combined approach depending on the hardware estate.
Data is erased using secure, documented procedures. At the end of the process, documentation is provided for audit and traceability purposes.
Before the technical work begins, an inventory is created of the IT assets to be processed. For each device, the serial number, model, type of storage medium and functional status are recorded. The information collected forms the basis of the final report and the documentation relating to the erasure operations performed.
The erasure method is selected according to the type of storage medium, its condition and the level of documentation required. For functioning HDDs and SSDs, software-based procedures using BitRaser may be used, configured in line with the technical guidance of NIST SP 800-88 for media sanitisation.
Depending on the characteristics of the device, treatment may include verifiable data wiping, secure erase or sanitize commands, or cryptographic erasure where supported. For each processed medium, a certificate can be produced containing identification data, the method applied and the verification outcome.
On request, data erasure can also be carried out on-site at the customer's premises. This allows work to be performed on PCs, notebooks, servers, hard drives, SSDs and other storage media without moving the devices off-site, while maintaining full traceability of the operations performed.
When a storage medium is damaged, cannot be detected or cannot be reliably erased using software, irreversible procedures may be adopted. Degaussing may be used for magnetic HDDs, while physical destruction may be required for SSDs and unreadable media. The work can be accompanied by technical documentation, serial-number recording and certification of the operation performed.
The service covers the main devices and storage media found in corporate IT estates: mechanical hard drives, SSDs, NVMe drives, servers, storage systems, flash memory, USB drives, memory cards and, where technically feasible, corporate smartphones containing data that must be protected.
The technical characteristics of the storage medium determine which methods can be applied. SSDs using NAND memory require procedures that are compatible with firmware operation, while servers and storage systems may require individual disks or arrays to be handled separately. For this reason, the treatment method is defined case by case after the hardware configuration has been assessed.
The secure data erasure service follows a documented process, from taking custody of the devices through to production of the final report. Each asset is identified and linked to the operations performed so that the treatment path and its outcome can be verified.
When devices are taken into custody, each one is recorded with its make, model, serial number, storage-media type and capacity, and functional status. The initial documentation records the assets received, the date of the work and the information required for subsequent traceability.
The technical assessment comes before selection of the erasure method. A functioning medium may undergo software-based data wiping, while an undetectable device or one with physical faults may require degaussing or destruction. The method applied is recorded for each asset.
At the end of the process, a report is produced which may include the list of processed media, serial numbers, the method applied, the relevant technical standard or reference, the verification outcome and the date of the work. An individual certificate may be issued for media processed using software-based erasure.
The documentation can be used for internal controls, compliance checks and reporting processes relating to the management of corporate data. The GDPR accountability principle requires the data controller to be able to demonstrate the adoption of technical and organisational measures appropriate to the protection of personal data.
Responsibility for data stored on corporate devices does not end when the hardware is removed from operational use. As long as a storage medium contains personal data, credentials or confidential information, the organisation must adopt appropriate measures to prevent unauthorised access.
Regulation (EU) 2016/679 requires personal data to be processed using appropriate security measures throughout its lifecycle. Article 5(1)(f) establishes that data must be protected against unauthorised or unlawful processing and against accidental loss, destruction or damage.
Corporate devices may contain employee and customer data, accounting documents, contracts, credentials, commercial information and intellectual property. Transferring or reusing a device without adequate erasure can lead to unauthorised access to information and, where applicable under the GDPR, may constitute a personal data breach that must be assessed under the organisation's internal procedures.
Data erasure should be assessed before any new destination is assigned to a device: internal reuse, reassignment to another employee, sale, return to a supplier, donation or permanent removal from the IT estate. The erasure process must be completed before the device leaves the company's possession and control.
Internal reuse may also require removal of data associated with the previous user or department. Entrusting the work to a specialised operator makes it possible to apply procedures appropriate to the storage technology and obtain documentation of the operations performed.
Secure data erasure can be combined with an assessment of assets that are still functional. Once the storage media have been processed, devices with suitable technical characteristics can be evaluated for reuse, refurbishment, remarketing or buyback.
Devices that pass the functional assessment can be evaluated for hardware remarketing. Residual value is determined by considering the model, year, configuration, cosmetic condition and state of the components. For corporate batches, the assessment may result in an overall commercial proposal.
Buyback is one of the options available to companies that wish to transfer assets that are still usable. After data erasure and technical assessment, suitable devices can be refurbished and returned to the market through professional channels.
Secure data erasure makes it possible to keep using devices that still have suitable technical and functional characteristics. Notebooks, desktops, workstations, servers and storage systems can therefore be assigned to a new use without retaining information linked to the previous user.
Reuse and refurbishment extend the working life of hardware and allow the owning company to recover part of the residual value of assets that are no longer required for its operations.
| Scenario | Erasure method | Documentation | Treatment outcome |
|---|---|---|---|
| Functioning HDD or SSD | Data wiping with BitRaser | Certificate for each storage medium | Reuse, refurbishment or remarketing |
| Magnetic HDD that cannot be erased | Degaussing | Certificate of work performed | Storage medium rendered unusable |
| Unrecoverable storage medium | Physical destruction | Certification and, where applicable, photographic documentation | Storage medium rendered unusable |
| Server or storage system | Processing of individual disks and array inventory | Report on processed assets | Technical assessment of the system |
The secure data erasure service is intended for organisations that manage IT devices containing personal data, credentials or confidential information. Operating methods are defined according to the number of assets, the type of storage media and the customer's traceability requirements.
Companies that regularly renew their IT estate may need to manage batches made up of notebooks, desktops, workstations, servers and different types of storage media. In these cases, a structured process can be planned that links each device to the erasure method applied and the corresponding documentation.
IT managers, DPOs and compliance teams can use the reports produced to verify the work carried out and incorporate the documentation into their internal control processes.
The service can also be requested for individual devices, such as a server that is no longer used, a notebook to be transferred or a hard drive that needs to be replaced. The operating method and documentation are defined according to the storage medium and the required level of traceability.
For organisations with recurring requirements, an ongoing process can be established with consistent operating methods and documentation across different intervention cycles.
To start the service, some preliminary information about the assets to be processed is required. This information makes it possible to identify the applicable methods, estimate time and costs, and determine whether any devices still have recoverable value.
For an initial evaluation, it is useful to provide the type and number of devices, the storage media present, their approximate functional condition, the level of documentation required and the expected timing of the work.
The information can be supplied through an existing inventory or a preliminary list. For large batches, an inventory activity at the customer's premises may be considered.
Based on the information received, a quotation is prepared specifying the erasure methods, included documentation, operating arrangements, expected timing and any valuation of reusable devices. The work can be organised at the customer's premises or through collection of the devices, depending on the characteristics of the batch.
© 2026 MGK Tech – Via Cardano, 28/A – 43036 Fidenza (PR) – P. IVA: IT 02820420343 – Privacy Policy
WhatsApp us