A business has boxes of old HR files, client contracts, and financial records that have passed their retention period. Someone suggests putting them in the general recycling bin. That’s a GDPR violation, and it’s happened to businesses that genuinely didn’t know any better.
Confidential shredding isn’t just about physical destruction. It’s about doing it in a way you can document and defend if the ICO ever asks.
Why Ordinary Shredding Often Isn’t Enough
A standard office shredder feels like it should do the job. In most cases, it doesn’t.
Strip-cut shredders produce long strips of paper that can, in theory, be reassembled. Even cross-cut shredders often fall short of the DIN 66399 security levels required for genuinely sensitive data, particularly financial records, medical information, or anything covered by a confidentiality clause.
Then there’s the volume problem. If you’re clearing several boxes of archived records, feeding them through a desktop shredder one sheet at a time isn’t realistic. It’ll take days, and someone still has to do it.
And there’s the process problem. Even if the shredding itself is thorough, an office shredder gives you no paper trail. If a regulator asks how you destroyed a batch of personal data, “we shredded it in the office” isn’t an answer that holds up without evidence.
What GDPR Requires for Document Destruction
Under UK GDPR, retained after Brexit through the Data Protection Act 2018, organisations can’t hold personal data longer than necessary. This is the storage limitation principle. Once data no longer serves the purpose it was collected for, it needs to be destroyed securely.
The ICO’s guidance is explicit that putting personal data in general waste doesn’t count as secure destruction. It has to be rendered unreadable and unreconstructable.
The part businesses often miss is the accountability principle, set out in Article 5(2). It’s not enough to destroy the data correctly. You have to be able to prove you did. That’s the gap a lot of in-house shredding arrangements fall into: the destruction might have happened, but there’s nothing to show for it.
What a Certificate of Destruction Is and Why It Matters
A certificate of destruction is a formal document from your shredding provider confirming what was destroyed, when, how, and to what security standard.
A proper certificate should include:
- The date of destruction
- The method used (shredding, and at what DIN 66399 security level)
- The volume or weight of material destroyed
- The provider’s details and, ideally, their BS EN 15713 accreditation
You need one every time personal data is destroyed, not just for large one-off clearances. And you should keep it indefinitely. It’s your evidence that you met your obligations under the accountability principle, and it’s the document you’d produce if a regulator or a client ever asked how a specific record was disposed of.
What to Check When Choosing a Shredding Provider
Shredding services vary more than most businesses assume. Before signing up with one, it’s worth asking:
- Are they certified to BS EN 15713, the British and European standard for secure document destruction?
- What DIN 66399 security level do they shred to, and does it match the sensitivity of your records?
- Is a certificate of destruction included as standard, or is it an extra?
- Is destruction carried out on-site, or is your material transported elsewhere first? If it’s transported, how is it secured in transit?
- Can they offer witnessed destruction if you need to see it happen?
- What happens to the shredded material afterwards? Most providers recycle it, but it’s worth confirming rather than assuming.
None of these questions are unreasonable to ask, and a provider that takes security seriously should have straightforward answers to all of them.
Scheduling Destruction as Part of a Retention Programme
The businesses that handle this well don’t treat destruction as a one-off event triggered by running out of storage space. They build it into a regular retention review instead.
That means setting a destruction date when a record is first filed, rather than trying to work out its age retrospectively years later. An archive management system can flag records as they approach that date automatically, so nothing sits around past its retention period by accident. If you’re using a managed archive provider, they can usually fold the destruction process into the wider service, so records move from storage to secure destruction without anyone having to remember to chase it.
Ardington Archives shreds records twice before pulping and provides a certificate of destruction as standard on every job. If you’ve got legacy records that need clearing or you want to set up a scheduled destruction programme, get in touch or take a look at our confidential destruction service.



