A Business Owner’s Checklist: What Non-Paper Items You’re Legally Required to Destroy
Most business owners have a shredding habit down cold. Old invoices, contracts, tax records, they go in the bin, get shredded, done. But data and sensitive information don’t only live on paper anymore, and the law doesn’t treat them like they do. Hard drives, backup tapes, ID badges, branded uniforms, product prototypes. Every one of these can carry information or liability that’s just as serious as a filing cabinet full of client records, and every one of them falls under the same disposal rules that paper does.
This checklist covers what non-paper items your business is actually required, or strongly advised, to destroy, the laws that make it non-negotiable, and how certified destruction keeps you out of legal trouble down the road.

Why This Isn’t Optional: The Laws Behind It
A surprising number of business owners assume data destruction rules only apply to documents. They don’t. Several federal and state laws specifically govern how businesses dispose of information regardless of the medium it’s stored on.
The FTC’s Disposal Rule, part of the Fair and Accurate Credit Transactions Act (FACTA), requires businesses to take reasonable measures to dispose of consumer information derived from credit reports, and that obligation applies to electronic media just as much as paper. HIPAA imposes strict destruction standards on any business handling protected health information, which today often means hard drives, imaging equipment, and mobile devices, not just charts. The Gramm-Leach-Bliley Act (GLBA) places similar requirements on financial institutions and businesses that handle consumer financial data. On top of federal law, states including New Jersey, New York, and Pennsylvania have their own data disposal and breach notification statutes, several of which explicitly reference electronic and physical media.
The common thread: if the item can identify a person, expose confidential business information, or misrepresent your brand if it ends up in the wrong hands, the law expects you to destroy it properly, not just throw it out.
The Checklist: Non-Paper Items You’re Required (or Strongly Advised) to Destroy
- Hard drives and SSDs. Deleting files or reformatting a drive does not remove the data; it just hides the index. Physical destruction is the only method that fully eliminates recoverable data, and it’s required for HIPAA and GLBA-covered information.
- Backup tapes and old servers. Retired backup media often holds years of accumulated records in one place, making it a high-value target if it isn’t destroyed on a documented schedule.
- USB drives and external storage. Small, easy to lose, and frequently overlooked when IT assets are decommissioned.
- Mobile devices and tablets. Company phones and tablets often retain emails, client data, and app credentials long after a factory reset.
- ID badges and access cards. An active badge left in a drawer or trash can is a physical security risk, not just a data one.
- X-ray film and medical imaging media. Covered under HIPAA and often forgotten because it doesn’t look like “data” in the traditional sense.
- Branded uniforms, ID lanyards, and promotional merchandise. These carry brand and security risk when they end up on resale sites or in the wrong hands, particularly for businesses in healthcare, finance, or government contracting.
- Prototypes and product samples. For manufacturers and product companies, unreleased designs in a dumpster are a real intellectual property exposure.
- Point-of-sale equipment and payment terminals. These can retain cardholder data and fall under PCI DSS destruction requirements.
How Often Should You Be Doing This?
There’s no single answer that fits every business, but the right frequency depends on volume and risk, not convenience.
Businesses with a steady stream of decommissioned IT equipment (device refresh cycles, employee turnover, retired point-of-sale systems) should schedule destruction on a recurring basis, monthly or quarterly, rather than letting drives and devices pile up in a storage closet. The longer retired media sits around, the more chances there are for it to walk out the door or get thrown in with regular trash by someone who doesn’t know better.
Healthcare practices and financial institutions handling protected data should treat destruction as an ongoing operational process tied directly to their retention schedule, not an occasional cleanout. For lower-volume situations, an annual or semi-annual purge covering everything accumulated since the last cycle is often reasonable, as long as items are stored securely in the meantime.
How Certified Destruction Protects You Legally
Destroying a hard drive yourself with a hammer might feel satisfying, but it doesn’t hold up as proof of compliance. If a regulator or a client ever asks how your business disposed of sensitive information, “we broke it up in the parking lot” isn’t an answer that protects you.
Working with a NAID AAA Certified destruction provider gives your business documented proof: chain of custody records showing exactly who handled the material and when, and a Certificate of Destruction for each job confirming what was destroyed and how. That documentation is what regulators, auditors, and insurers actually want to see, and it’s the difference between a defensible compliance record and a guess.
IDS AutoShred provides NAID AAA Certified destruction for both paper and non-paper items, including hard drives, electronic media, uniforms, and product samples, with full chain of custody and Certificates of Destruction for every job, on-site or off-site, across New Jersey, New York, Pennsylvania, Delaware, and Connecticut.
FAQ
Does reformatting a hard drive count as destruction?
No. Reformatting or deleting files removes the file index, not the underlying data, which can often be recovered with readily available software. Physical destruction is the only method that meets HIPAA, GLBA, and most state compliance standards.
Do small businesses need to worry about this, or just large companies?
Business size doesn’t exempt you. If your business handles consumer data, employee records, financial information, or health information in any volume, the same disposal laws apply whether you have five employees or five hundred.
What’s the difference between on-site and off-site destruction?
On-site destruction happens at your location with mobile equipment, so nothing leaves your building before it’s destroyed. Off-site destruction involves secure transport to a certified facility. Both can be fully compliant when handled by a certified provider with documented chain of custody.
Can we destroy branded merchandise and uniforms along with electronic media?
Yes, and many businesses schedule both together. Uniforms, ID lanyards, and promotional items with your logo carry brand and security risk if they end up in circulation, and a certified provider can handle both categories in the same service visit.
Conclusion
The rules around data destruction were written with paper in mind decades ago, but they’ve expanded to cover every format a business actually uses today. Hard drives, backup tapes, ID badges, uniforms, prototypes: if it can identify someone or expose your business, it belongs on the destruction schedule, not in the regular trash.
IDS AutoShred is NAID AAA Certified and handles both document and non-document destruction with full chain of custody and Certificates of Destruction for every job, serving businesses across New Jersey, New York, Pennsylvania, Delaware, and Connecticut. Contact us to schedule a pickup or on-site service, or call 877-886-4732.
