Nabel Solutions

Resources

How long must you keep a certificate of destruction?

Three to seven years is the working answer. The real answer is set by your client's regulator, not by your client — and often not by anything they will tell you unprompted.

Applies toUnited States

Published August 17, 2026 · Last checked August 17, 2026

Three to seven years covers most of it. Six years if the device held protected health information, seven if your client is a publicly traded company or a law firm, and seven as a safe default when you cannot establish which applies. Keep the evidence behind the certificate for the same period, not just the certificate itself.

The reason this question is hard to answer cleanly is that the obligation is not yours. It belongs to whoever owned the data, and it is set by their regulator. You are holding a record on someone else’s behalf, against a rule neither of you chose.

The obligation flows from the data, not from the contract

An ITAD operator does not have a retention period. Their clients do — and their clients’ regulators set it.

A hospital’s obligation under HIPAA does not disappear because the drives were destroyed by a third party. It follows the evidence. When the auditor asks the hospital to produce proof that a specific device was destroyed, the hospital comes to you. If you disposed of that record after three years and their obligation was six, the gap is theirs — but the failure is yours to have caused.

This is why “we keep certificates for three years” is a reasonable general policy and a dangerous one the moment you win a healthcare client.

What the common regimes require

Regime Retention required Applies to
HIPAA Six years, from creation or the last effective date, whichever is later Healthcare clients, protected health information
SOX Seven years Publicly traded company clients
PCI DSS No fixed period for destruction records. You must define, document and justify your own. Log retention is at least twelve months Card data environments
Massachusetts 201 CMR 17 Part of the WISP audit trail, retained while the program is active Any business holding personal information of Massachusetts residents
Legal and professional services At least seven years, commonly matching the client file Law firm and professional services clients
General commercial Three to seven years. Retain longer rather than shorter when unsure Everything else

Two of those deserve a note. HIPAA’s six years runs from creation or the last effective date, whichever is later — so a record attached to a policy that was current until 2028 starts its six years in 2028, not on the day you issued it. And PCI DSS does not give you a number. It requires you to have decided one and be able to explain it, which is a different and slightly harder thing.

Working it out when the client cannot tell you

Most operations directors have had this conversation: you ask the client how long they need the certificates kept, and they do not know either. Working it out from first principles takes four questions.

  1. What was on the device? Health information, cardholder data, personal information of residents of a specific state, financial records. The data class determines the regime, not the device type.
  2. Who was the data controller? Not who handed you the asset — who owned the data on it. A managed service provider delivering drives on behalf of a hospital inherits the hospital’s clock.
  3. What binds them? A publicly traded healthcare provider is subject to both HIPAA and SOX. Where two regimes apply, the longer one governs in practice.
  4. What does your contract say? A retention term in the service agreement is binding on you regardless of what the regulation requires. Contracts sometimes specify shorter periods than the regulation, which is a problem worth raising before signing rather than after.

When you cannot establish the answer, keep it for seven years and write down why. Seven covers every common regime in the table. The written note matters as much as the period: a decision you can explain is defensible, and an arbitrary one is not.

Retention applies to the evidence, not only the certificate

This is the part most operators get wrong, and it is the expensive one.

A certificate of destruction is a summary. What makes it hold up under challenge is what sits behind it — the per-device record showing the serial, the method, the date, the operator who confirmed it, and the capture that proves the serial was read from that device rather than typed from memory.

If you keep the PDF for seven years but the underlying records roll off after one, you have kept the claim and discarded the proof. An auditor testing a single line on a certificate will ask for exactly the thing you no longer have.

Retention should be set on the record set as a whole, and it should be technically enforced rather than left to whoever remembers to run the archive.

A practical policy

For an operator serving mixed clients, a workable position:

  • Default to seven years for all destruction records and their supporting evidence.
  • Record the applicable regime per client at onboarding, not at disposal. By the time the drives arrive, nobody is asking.
  • Set retention on the whole record set, not just the certificate.
  • Make deletion an event you can evidence. When a record does reach the end of its period, the fact that it was disposed of on purpose, on a date, under a policy, is itself worth being able to show.
  • Review it when you win a client in a new sector. A healthcare or public company win changes your obligations on the day the contract is signed.

What this is not

This is a summary written for operations directors, not legal advice. Retention law varies by state and by sector, contracts override defaults in both directions, and the position changes. The links below go to the primary sources so you can check them, and anything with real money attached deserves a professional opinion rather than an article — including this one.

We're on a mission to bring automation to ITAD

Interested in hearing more, or got something you'd like to talk through? Get in touch.