Tijuana · Baja California, Mexico Mexico–U.S. border operations
B2B guide · Tijuana

Hard drive and data destruction in Tijuana

Hard drive destruction and secure erasure of every storage medium: aligned to the NIST 800-88 standard, with a per-serial-number certificate, a documented chain of custody and Mexican LFPDPPP compliance. Your company’s information is never exposed.

  • NIST 800-88 secure erasure
  • Certificate per serial number
  • Chain of custody documented
  • NOM-161 recycling of destroyed media
Opened hard drives for certified data destruction with NIST 800-88 erasure in Tijuana

What certified data destruction is (and what it is not)

Certified data destruction is the irreversible elimination of the information stored on your company’s media — hard drives, SSDs, servers, backup tapes, phones — backed by documentary evidence of every step: which device was processed, with what method, when, and by whom. The deliverable is not just a clean drive; it is a file you can put on the table when an auditor, a client or headquarters asks what happened to the information on those machines.

What it is not: formatting the drive, deleting files, or a factory reset. A quick format only removes the file index — the information is still there and can be recovered with publicly available tools. Every device your company donates, sells or scraps without proper sanitization is a potential data breach.

Compliance on both sides of the border: NIST 800-88 and Mexico’s LFPDPPP

For a U.S. company operating in Mexico, NIST 800-88 covers the technical side your headquarters expects — but it is not the law that applies to your Mexican entity. Companies that handle personal data in Mexico are bound by the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), which requires that information be eliminated so it cannot be recovered, and that you can prove it. Penalties can reach hundreds of thousands of UMAs (up to 320,000 — double for sensitive data such as health or financial records).

Most vendors targeting cross-border clients anchor only on the U.S. standard and skip the Mexican legal framework that actually binds your local operation. Our certificate and chain of custody are built to serve as evidence for both: your U.S. audit and your Mexican compliance file.

NIST 800-88: Clear, Purge, Destroy

The global reference for media sanitization is NIST Special Publication 800-88, the standard most corporate security policies cite — including the headquarters of nearshoring companies on the border. It defines three levels: Clear (logical overwrite, protecting against software-based recovery), Purge (deeper techniques such as cryptographic erase, making recovery infeasible even with lab methods — the usual level when equipment leaves the company for reuse or resale) and Destroy (physical destruction that renders the media unusable). At Tianlu we apply secure erasure aligned to NIST 800-88, or physical destruction, depending on each device and risk level.

We destroy the drive — we do not wipe it

Worth stating up front, because it sets us apart and prevents misunderstandings: at Tianlu the storage medium is always physically destroyed. We do not perform erasure that keeps a drive alive for reuse.

That does not mean you lose the equipment. Quite the opposite:

  • The drive is destroyed; the machine stays yours. We remove and destroy the storage medium, and the rest of the unit stays with you. Redeploy it internally, donate it or sell it — that resale value is entirely yours, it never passes through us.
  • If you would rather be rid of all of it, we buy it. We appraise by material composition and recycle it under Mexican NOM-161. We resell nothing: everything we buy goes to material recovery.
  • Why destroy rather than wipe. Verified erasure requires proving model by model that the method actually worked, and on SSD and NVMe that verification is notoriously fragile. Physical destruction is not open to argument: the medium ceases to exist, and an auditor can confirm that without taking anyone’s word for it.
How this compares to other vendors. Many ITADs offer to wipe your drive so they can resell the unit and keep that margin. Our model is the reverse: we destroy the medium and the equipment — with its value — stays on your side. It is worth asking any vendor exactly what happens to the equipment they take away.

How a hard drive is physically destroyed (and why SSDs are different)

When the decision is to destroy the hard drive rather than erase it, the right technique depends on the media type. A mechanical drive (HDD) stores data on magnetic platters; a solid-state drive (SSD) stores it on flash memory chips — and they don’t die the same way:

  • Shredding. The media is broken into particles. The most definitive method, valid for both HDDs and SSDs — provided the particle size is fine enough for an SSD’s memory chips.
  • Punching / deformation. The platter is pierced or bent to disable it. Fast for damaged or worthless HDDs, but can leave readable fragments unless combined with shredding; unreliable on its own for SSDs.
  • Degaussing. A strong magnetic field wipes an HDD and leaves it unusable. Highly effective on mechanical drives, but it does not work on SSDs or flash memory, which don’t store data magnetically.

This matters: destroying an SSD as if it were an HDD — for example, only degaussing it — leaves the data intact. So before destroying, we identify the media type, apply the technique that truly renders it unusable, and document it by serial number on the certificate.

The process, step by step

  1. 1

    Assessment and scope

    You tell us which media need sanitizing (drives, SSDs, servers, tapes, phones), the volume and your audit requirements. We confirm the scope and quote with no obligation. Every storage medium is destroyed, so there is no method to negotiate.

  2. 2

    Pickup with chain of custody

    We collect the equipment at your facility and every device is logged by serial number from the moment it leaves your company. The chain of custody documents who held the material at every step.

  3. 3

    Physical destruction

    Every storage medium is destroyed so it cannot be read again, using the method that suits the device type — a drive, an SSD and a tape are not destroyed the same way.

  4. 4

    Verification

    Each device is verified after processing: the destruction must be complete. No medium moves on to material recovery without this check.

  5. 5

    Certificate and evidence

    You receive a destruction certificate per device — serial number, method, date and operator — together with the chain of custody: the evidence that backs your compliance in audits.

The certificate: your compliance evidence

For a destruction certificate to hold up in an audit it must identify each device unequivocally. Ours carries, per device:

  • Legal name of both parties — the client that handed over the medium and the provider that destroyed it.
  • Device inventory: make, model, capacity and serial number, so the evidence is traceable unit by unit rather than as a "generic lot".
  • Method and standard applied: erasure using NIST 800-88 methods, degaussing or physical destruction.
  • Sanitization level per NIST 800-88: Clear, Purge or Destroy. This is the field an auditor looks for first.
  • Date and place of execution.
  • Name and signature of the operator responsible, closing the accountability chain.
  • Witness, when your security policy requires someone from your team to observe the process.
  • Folio and final destination of the medium, linking the certificate to the disposal record.

Together with the chain of custody, that forms the evidence file for internal, client, headquarters or regulatory audits. If you are comparing vendors, ask to see a sample certificate before you decide: one missing the serial number, the sanitization level or the final destination proves that something happened, but not what happened to which device.

Will your U.S. auditor accept a certificate issued in Mexico?

This is the question that actually stalls the purchase, so here is the direct answer: an auditor does not check what country the letterhead is from — they check whether the document proves the claim. What travels across the border is the evidence, not the jurisdiction.

Map it field by field against what a U.S. ITAD certificate contains and the overlap is near complete: per-serial-number inventory, the NIST 800-88 sanitization level, method, date, operator and final destination. NIST 800-88 is a U.S. federal guideline, so your security team is already reading the same vocabulary. What our certificate adds is the piece a U.S. vendor cannot give you: evidence that the material was disposed of under Mexican NOM-161-SEMARNAT, which is what your Mexican entity is actually accountable for.

We issue documentation in English and Spanish for exactly this reason — one file that answers to headquarters and to a PROFEPA visit at the same time.

For San Diego companies with a plant in Tijuana

If your IT organization sits in San Diego and your production sits across the line, the drives are on the Mexican side and your policy is written on the U.S. side. A San Diego destruction vendor can handle your California offices but cannot collect at a Tijuana plant. We work the other way around: we sanitize and destroy in Mexico, an hour from the Otay and San Ysidro crossings, and hand you bilingual certificates your U.S. security and compliance teams can file directly.

To be clear about scope: we do not collect inside California. Our service covers your Mexican sites — which is precisely the gap a U.S. vendor leaves open. See cross-border ITAD for how the full flow works.

Don’t forget the “invisible” media: office printers with internal drives, network gear holding credentials, corporate phones, USB sticks and backup tapes. They are the devices that most often slip through sanitization policies — we cover them too.

Cross-border advantage: destroy data locally

U.S. companies with nearshoring operations in Tijuana, Mexicali, Ensenada, Rosarito or Tecate do not need to ship equipment back across the border to sanitize it. We do it on this side — bilingual process, certificates valid as evidence in both countries — so data-bearing drives travel as little as possible. See our cross-border ITAD page.

After the data: recycling and value recovery

Data destruction is one link in the full disposition chain. Once the drive is gone, the functional equipment is yours to redeploy or sell, the rest leaves your site with our documented pickup, and end-of-life material is recycled under Mexico’s NOM-161 regulation with its own documentation. For the complete cycle, see our IT asset disposition (ITAD) service and our electronics recycling guide, plus NOM-161 compliance.

FAQ

Certified data destruction: FAQ

What is certified data destruction?

It is the irreversible elimination of the information stored on hard drives, SSDs and other media, backed by documentary evidence: a per-serial-number certificate stating the method applied, the date and the operator. Unlike a simple format, certified destruction guarantees the data cannot be recovered — and gives you the proof for any audit.

Why is formatting a drive not enough?

A quick format only deletes the file index, not the information itself. With publicly available recovery tools, much of that data can be read again. Secure erasure per standards like NIST 800-88 overwrites or purges the information so it cannot be recovered, and physical destruction renders the media unusable.

What is the NIST 800-88 standard?

It is the media sanitization guideline from the U.S. National Institute of Standards and Technology (NIST Special Publication 800-88), the most widely used reference in the industry. It defines three levels — Clear, Purge and Destroy — and helps decide which one to apply based on data sensitivity and the device’s next destination.

Do you ever erase instead of destroying?

No. Every storage medium we handle is physically destroyed, with a per-serial-number certificate. Verified erasure requires proving model by model that the method worked, and on SSD and NVMe that proof is fragile — so we do not rely on it. The upside for you: with the drive gone, the machine itself stays yours to redeploy or sell, and that value never passes through us.

Can U.S. companies with operations in Mexico use this service?

Yes — it is one of our specialties. Nearshoring operations in Tijuana and Baja California can destroy data locally, with bilingual service and per-serial-number certificates that work as audit evidence on both sides of the border, without shipping data-bearing equipment back to the U.S.

What happens to the drive and to the device afterwards?

The drive is destroyed and its remains go to material recovery. The device itself stays with you: redeploy it, donate it or sell it — that value is yours. If you would rather not deal with it, we buy the parts that carry value: motherboards, processors and memory and recycle it under Mexico’s NOM-161 regulation, with its own documentation. Nothing ends up in regular trash.

Is secure erasure enough to comply with Mexico’s LFPDPPP?

It can be. The LFPDPPP does not mandate a specific method — it requires that the information be eliminated so it cannot be used or recovered, and that you can prove it. Secure erasure aligned to NIST 800-88, verified and backed by a per-serial-number certificate, meets that goal when the equipment will be reused. If the media is damaged, cannot be verifiably erased, or your policy requires it, physical destruction applies. Either way, what sustains compliance is the documentary evidence, not the method itself.

When is physical destruction of a hard drive mandatory?

Regulation rarely mandates a specific method — what it demands is that the data cannot be recovered and that you can prove it. But some policies do require physical elimination outright, which is common in banking, healthcare and government, and a damaged drive that cannot be verifiably erased leaves no other option anyway. We apply destruction in every case, so the question never becomes a judgement call in the middle of a project.

What is degaussing, and does it work on SSDs?

Degaussing applies a strong magnetic field that wipes a mechanical hard drive (HDD) and leaves it unusable. To be clear up front: we do not offer it. We explain it because you will run into it while comparing vendors, and because it carries an important trap — it does not work on solid-state drives (SSDs) or flash memory, which do not store data magnetically. A vendor offering to degauss your SSDs is selling you a procedure that erases nothing. We handle those cases with device-level verified erasure or physical destruction, and issue a per-serial-number certificate either way.

How much does certified hard drive destruction cost?

It depends on the volume of media, the logistics and the level of evidence you need. We don’t quote a blind per-unit price: tell us how many drives or devices you have and what certificate you require, and we return a clear, no-obligation quote. In every case, the cost is a fraction of what a data breach implies.

Drives full of data waiting for a destination?

Tell us which media you have, how many, and what evidence you need. We reply with the right method and a clear quote.

Message us Call us