Coleman Technologies Blog

Blogs on IT Support and Cybersecurity for Small Business

Insights on cybersecurity, AI, and IT strategy to help business leaders reduce risk, improve performance, and make better technology decisions.

Formatted Is Not Erased: Secure Device Disposal for Greater Vancouver Businesses

Untitled-design-14

Just over one in four Canadian businesses had written cyber security policies in place in 2023, according to Statistics Canada. Everyone else is improvising, and improvisation shows up fastest in secure device disposal for Greater Vancouver businesses.

The closet nobody audits

Walk through most offices in Vancouver, Burnaby or Richmond and you will find the same corner. A shelf of retired laptops. A shoebox of USB sticks. Two phones belonging to staff who left years ago.

Nobody decided to keep any of it. It simply was never dealt with, and the pile grew.

That pile is a records problem wearing a hardware costume. The Office of the Privacy Commissioner of Canada is blunt about the point. An organization holding personal information cannot simply throw that information in the trash. It has to find a way to dispose of it securely.

What the pile is actually holding

Think about what actually sits on a five-year-old laptop from an accounting or law practice. Client files, payroll exports, scanned identification, email archives going back to the day the machine was issued. None of that becomes less sensitive because the battery stopped holding a charge.

The OPC's list of electronic storage media runs wider than most owners expect. Computer hard drives are on it. So are copier and printer hard drives, removable drives and memory, disks, USB flash drives, mobile phones and magnetic tapes. The multifunction printer humming in the corner belongs on your disposal list.

Statistics Canada also found that identity theft climbed faster than any other attack method in 2023. Just under one-third of impacted Canadian businesses experienced it, an eleven percentage point jump from 2021. Retired equipment is one of the quieter places identity data waits.

Deleting is not erasing, and formatting is no better

When you delete a file, the operating system removes the pointer to it, not the file. When you reformat a drive, you rebuild the index, not the shelves. The data stays where it was until something writes over top of it. Free recovery tools can pull a great deal of it back.

The Canadian Centre for Cyber Security makes the same point in its guidance on IT media sanitization. Erasing a device and resetting it to factory default puts the data beyond the reach of the normal user interface. That stops casual snooping. The Centre notes that the data is normally not truly erased, and that erasure often cannot be verified.

What actually works depends on the media. For a modern magnetic hard drive, a single overwrite pass does the job. Solid-state and flash storage is harder, because wear leveling scatters writes across the chip and retired bad blocks can hold data that no erase command reaches.

Methods the federal guidance recognizes:

  • Overwriting or secure erase, dependable on magnetic hard drives and unreliable on much flash storage
  • Crypto erase, which destroys the encryption key on a device that was encrypted from its first day
  • Degaussing, useful for magnetic tape and older magnetic media, and useless on anything solid state
  • Physical destruction through shredding, disintegration, crushing or incineration, best applied after erasure rather than in place of it
  • Verification, meaning a sample of the media is checked afterward to confirm the erase worked

That last step is the one that gets skipped. The Cyber Centre treats verification as essential and advises choosing a different method whenever the results cannot be checked. It also warns against leaning on physical destruction alone, since dense modern memory components can survive a partial crush with data intact. Skipping verification is the most common gap in secure device disposal for Greater Vancouver businesses.

What Canadian privacy law asks of a retired device

The duty to destroy

PIPEDA states that personal information no longer required to fulfil its identified purposes should be destroyed, erased or made anonymous. It also says organizations shall develop guidelines and implement procedures to govern that destruction. A second clause requires care in disposal so unauthorized parties cannot gain access.

Most companies operating entirely inside British Columbia answer to the province's Personal Information Protection Act instead. Section 35 requires an organization to destroy documents holding personal information, or strip out the means of linking that information to individuals. The trigger is the point where the collection purpose is no longer served and retention is no longer necessary for legal or business reasons. Different statute, same obligation.

Neither law prescribes a wiping standard or names a vendor. Both assume you have already decided what gets kept, for how long, and what happens at the end of that period. Small firms tend to skip exactly that decision, then improvise under pressure on the day the equipment goes out the door.

Sensitivity raises the bar further. The OPC singles out categories such as health and financial data, ethnic and racial origin, biometric identifiers and religious belief as warranting stronger handling. A medical clinic or an HR consultancy in Greater Vancouver is holding a heavier obligation than a firm whose worst-case disclosure is a stack of quotes.

Copies count as well

OPC guidance is specific that disposal includes destroying all associated copies and backup files. A properly wiped laptop achieves very little if the same client folder sits on an external drive one shelf over. The device you remember is rarely the only place the data lives.

This is why a retention schedule does more work than any single tool. The OPC recommends keeping an inventory of what personal information is held, for what purpose and for how long, then reviewing those holdings on a regular cycle. Once someone has decided how long a record should live, disposal stops being a judgement call made in a hurry.

Retention and disposal also pull in opposite directions, which is where the schedule earns its place. Tax rules, employment standards and limitation periods set floors you cannot go below. Privacy law sets a ceiling you should not sit above. The gap between the two is the window in which disposal actually happens.

Where custody quietly breaks

Handing a pallet of old gear to a recycler feels like the end of the story. Under Canadian privacy law it is not. The OPC is explicit that an organization contracting out disposal remains responsible for the information being disposed of.

Worth requiring from any disposal vendor:

  • Verifiable credentials rather than a website and a truck
  • Secure transfer of the equipment from your office to their facility
  • A destruction method matched to the media type and the sensitivity of the data
  • Privacy protection clauses in the contract that bind any subcontractors
  • Monitoring and audit rights, including the occasional spot check
  • A written record of what was destroyed, by what method, and on what date

Federal guidance goes a step further on the handoff itself. It advises erasing media or rendering it non-functional before it ships to an external destruction service. Where that is not possible, the equipment should travel and be stored securely, and the destruction should be witnessed.

The Cyber Centre describes chain of custody as chronological documentation of everyone who has held the media and every action taken on it. It starts when a device is flagged for sanitization and continues through transport and final disposal. That sounds heavy for a forty-person firm. In practice, secure device disposal for Greater Vancouver businesses runs on a spreadsheet, a locked cabinet and a signed receipt.

The exits nobody labels disposal

A pile of dead laptops is at least visible. The larger exposure sits in equipment that leaves through ordinary business channels, where nobody thinks of it as disposal at all.

Common blind spots:

  • Leased copiers and multifunction printers returned at the end of term with their internal drives untouched
  • Trade-in credit programs for phones, tablets and laptops
  • Staff purchasing their old equipment on the way out the door
  • Donations to schools, charities or community organizations
  • Office moves, where boxes travel and a few never arrive
  • Warranty replacements, where a failed drive goes back to the manufacturer holding everything it ever stored

The OPC calls out relocations directly. When an organization is planning a move or closing its doors, personal information should be safeguarded or securely disposed of in line with retention requirements. Offices across the Lower Mainland relocate constantly, and moving week is exactly when inventory discipline earns its keep.

Copiers deserve their own line. Federal guidance treats multifunction devices as holding real user data, not just configuration settings. Where the device does not support a properly evaluated overwrite function, the storage should be removed and sanitized. A factory reset from the control panel is not the same thing.

Making retirement a routine

The OPC suggests naming a designated person responsible for arranging data destruction, then instructing staff to route every retired device and every piece of electronic material to that person. One name, one path. It removes the moment where a laptop goes into a drawer because nobody was sure who to hand it to.

The same guidance advises segregating equipment awaiting disposal and storing it in a secure area with restricted access. In plain terms, that means a locked cabinet rather than the shelf by the kitchen. Devices in limbo are still live records, and they are easier to walk off with than anything on your network.

A routine that holds up:

  • Inventory everything that stores data, copiers and phones included
  • Give one person accountability for the retirement stage
  • Encrypt devices from day one, which makes end-of-life erasure far simpler
  • Hold retired equipment in a locked, access-controlled space
  • Erase, verify, and destroy the media when verification fails
  • Log each device, its disposal method and the date it left

Encryption is the quiet winner in that list. The Cyber Centre notes that media encrypted throughout its life can be sanitized quickly at the end, because destroying the key destroys access. Decisions made when a laptop is first issued determine how much work its retirement takes.

None of this calls for a large IT department. Secure device disposal for Greater Vancouver businesses mostly comes down to deciding who owns the final step of the hardware lifecycle, then writing down what happened at each stage.

Procurement gets planned. Deployment gets planned. Retirement tends to happen by accident, in a closet, on a loading dock, or in the back of somebody's car.

The data on those drives is indifferent to which. It stays readable until a deliberate step makes it otherwise.

Sources:

Statistics Canada, The Daily, Impact of cybercrime on Canadian businesses, 2023: https://www150.statcan.gc.ca/n1/daily-quotidien/241021/dq241021a-eng.htm

Office of the Privacy Commissioner of Canada, Personal Information Retention and Disposal: Principles and Best Practices: https://www.priv.gc.ca/en/privacy-topics/privacy-for-businesses/appropriate-handling-of-personal-information/gd_rd_201406/

Canadian Centre for Cyber Security, IT media sanitization (ITSP.40.006): https://www.cyber.gc.ca/en/guidance/it-media-sanitization-itsp40006

Personal Information Protection Act (British Columbia), section 35: https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01

Continue reading

Replacing Your Business Computers Actually Protects Your Bottom Line

Replacing Your Business Computers Actually Protects Your Bottom Line

How frustrating is it when your computer just doesn’t want to cooperate, whether it takes its sweet time starting up in the morning or decides to go on break in the middle of a meeting? How frustrating it is to see it happening to your team members, fully aware that they are feeling the same frustration you would? How much does it cost you, all events converging over time?

How much of a relief would it be if all these problems stemmed from one source: it being the time to retire that particular piece of hardware and replace it with something new?

Continue reading

The Math Behind the 5-Second Tech Lag

The Math Behind the 5-Second Tech Lag

How much does a 5-second lag on your technology cost? Most business owners will look at an aging laptop and think, “It still works, so why replace it?” The reality is that older devices can lead to a silent, invisible drain on your budget that doesn’t show up on the hardware invoice: the labor leak.

Continue reading

What You Need to Know About the FCC Router Ban

What You Need to Know About the FCC Router Ban

On March 23, the Federal Communications Commission announced its intention to ban the sale of all foreign-made Wi-Fi routers moving forward, with manufacturers able to apply for a conditional approval exemption on the FCC’s website. While this will obviously have an impact on businesses of all shapes and sizes, it may not be the one you’d expect.

Let’s talk about what this ban means, both in terms of its requirements and in relation to your business. Spoiler: it’s going to get complicated.

Continue reading

Your Data is Truly Everywhere… So Be Careful What You Throw Out

Your Data is Truly Everywhere… So Be Careful What You Throw Out

There’s a lot of hardware in the modern business setup, and most of it is computerized to some degree. As such, ridding your business of any of it has become a more involved process than it once was… all in the name of data security.

The simple fact is that more devices than ever have memory, which can easily cause serious problems if you are not careful.

Continue reading

Boost Business Collaboration with the Right Communication Tools

Boost Business Collaboration with the Right Communication Tools

In order for any modern business to be successful, it is crucial that everyone is on the same page…and in order for this to happen, a business needs to have the tools available to collaborate and communicate, internally and externally.

Let’s take a few minutes to go over what these tools look like nowadays to see if we can identify any gaps in your own resources that should be filled.

Continue reading

How Network Switches, Routers, and Hubs Work

How Network Switches, Routers, and Hubs Work

Network hubs, network switches, network routers… What does it all even mean? All of these devices and terms can be confusing, and to some, they might even be interchangeable. However, the fact remains that they all serve different purposes, and some might not be the right solution for your business’ needs. Today, we want to break down the differences and when you might consider one over the other for your infrastructure.

Continue reading

Four Decades Later, We’re Looking Back to 1986’s Business IT

Four Decades Later, We’re Looking Back to 1986’s Business IT

It is fascinating to think that in 2026, our workdays will be defined by orchestrating AI agents, optimizing cloud-native environments, and deploying self-healing security protocols. But if we rewind exactly 40 years to 1986, business technology wasn’t just "retro," it was a different reality entirely.

In 1986, the cloud was something that ruined your Saturday tee time, not a place where you stored your database. Here is what the cutting edge looked like when high-tech involved a lot more physical heavy lifting.

Continue reading

How a Modern Firewall Supports Your Network Security

How a Modern Firewall Supports Your Network Security

A lot goes into a successful network security strategy, and when there isn’t a clear head honcho at the top of the chain of command (from a network security standpoint, anyway), things can get a little murky. The security that comes from a modern firewall, however, is vital, and all businesses should strive to implement it. Here are the four key elements of a modern cybersecurity strategy and how a modern firewall contributes to the digital security of your business.

Continue reading

Music is Being Lost to Failing Hard Drives, Reminding Us of a Few Best Practices

Music is Being Lost to Failing Hard Drives, Reminding Us of a Few Best Practices

Nostalgia is a powerful force. It can drive us to look to the past for things we once loved, such as the music we listened to over the years. However, what if the music you loved was lost forever?

This could be the case for many, as older hard drives that archive this music have been discovered to have failed. Let’s examine the situation to see what lessons any small-to-medium-sized business can learn.

Continue reading

Neglecting this Patch Could Allow a Computer to Explode

Neglecting this Patch Could Allow a Computer to Explode

Your computer has a brain, of sorts, in its CPU… a tiny square that literally enables everything the device does, as it processes billions of instructions at a time. Of course, to support this on such a relatively tiny piece of hardware, most CPUs are packed with microscopic transistors—these transistors being small enough to fit hundreds on a single blood cell.

As you might imagine, this means things can go wrong pretty easily… and gone wrong, things have. Many newer computers are suffering from a bug that could cause permanent damage to the CPU… and if you don’t take steps fast, it could be too late.

Continue reading

Benefits of Virtualization on Your IT Infrastructure

Benefits of Virtualization on Your IT Infrastructure

Is your business frequently grappling with the challenges of implementing new solutions, whether software or hardware? Consider harnessing the power of virtualization in the cloud to address these issues head-on. With the right tools, virtualization can open up remarkable opportunities to enhance your business' operations while bolstering its security and flexibility.

Continue reading

Properly Cleaning a Laptop

Properly Cleaning a Laptop

It is important to keep modern computers clean, and laptops are no exception. However, a laptop's different form factor makes cleaning it much different from cleaning a traditional desktop computer.

Continue reading

Why You Need to Keep Track of Your IT Infrastructure

Why You Need to Keep Track of Your IT Infrastructure

When taking stock of your business assets, technology is particularly critical to pay attention to. Let’s discuss why this is and what you must do to manage it properly.

Continue reading

USB-C? Thunderbolt? What Ports Should My New Laptop Have?

USB-C? Thunderbolt? What Ports Should My New Laptop Have?

We’re at a weird point in the technology world (but honestly, when is it not at least a little convoluted?). Right now, modern technology has been slowly shifting between a few different technologies and consumers and businesses are stuck in the middle trying to figure out what to do and how to future-proof their hardware investments.

Continue reading

Necessary Networking Tools You Need to Know

Necessary Networking Tools You Need to Know

Every organization, whether it’s a farm with a stable full of horses or an office with a stable filled with people, depends on its access to the Internet. Most people take for granted their ability to connect whether it be with their smartphone via Wi-Fi or their workstation, which is typically hardwired. There is a whole infrastructure behind the near ubiquitous Internet access you enjoy. Today, we will go through some of the essential hardware needed. 

Continue reading

How to Implement an Effective BYOD Policy

How to Implement an Effective BYOD Policy

Let’s face it; running a business can be expensive, and taking any measures possible to mitigate those costs can have huge benefits for your bottom line. One way companies are minimizing costs is by implementing a Bring Your Own Device policy, or BYOD, to allow employees to use their own personal devices for work purposes. We’re here to help you do so without putting security at risk.

Continue reading

ALERT: Dangerous Zero-Day Threats Found in Recent Samsung Chipsets

ALERT: Dangerous Zero-Day Threats Found in Recent Samsung Chipsets

Google’s Project Zero team has discovered 18 zero-day vulnerabilities impacting the Samsung Exynos modems—four of which enable remote code execution. Let’s talk about what this issue does, and what needs to be done to minimize risk.

Continue reading

Are Magnets Really Bad for a Computer?

Are Magnets Really Bad for a Computer?

Magnets are often portrayed as the bane of technology’s existence, especially in media where data must be scrubbed from devices through the use of a magnet. How true is this representation of the relationship between magnets and technology? We’ll examine this in today’s blog article.

Continue reading

The Rubber Ducky Hacking Tool is Back

The Rubber Ducky Hacking Tool is Back

For millions of people, the rubber ducky is a benign reminder of childhood. Depending on when you were a child, the rendition of Sesame Street’s Ernie singing “Rubber Duckie, you’re the one,” is ingrained in your mind every time you hear the term. Unfortunately, the Rubber Ducky we are going to tell you about today has only fond recollection for people who are looking to breach networks they aren’t authorized to access or deliver malware payloads that are designed to cause havoc. 

Continue reading

About Coleman Technologies

Coleman Technologies is a managed IT and cybersecurity partner for growing businesses that can’t afford downtime, breaches, or guesswork. For over 25 years, we’ve helped organizations across British Columbia run stable, secure, and scalable technology environments—backed by 24/7 support, enterprise-grade security, and clear accountability. We don’t just fix IT problems. We take ownership of them.

get a free quote

Understanding IT

Get the Knowledge You Need to Make IT Decisions

Technology is constantly evolving, and keeping up can feel overwhelming. Whether you want to understand cybersecurity threats, explore automation, or learn how regulations like PCI DSS impact your business, we’ve made it easy to access clear, straightforward insights on key IT topics.

Insights to Understanding IT

Contact Us

20178 96 Ave C400
Langley, British Columbia V1M 0B2

Mon to Fri 7:00am–5:00pm

[email protected]

(604) 513-9428

Coleman Technologies Awards & Memberships

Image
Image
Image