What a Certificate of Destruction Should Actually Contain

Almost every disposal vendor in India will give you a certificate. Very few of those certificates would do anything useful if an auditor, a client's compliance team, or a regulator asked what happened to a specific device.
The difference is not formatting or a nicer seal. It is whether the document contains enough specific, verifiable detail to connect a device that was in your building to an event that happened to it.
What the certificate is for
A Certificate of Destruction has one job: to be the artifact you produce, months or years later, when someone asks a question you can no longer answer from memory.
That question is usually one of three:
- “What happened to the twelve laptops that came off the finance floor in March?”
- “Can you demonstrate that data on retired devices was destroyed rather than resold?”
- “Show me the disposal trail for this asset tag.”
A certificate that reads “PrivAce collected 240 kg of e-waste on 12 March and disposed of it responsibly” answers none of those. It confirms a transaction occurred. It does not confirm what happened to any particular device, which is exactly what is being asked.
The eight elements that matter
A defensible certificate contains, at minimum:
- Your legal entity name as the client, matching how your organisation appears in your other compliance records.
- The issuing entity's legal name and authorization reference — the actual licensed processor, not just a trading name.
- A unique certificate number, so the document can be referenced and cannot be silently duplicated.
- The date of destruction, distinct from the date of collection. These are often different, and the gap between them is exactly the window an auditor asks about.
- Device-level identification — make, model, and serial number for every data-bearing device covered.
- The method used, stated specifically. “Securely destroyed” is not a method. “Physical shredding” or “certified software erasure with verification” is.
- Confirmation of sequence — that data destruction occurred before any resale, recovery, or recycling step.
- An authorised signature and designation from the processing entity.
The serial number testIf a certificate does not list serial numbers for data-bearing devices, it cannot connect a specific asset in your inventory to a specific destruction event. That connection is the entire evidentiary value of the document.
Warning signs of a weak certificate
These are the patterns that suggest the certificate is decorative rather than evidentiary:
- Weight-only descriptions. “340 kg of mixed e-waste” tells you nothing about which devices, or whether any drives were wiped.
- No date distinction between collection and destruction.
- Vague method language — “disposed of as per norms,” “handled responsibly,” “processed securely.”
- No authorization reference for the processing facility.
- Issued at pickup. A certificate handed over when the van is loaded certifies an intention, not an outcome. Destruction has not happened yet.
- No device-level annexure, and no offer to provide one.
That last one is worth pressing on. Many vendors can produce device-level records but do not by default, because generating them takes effort. Ask; the answer tells you whether the underlying tracking exists at all.
Batch summary vs device-level records
You want both, and they serve different purposes.
The batch certificate is the summary document you file and can hand over quickly — one page, referencing the engagement as a whole.
The device-level annexure is the detail that makes the summary meaningful: a line per device, with serial number, condition, method applied, and outcome. This is what you reconcile against your own retired-asset inventory.
A vendor providing only the summary is asking you to take the detail on trust. A vendor providing only a long spreadsheet with no summary has given you data but no document. Insist on both.
How to file it
The most common failure after obtaining good certificates is losing them. Practically:
- Store certificates with your compliance documentation, not in the IT team's shared drive or an individual's mailbox.
- Cross-reference the certificate number against your asset register entry, so retirement of an asset in your system links to its disposal evidence.
- Keep the vendor's authorization document alongside the certificates it supports.
- Retain according to your statutory and contractual retention obligations — and remember these records cannot be recreated later.
If you want to check how your current documentation position holds up, our free Exposure Score includes exactly these questions and returns a scored breakdown. Or read how our six-step process produces the records described here.

