DATA SANITIZATION — ON-SITE SERVICE
On-Site Data Destruction Service: Media Never Leaves Your Control
DTI brings industrial-grade degaussing and physical destruction equipment directly to your facility. Every unit of media is destroyed in front of your own witnesses, documented serial by serial, and closed out with a certificate of destruction and a chain-of-custody report.
When hard drives, tapes, or SSDs reach end of life, the data on them does not. For banks, hospitals, and government institutions, retired storage media is one of the most overlooked data-leakage paths — precisely because it exits the monitored environment and moves to a warehouse, a third-party vendor, or the second-hand market. An on-site data destruction service closes this gap with one simple principle: media never leaves your premises or your organization's control until the data on it has been permanently destroyed.
Indonesia's regulatory framework is increasingly firm on this point. Law No. 27 of 2022 on Personal Data Protection obliges data controllers to destroy personal data under specified conditions (Article 44), with sanctions attached to non-compliance. In financial services, POJK 11/POJK.03/2022 requires banks to manage information technology risk comprehensively — including securing information through the end of the media lifecycle. In healthcare, Permenkes 24/2022 governs the retention and destruction of electronic medical records. None of these regulations accepts 'we formatted the drives' as evidence of compliance.
The global technical reference, NIST SP 800-88, distinguishes three sanitization levels — Clear, Purge, and Destroy — and emphasizes the two things most often missing from ad-hoc practice: verification and documentation. DTI's on-site service is built around exactly those two. This page explains specifically how destruction at your premises works — from assessment to certificate handover — as a companion to our broader Data Sanitization product line.
Why Shipping Media Off-Site Is a Risk You Don't Need to Take
Chain of custody breaks in transit
The moment media leaves your building, you depend entirely on the integrity of the courier and the destination facility. A single drive 'lost in transit' is enough to become a reportable data incident.
Delete and format do not destroy data
Logical deletion only removes file pointers; the data itself remains recoverable with freely available forensic tools. NIST SP 800-88 explicitly distinguishes ordinary deletion from verified sanitization.
Piles of retired media with no paper trail
Many organizations keep hundreds of retired drives 'temporarily' in storage with no inventory, no owner, and no proof of destruction. When the ISO 27001 audit or a regulator's inspection arrives, there is nothing to show.
The wrong method for the wrong media type
Degaussing is effective on magnetic media such as HDDs and tape, but it does not erase data on SSDs and flash memory. Without a method mapped to each media type, 'already destroyed' can mean the data is still intact.
Destruction at Your Premises, to an Auditable Standard
The entire process happens at your facility
DTI's team brings degaussers and destruction machines to your site. Media moves from your storage room straight to the destruction point — no transit, no third parties, no unsupervised gaps.
Methods mapped per media type under NIST SP 800-88
Magnetic media is degaussed beyond usability; SSDs and flash media are physically destroyed. A combined degauss-plus-destroy option is available where the highest assurance is required.
End-to-end documented chain of custody
Every unit is logged by serial number from the initial inventory, destroyed in front of your designated witnesses, and can be additionally evidenced with photo or video documentation.
Certificates of destruction per batch and per unit
You receive certificates listing serial numbers, method, date, operator, and witnesses — documents ready to present to internal auditors, ISO 27001 assessors, or regulators.
Industrial-grade equipment, a certified team
DTI — an ISO/IEC 27001-certified company — operates degaussers and destroyers from the Proton, MagWiper, SEM, and CrushBox lines, built for both scheduled operations and high-volume decommissioning.
DTI's on-site destruction service is used by financial institutions and organizations in Indonesia's regulated sectors whose policies require that storage media never leave their facilities.
How the On-Site Service Works
Assessment and planning
Together with your team, we map media types (HDD, SSD, tape, optical), quantities, storage locations, and data sensitivity. From there we produce a per-media-type method plan referenced to NIST SP 800-88, an execution schedule, and the working-area requirements at your facility.
Equipment mobilization to your site
DTI's team transports degaussers and destruction machines to your facility on the agreed schedule. Before execution, every unit is verified against the serial-number inventory — the formal starting point of the chain of custody.
Execution witnessed by your personnel
Destruction proceeds unit by unit in front of witnesses you designate. Magnetic media passes through degaussing; SSDs and non-magnetic media are physically destroyed. Each completed unit is logged immediately, and the process can be documented with photos or video.
Certificate and report handover
At the end of the session you receive the certificates of destruction along with a complete chain-of-custody report: serial numbers, method per unit, timestamps, operators, and witnesses. Handling of the physical remains — returned to you or routed to electronic-waste processing — follows your organization's preference.
Frequently Asked Questions About On-Site Data Destruction
What is the difference between on-site and off-site data destruction?
With an on-site service, the entire destruction process takes place at your facility and is witnessed by your own personnel, so media never leaves your organization's control while it still holds data. In the off-site model, media is transported to a third-party facility — which introduces a transit and storage phase outside your supervision. For highly classified data, on-site eliminates that entire phase of risk.
Is degaussing sufficient to destroy data on SSDs?
No. Degaussing works by destroying magnetic patterns, so it is only effective on magnetic media such as HDDs and tape. SSDs and flash memory store data electrically and therefore require physical destruction (shredding/crushing) or another appropriate Purge method under NIST SP 800-88. Our team maps the correct method to each media type before execution.
Do Indonesian regulations mandate a specific destruction method?
Generally no — the PDP Law obliges destruction of personal data under specified conditions but does not prescribe the technical method, and sectoral rules such as POJK 11/2022 require adequate risk management without naming specific techniques. The defensible practice is therefore a risk-based method choice referenced to a standard such as NIST SP 800-88, backed by documentation. That documentation is precisely what auditors ask for most.
What documents do I receive once destruction is complete?
You receive certificates of destruction and a chain-of-custody report listing every media serial number, the method used, date and time, the executing operator, and your witnesses. Photo or video documentation can be included where your internal policy requires it. The document package is designed to be usable directly in ISO 27001 audits and regulator inspections.
Which media types can be destroyed on-site?
Hard drives (HDD), backup tapes such as LTO, SSDs and flash media, and optical media. The method differs by type: degaussing for magnetic media, physical destruction for SSDs and non-magnetic media, or a combination of both where the highest assurance is required. Both small batches and large-scale decommissioning projects can be scheduled.
What happens to the physical remains after destruction?
The remains can be handed back to your organization or routed to electronic-waste processing, according to your preference and environmental policy. Either way, the handover of the physical remains is recorded as the closing entry of the chain of custody, so no stage goes undocumented.
DATA SANITIZATION — ON-SITE SERVICE
Schedule a Data Destruction Assessment at Your Site
Tell us the types and volume of media you need destroyed. DTI's team will prepare a per-media-type method plan referenced to NIST SP 800-88, an on-site schedule estimate, and a sample documentation package — free of charge and with no commitment.
