What we do and don't do — plainly
We are a licensed waste carrier, not a data destruction company. We do not offer shredding, and we do not issue certificates of data destruction, because those require accreditations and an audited chain of custody we do not hold.
We would rather say that clearly here than take a booking and disappoint. A business that hands confidential records to a general waste carrier has not discharged its obligation, whatever the carrier says.
What we do is the rest of an office clearance: furniture, fittings, general waste, and IT equipment under WEEE — with the data element handled by a specialist first. That combination works well and it is how most office moves are actually run.
What the law requires
Under UK GDPR you must have appropriate technical and organisational measures to protect personal data, and that obligation covers the end of the data's life as much as its storage. A skip full of client files is a personal data breach.
If you engage a company to destroy data on your behalf they are a processor, which means a written contract, documented due diligence on their suitability, and records of the destruction. That paperwork is the evidence you would need if it ever came to it.
The Information Commissioner's Office has taken enforcement action over documents recovered from bins and skips. It is not a theoretical risk, and 'we assumed the waste company handled it' has not historically been a defence.
- UK GDPR: appropriate security measures
- Applies to disposal, not just storage
- Written contract with any processor
- Due diligence on the supplier
- Records of what was destroyed and when
- ICO can fine for disposal failures
Data handled, everything else to shift?
That's the part we do — furniture, fittings, general waste and IT under WEEE.
Paper: standards and practice
Shredding is graded under the DIN 66399 standard, from P-1 up to P-7. P-4 cross-cut is the usual commercial baseline for ordinary confidential paper; P-5 and above suits sensitive personal, financial and medical records. Strip-cut shredding at the low grades is not adequate for personal data.
On-site shredding — a mobile unit at your premises where you can watch it happen — gives the shortest chain of custody. Off-site is generally cheaper and fine for routine material, provided the sacks are sealed and tracked.
Whichever you use, get a certificate of destruction with dates and quantities and keep it. That certificate is the record UK GDPR expects you to hold.
Digital is where the real risk sits
Paper gets the attention and hard drives cause the breaches. Old computers, laptops, phones, tablets, servers, network appliances, multifunction printers and photocopiers all hold data — copiers in particular have internal drives that retain images of everything scanned, and they are routinely returned at end of lease without being wiped.
Deleting files and formatting a drive does not remove the data. Proper disposal means certified data erasure to a recognised standard, or physical destruction of the drive, with a certificate either way and an asset-level record of serial numbers.
Once the data is dealt with, the hardware is WEEE and follows that route — recoverable metals, regulated components, and a duty of care (your legal responsibility for waste you produce) transfer note. That part we do: see WEEE disposal.
Running it as one job
For an office move, a lease end or a downsizing, the practical sequence is: identify what holds data, get that destroyed by a specialist with certificates, then clear everything else in one visit.
That way the confidential element is handled to the right standard and the bulk — desks, chairs, partitions, filing cabinets, kitchen equipment and general waste — is priced as an ordinary clearance rather than at data destruction rates.
We work around an out-of-hours or weekend schedule as standard for commercial jobs, because a trading day lost costs more than the clearance. Every collection carries a transfer note under our SEPA registration (WCR/R/3002381) — see office clearance and soft strip out.


