Data Destruction and Drive Sanitization in Montreal

When a device leaves your building, whatever is on it leaves too. A retired server, a laptop, a copier or a switch all hold something — accounts, records, configuration, history — and a machine that looks wiped is not the same as one that has been sanitized. We settle the storage before the hardware goes anywhere.

What's included

  • Hard drives and solid-state drives out of servers, desktops and laptops
  • NVMe and M.2 drives, USB keys, memory cards and external drives
  • Network devices that still hold their configuration
  • Copiers, printers and multifunction units with internal storage
  • Backup tapes and older removable media
  • Phones, tablets and thin clients
  • Software wiping where the drive stays with you, physical destruction where it does not
  • A written record of what was destroyed, by serial number

Wipe or destroy: the two real choices

Sanitization is a decision, not a default. The reference most IT departments work from is NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization, which sets out three levels: Clear, Purge and Destroy. Clear is overwriting or a block erase, and it is right when the device stays in your hands and will be reused. Purge is stronger — cryptographic erase where the drive supports it, or degaussing on magnetic media — and it is what fits equipment leaving your control. Destroy is physical: shredding, pulverizing or incineration, for drives that must not be recoverable at any price.

The one that catches people out is degaussing. It works on magnetic media and does nothing at all to an SSD or a memory card, because there is no magnetic field to scramble. For solid-state storage the practical routes are a cryptographic erase, where the drive supports it, or physical destruction.

Which method fits which drive

The storageWhat fits it
Magnetic hard driveOverwrite or block erase if it is being reused; degauss or shred if it is leaving your control
Solid-state drive, NVMe or M.2Cryptographic erase where supported, otherwise physical destruction — degaussing has no effect on flash
USB key or memory cardOverwrite or destroy; they are too small to trust a partial wipe
Laptop or desktop going to a new userOverwrite, then reimage
Anything leaving the site for goodPurge or physical destruction, with a record of it
An encrypted volume whose key is goneCryptographic erase — without the key, the data is already unreadable

Why this is a Quebec obligation and not just good practice

Quebec’s private-sector privacy law — the Act respecting the protection of personal information in the private sector, modernised by Loi 25 — requires personal information to be destroyed or anonymised once the purpose it was collected for has been achieved. The burden runs the opposite way from habit: once the purpose is fulfilled the information is to be destroyed, not kept by default. A drive that leaves your building still holding records is personal information you are still responsible for, sitting somewhere you no longer control.

That is the difference between decommissioning equipment and decommissioning the data on it. We do both, and we tell you which devices needed which treatment.

What the record looks like

Every drive is logged against its serial number: what method was used, the date, and which device it came out of. If you have to show an auditor, a client or your insurer what became of a specific machine, the record answers it. Say at the survey if you need it in a particular form — most clients ask for it as a simple destruction report, and if your auditor wants something more specific, we will tell you whether we can produce it.

How it fits with decommissioning

Data destruction is usually the first step of decommissioning rather than a separate project. The equipment is surveyed, the storage is dealt with, and then the hardware leaves with the crew. If the drives are staying with you, we wipe them and stop there. If they are not, they are destroyed and recorded before anything goes out the door. See how decommissioning fits into a project.

Where we work

We install and certify this work across Montreal, Laval, Longueuil, the Québec City area and the surrounding regions — see all service areas.

Related services

Data destruction questions

Wiping is a software operation on a drive you keep: NIST SP 800-88 calls the levels Clear and Purge, and either can be the right answer for equipment that stays with you. Destroying is physical — shredding, pulverizing or incineration — and it is what fits drives that must not be recoverable.

No. Degaussing scrambles magnetic media, and a solid-state drive has none. For flash storage the realistic options are a cryptographic erase where the drive supports it, or physical destruction.

Yes. That is the reuse case: the drive is overwritten to the Clear level and the machine can then be reimaged and handed to the next user. Tell us at the survey which machines are staying and which are going.

Yes — a written record of what was destroyed, logged by serial number with the method and the date. If your auditor asks for a specific form of report, tell us at the survey and we will confirm what we can provide.

It depends on the equipment and on what you want. Say at the survey whether the drives have to be dealt with before they leave the building, and we will tell you what applies to your drives rather than assume.

It is quoted with the work. Tell us how many devices are involved and what they are when you ask for a quote, and it comes in the estimate instead of turning up as a surprise on the day.

Get a free site survey

Tell us what needs to be cabled and we will come out, look at the space and put together a written quote. Call (438) 817-4587 or send the details through the quote form.

Request a free site survey