PRODUCT · HARDWARE DATA DESTRUCTION · NIST 800-88
Secure data destruction for retired devices and storage media.
Data Sanitization helps organizations ensure sensitive data does not remain on retired devices through a secure, documented, and auditable destruction process.
ABOUT DATA SANITATION
Erase is not enough — sanitize.
Standard deletion (Delete, Format, factory reset) only removes the pointer to data — the physical bits remain on disk and can be recovered with commercial recovery tools. Indonesian regulators know this. UU PDP Article 44 mandates "pemusnahan" (destruction), not just deletion, when personal data is decommissioned. POJK 11/2022 includes "penghentian dan penghapusan sumber daya teknologi informasi" as a regulated phase of IT lifecycle. Permenkes 24/2022 requires hospitals to destroy electronic medical records after the 25-year retention window — using methods that guarantee non-recoverability.
Data Sanitization is the secure and permanent removal of sensitive data from storage media (HDD, SSD, tape, USB) so that no residual data can be recovered — even through laboratory-grade forensic analysis. The internationally recognized standard is NIST SP 800-88, with three categories: Clear (overwrite), Purge (advanced overwrite, cryptographic erase, or degaussing), and Destroy (physical destruction). ISO/IEC 27001 Annex A 7.14 and 8.10 provide the audit framework.
DTI delivers data sanitization as a chain-of-custody service: degaussing for magnetic media, physical destruction (shredding, crushing) for SSDs, and certified destruction reports (Berita Acara Pemusnahan) — the artifact your auditors and regulators ask for. We pick up media on-site, sanitize in our certified facility, and return signed destruction certificates per serial number.
TRUSTED BY
Trusted by institutions that manage sensitive data
Financial institutions and enterprises rely on DTI for secure, certified data sanitization across their device and storage lifecycle.
Bank BRI
Bank BNI
Bank BTN
BNI Sekuritas
Husky Energy
PT Margot Lestari
MuktiLogos are the property of their respective institutions.
MANAGED SERVICE — RECOMMENDED
We pick up, destroy, and certify — you keep the audit trail
DTI's chain-of-custody destruction service handles it end to end: sealed pickup from your site, certified sanitization by the right method for each medium, and a signed Berita Acara Pemusnahan per serial number. No machines to buy, run, or maintain.
Sealed pickup
Tamper-evident, GPS-tracked collection from your data center or office. Two-person rule for sensitive cargo.
Certified destruction
Degauss, destroy, or shred per media type and sensitivity — CCTV-witnessed, at our facility or on-site.
Berita Acara Pemusnahan
Signed destruction certificate per serial number — the artifact your auditors and UU PDP regulators require.
SANITATION METHODS
Three methods. One chain of custody.
Data Sanitization helps select the right method for each medium—from overwrite and degaussing to physical destruction—with auditable evidence.
Magnetic field erasure
Strong magnetic field exposure that disrupts magnetic alignment on HDDs and magnetic tapes. NIST "Purge" tier. Disk becomes unusable; data unrecoverable.
- For HDDs, magnetic tapes, LTO cartridges
- On-site mobile unit or DTI facility
- Coercivity tested per manufacturer spec
Shred & crush
Industrial shredding to NIST/NSA particle size for HDDs and SSDs. Solid-state media requires shredding (degaussing does not affect SSD flash cells).
- For HDDs, SSDs, M.2 NVMe
- NSA/CSS-aligned particle size
- CCTV-witnessed destruction
Encryption key destruction
For self-encrypting drives (SED) and cloud volumes — destroying the encryption key renders ciphertext unrecoverable. NIST "Purge" tier when properly implemented.
- For SEDs, encrypted SSDs, cloud volumes
- Faster than overwrite at scale
- Audit log of key destruction
Secure pickup & transport
Sealed-container collection from your data center or office. GPS-tracked vehicle transport. Tamper-evident packaging. Two-person rule for sensitive cargo.
- Sealed containers, tamper-evident
- GPS-tracked transport
- Two-person rule for sensitive media
Berita Acara Pemusnahan
Signed destruction certificate per serial number — the artifact your auditors and UU PDP regulators require. Includes method, witness, date, and disposal manifest.
- Per-serial-number certification
- Auditor-ready (POJK, UU PDP, Permenkes)
- Digital + physical signed copies
Regulatory alignment
Process mapped to UU PDP Articles 43-45, POJK 11/2022 IT lifecycle, Permenkes 24/2022 RME destruction, Peraturan BSSN 8/2020, plus international standards NIST SP 800-88 and ISO/IEC 27001 Annex A 7.14 + 8.10.
- UU PDP Art. 44 compliant
- POJK 11/2022 lifecycle phase
- Permenkes 24/2022 25-year window
METHODS
Not all erasure is equal
Security level by sanitization method (per NIST SP 800-88).
| Method | Avg time /100GB | Security | Notes |
|---|---|---|---|
| OS file deletion | Minutes | LOW | Only deletes the pointer — data is recoverable with recovery software. |
| Block overwrite (DoD 5220) | > ½ day | MEDIUM | Obsolete; may miss reassigned blocks. |
| NIST 800-88 Secure Erase | 30 min – 3 h | HIGH | In-drive erase of all user-accessible blocks. |
| Crypto-erase (Enhanced SE) | Milliseconds | HIGH | Destroys the drive encryption key — fast for SED/SSD. |
| Physical/magnetic destruction | Seconds–minutes | HIGHEST | Degauss / destroy / shred — required for top-secret data & SSD. |
HDD vs SSD
Different media need different methods
Degaussing only works on magnetic media. SSD/flash needs crypto-erase or physical shredding — never assume one method fits all.
| Method | HDD | SSD | Notes |
|---|---|---|---|
| Degaussing (magnetic) | ✓ | ✕ | SSD is non-magnetic — degaussing has no effect (NIST 800-88 / IEEE 2883). |
| Crypto-erase | △ | ✓ | For self-encrypting drives (SED/SSD); needs verification. |
| Physical destruction (shred) | ✓ | ✓ | SSD requires far smaller particle size than HDD. |
OR — RUN IT IN-HOUSE
Prefer to operate the machines yourself?
Buy the degausser, destroyer, or shredder and sanitize on your own schedule — for HDD & SSD. Most clients start with the managed service above.
USE CASES BY INDUSTRY
Where data sanitization closes the loop
Banking & FSI
ATM hard disk decommissioning, branch laptop refresh cycles, core banking server retirement, customer data destruction after retention window.
Healthcare
Electronic medical record destruction after 25-year retention, imaging workstation refresh, lab system decommissioning with patient data on disk.
Government & BUMN
Classified system decommissioning, ministry laptop refresh, BUMN data center hardware retirement, citizen data destruction per UU PDP Article 44.
Enterprise
End-of-life laptop fleets, data center storage refresh, M&A divestiture data segregation, employee personal data destruction after exit.
STANDARDS & REGULATIONS
Mapped to the rules your auditors cite
FAQ
Common questions
Does DTI provide a hard-drive data destruction service?
Yes. DTI provides managed data destruction for HDDs and SSDs — on-site or as a managed service — covering degaussing, physical destruction, and shredding, complete with a destruction certificate and audit evidence per NIST SP 800-88 and Indonesia’s PDP Law.
Is Delete or Format enough?
No — those only remove the pointer to data; the bits remain on disk and are recoverable with commercial tools. Sanitization renders data irrecoverable.
Can I degauss an SSD?
No. Degaussing only works on magnetic media (HDD/tape). SSD/flash is non-magnetic — it needs crypto-erase or physical shredding (NIST 800-88 / IEEE 2883).
Do you provide a destruction certificate?
Yes — a signed Berita Acara Pemusnahan per serial number, with method, witness, and date. The artifact your auditors and UU PDP regulators ask for.
Do I buy the machine or use a service?
Both. DTI supplies the machines (degausser, destroyer, shredder) and also offers managed, chain-of-custody destruction at your site or our facility.
Does regulation require physically destroying the disk?
Regulations require data to be irrecoverable when media is retired — physical destruction is one accepted method (the strongest), alongside verified secure-erase/crypto-erase, chosen by data sensitivity.
FREE DOWNLOADS
Related guides & checklists
PDF · 4 pages · Flowchart & matrix
Data Destruction Method Selection Guide
Not all media is destroyed the same way — degaussing does not work on SSD/flash. This technical guide helps you pick the correct method (degauss, crypto-erase, or physical destruction) via a decision tree and a media × method matrix, referencing NIST SP 800-88, IEEE 2883, and ISO/IEC 27001.
Download the guide (PDF) →PDF · 4 pages · Table & checklist
Data Disposal Compliance Checklist
Compliant data disposal requires data to be irrecoverable plus auditable evidence. This checklist maps obligations from UU PDP, ISO/IEC 27001, POJK/PADK, Permenkes 24/2022, and the Archives Law to practical steps and the evidence (policy, records, certificates, audit trail) you need to prepare.
Download the checklist (PDF) →OTHER PRODUCTS
Specialist depth in three categories
Tilaka Digital Signature
Certified electronic signatures for approval workflows that are faster, legally valid, and easy to trace and audit.
YubiKey Security Key
Hardware-grade phishing-resistant authentication. FIDO2, U2F, FIPS. Yubico Preferred Partner in Indonesia.
DHealth SIMRS
Hospital information system and electronic medical records that help hospitals operate more cohesively and efficiently.
READY TO DEPLOY DATA SANITIZATION?
Sandbox access and a tailored walkthrough.
Discuss your data destruction needs to determine the method, execution location, chain of custody, and reporting format required.




