How long must you keep a certificate of destruction?
Three to seven years is the working answer. The real answer is set by your client's regulator, not by your client — and often not by anything they will tell you unprompted.
Applies toUnited States
Published August 17, 2026 · Last checked August 17, 2026
Three to seven years covers most of it. Six years if the device held protected health information, seven if your client is a publicly traded company or a law firm, and seven as a safe default when you cannot establish which applies. Keep the evidence behind the certificate for the same period, not just the certificate itself.
The reason this question is hard to answer cleanly is that the obligation is not ours. It belongs to whoever owned the data, and it is set by their regulator. We hold a record on someone else’s behalf, against a rule neither party chose.
The obligation flows from the data, not from the contract
An ITAD operator does not have a retention period. Our clients do — and their regulators set it.
A hospital’s obligation under HIPAA does not disappear because the drives were destroyed by a third party. It follows the evidence (45 CFR 164.316, eCFR, accessed 2026-09). When the auditor asks the hospital to produce proof that a specific device was destroyed, the hospital comes to us. If we disposed of that record after three years and their obligation was six, the gap is theirs — and we are the ones who caused it.
This is why “we keep certificates for three years” is a reasonable general policy and a dangerous one the day we win a healthcare client.
What the common regimes require
| Regime | Retention required | Applies to |
|---|---|---|
| HIPAA | Six years, from creation or the last effective date, whichever is later | Healthcare clients, protected health information |
| SOX | Seven years | Publicly traded company clients |
| PCI DSS | No fixed period for destruction records. You must define, document and justify your own. Log retention is at least twelve months | Card data environments |
| Massachusetts 201 CMR 17 | Part of the WISP audit trail, retained while the program is active | Any business holding personal information of Massachusetts residents |
| Legal and professional services | At least seven years, commonly matching the client file | Law firm and professional services clients |
| General commercial | Three to seven years. Retain longer rather than shorter when unsure | Everything else |
Two of those deserve a note. HIPAA’s six years runs from creation or the last effective date, whichever is later (45 CFR 164.316(b)(2)(i); 45 CFR 164.530(j)(2), eCFR, accessed 2026-09) — so a record attached to a policy that was current until 2028 starts its six years in 2028, not on the day we issued it. And PCI DSS does not give us a number. It requires us to have decided one and to be able to explain it, which is a different and slightly harder thing.
Working it out when the client cannot tell you
Most operations directors have had this conversation: we ask the client how long they need the certificates kept, and they do not know either. Working it out from first principles takes four questions.
- What was on the device? Health information, cardholder data, personal information of residents of a specific state, financial records. The data class determines the regime, not the device type.
- Who was the data controller? Not who handed us the asset — who owned the data on it. A managed service provider delivering drives on behalf of a hospital inherits the hospital’s clock.
- What binds them? A publicly traded healthcare provider is subject to both HIPAA and the record-retention duty created by (Sarbanes-Oxley Act 2002, § 802). Where two regimes apply, the longer one governs in practice.
- What does the contract say? A retention term in the service agreement binds us regardless of what the regulation requires. Contracts sometimes specify shorter periods than the regulation, which is a problem worth raising before signing rather than after.
When we cannot establish the answer, we keep it for seven years and write down why. Seven covers every common regime in the table. The written note matters as much as the period: a decision we can explain is defensible, and an arbitrary one is not.
Retention applies to the evidence, not only the certificate
This is the part most operators get wrong, and it is the expensive one.
A certificate of destruction is a summary. What makes it hold up under challenge is what sits behind it — the per-device record showing the serial, the method, the date, the operator who confirmed it, and whatever ties that serial to the destruction itself rather than to a bench scan taken earlier in the shift.
If we keep the PDF for seven years and let the records underneath it roll off after one, we have kept the claim and discarded the proof; the sequence after that is always the same —
- the assessor picks a single serial off a certificate we issued, quite possibly one from six years ago;
- we produce the certificate and nothing that stands behind it;
- the client is left holding a claim rather than proof, and the record that would have settled it was ours to keep.
Retention should be set on the record set as a whole, and it should be technically enforced rather than left to whoever remembers to run the archive.
A practical policy
For an operator serving mixed clients, the position we would defend:
- Default to seven years for all destruction records and their supporting evidence.
- Record the applicable regime per client at onboarding, not at disposal. By the time the drives arrive, nobody is asking.
- Set retention on the whole record set, not just the certificate.
- Make deletion an event you can evidence. When a record does reach the end of its period, the fact that it was disposed of on purpose, on a date, under a policy, is itself worth being able to show.
- Review it when we win a client in a new sector. A healthcare or public company win changes our obligations on the day the contract is signed.
What this is not
This is a summary written for operations directors, not legal advice. Retention law varies by state and by sector, contracts override defaults in both directions, and the position changes. The links below go to the primary sources so they can be checked, and anything with real money attached deserves a professional opinion rather than an article — including this one.
So here is the question worth taking back to the floor: if a client’s assessor picked one serial off a certificate we issued six years ago, could we still produce the record behind it, and could we say which rule told us to keep it that long? If your answer differs from ours, we would like to hear it.