Under the amended Safeguards Rule, institutions must adopt documented secure disposal procedures and, absent a documented exception, dispose of customer information within a reasonable period after its last use, commonly about two years. Meet that standard by pointing your program at two references: NIST SP 800-88 Rev 2 for how you destroy media, and 16 CFR §682.3 for what the law requires. Start this quarter with a written SOP, a named Qualified Individual, and serialized certificates of destruction for every device that leaves your custody.
TL;DR:
- Disposing of customer information within about two years of last use is standard unless there is a documented business or legal reason to retain it longer.
- Physical destruction or cryptographic erasure is required for electronic media, especially for SSDs and flash drives, since overwriting cannot reliably remove residual data.
- Vendors must provide serialized certificates of destruction, chain-of-custody logs, and proof of ongoing oversight, with documentation increasingly scrutinized in audits.
- Regular vendor reassessments—at least annually—are essential to meet examiner expectations and ensure destroyed data cannot be recoverable.
- Discovery of missing or mishandled devices must trigger immediate tracing, forensic validation, and thorough documentation to avoid breach notifications under the 2024 Safeguards Rule.
Table of Contents
- What Does the GLBA Disposal Rule Actually Require?
- How Do NIST Sanitization Standards Apply to Financial Data?
- What Should You Look for When Selecting a Disposal Vendor?
- What Documentation Do Auditors Expect for Disposal Programs?
- What Triggers Breach Notification After a Disposal Incident?
- A 30/60/90-Day Plan to Build an Audit-Ready Program
- Lessons From the Field on Disposal Compliance
- How Usedcartridge Closes the Gaps in Your Disposal Program
- Sources
- FAQ
What Does the GLBA Disposal Rule Actually Require?
The phrase “GLBA disposal rule” doesn’t point to a single regulation. It’s shorthand compliance officers use for a set of overlapping obligations that all trace back to the Gramm-Leach-Bliley Act: the FTC Safeguards Rule (16 CFR Part 314) and the FCRA Disposal Rule (16 CFR §682.3). Both apply to how financial institutions get rid of customer and consumer information, and both got sharper teeth in the 2023 Safeguards Rule amendments.
The Safeguards Rule is the broader of the two. As of the June 2023 amendments, it requires financial institutions to maintain written procedures for securely disposing of customer information in any format, paper or electronic, and to periodically review how long that information is retained. The rule sets a default disposal window typically around two years tied to the last date the information was used, unless you have a documented business or legal reason to keep it longer.
The Disposal Rule under the Fair Credit Reporting Act is narrower but more concrete about method. It requires anyone who maintains consumer information for a business purpose to take reasonable measures against unauthorized access during disposal. The regulation names specific acceptable measures: burning, pulverizing, or shredding paper records; erasing electronic media so the data can’t practicably be read; and contracting with a qualified, vetted record-destruction vendor.
Examiners layer a third expectation on top of these two. Interagency guidance from banking regulators has moved in step with the amended Safeguards Rule. Consequently, disposal documentation written before mid-2023 is likely already out of date in an exam. Together, these three sources form the compliance stack:
- 16 CFR Part 314 sets the program-level requirement: written procedures, risk assessment, retention review.
- 16 CFR §682.3 sets the disposal-method bar: reasonable measures, named examples, vendor due diligence.
- Interagency examiner guidance sets the practical expectation: documentation has to reflect the current rule, not the 2003 version most programs were built around.
How Do NIST Sanitization Standards Apply to Financial Data?
NIST SP 800-88 Rev 2 is the technical benchmark examiners and auditors expect you to reference, even though it’s a security guideline rather than a law. It defines three sanitization levels, and picking the wrong one for a given device is one of the most common gaps in disposal programs.
- Clear removes data using standard read/write commands, like a factory reset. It’s the weakest level and generally not defensible for media that held customer financial data.
- Purge applies physical or logical techniques, such as cryptographic erase or degaussing, that make recovery infeasible even with advanced lab techniques.
- Destroy physically disintegrates, pulverizes, shreds, or melts the media so it can never be reused or read.
For hard drives and servers reaching end of life, physical destruction is generally treated as the most reliable option, because it removes any residual risk that a purge method failed silently. Solid-state drives complicate the picture further: their wear-leveling architecture means overwriting doesn’t reliably touch every physical cell, so destruction or cryptographic erase is typically the only defensible end-of-life option for SSDs and flash media.
Mobile devices, memory cards, and SIMs need their own protocol. CISA’s guidance on device disposal recommends physical destruction of memory and SIM cards specifically, since factory resets on phones and tablets don’t reliably clear cached credentials or app data.
Pro Tip: Never assume a vendor’s “wipe” service meets the purge standard just because they call it that. Ask them which NIST 800-88 method they’re certifying against, in writing, before you sign a contract.
Software wipe utilities remain acceptable for many use cases the FTC itself cites as reasonable measures for electronic media disposal. The distinction that matters for financial institutions is scale and reuse: media that’s being redeployed internally can often be cleared or purged, while media leaving your custody permanently, especially anything that touched core banking systems, belongs on the destroy track. Our own breakdown of NIST data destruction rules walks through which method applies to which media type in more detail.

What Should You Look for When Selecting a Disposal Vendor?
The 2023 Safeguards Rule amendments raised the bar on vendor oversight, and §314.4(f) now expects ongoing monitoring, not a one-time vetting call. Build your vendor selection process around three phases.
- Pre-selection due diligence. Confirm relevant certifications, request SOC 2 reports or independent audit documentation, and ask for references from other financial-sector clients specifically.
- Contract language. Specify the exact NIST sanitization standard required by media type, require serialized device-level reporting, chain-of-custody documentation, proof of insurance, and a breach-notification clause with a defined timeline.
- Periodic reassessment. Set a recurring cadence, annually at minimum, to re-review vendor performance, collect updated audit reports, and document any remediation history.
That third phase is where most programs quietly fall short. A single vendor audit sitting in a contract file from three years ago no longer satisfies what examiners are asking to see. Periodic, dated, risk-based reassessments have become the standard, not the exception, and the absence of a recurring review file is one of the first things an examiner will flag.
If you handle data recovery scenarios alongside disposal, it’s worth understanding when recovery is technically still possible on failed or damaged drives. Resources like ISO Class 5 cleanroom data recovery services illustrate why partial destruction or a failed wipe can leave data recoverable, which is exactly the scenario your vendor contract should make impossible.
What Documentation Do Auditors Expect for Disposal Programs?
Examiners in 2026 want to see a specific evidence trail, not just a policy binder. Build your documentation set around five categories.
- A written disposal SOP that names the sanitization standard for each media type, the retention review cadence, and the roles responsible for execution.
- Retention-justification logs documenting any case where customer information was kept past the two-year default, with the specific business or legal reason recorded.
- Device-serial destruction certificates tying each destroyed asset’s serial number to a date, method, and operator.
- Vendor reassessment files, dated and updated on a recurring schedule, not a single audit from years back.
- Incident logs covering any disposal-related exposure, however minor, with the investigative steps taken.
The Qualified Individual role sits at the center of all of this. That person, required under the Safeguards Rule, is expected to sign off annually on the disposal program and attest that vendor oversight actually happened, not just that a policy exists on paper. Examiners increasingly expect a dated attestation from a named individual rather than a generic “IT department” sign-off.
Serialized, device-level certificates of destruction are treated as far stronger evidence than generic lot receipts that just state “200 drives destroyed on this date.” A chain-of-custody log that tracks a device from pickup through final destruction, with a witness signature at the point of destruction, closes the gap examiners look for. Our guide to certified hard drive destruction covers what a defensible certificate should include line by line.
What Triggers Breach Notification After a Disposal Incident?
A disposal-related incident, a drive that went missing before destruction, a vendor that skipped a step, still triggers the same notification math as any other data event. The 2024 Safeguards Rule amendment requires covered non-bank financial institutions to notify the FTC within 30 days of a notification event affecting 500 or more consumers.
If you suspect a disposal-related exposure, move through these steps immediately:
- Trace the inventory. Identify exactly which devices or records were involved and whether the 500-consumer threshold is plausible.
- Validate forensically. Confirm whether the data was actually exposed or recoverable, versus merely mishandled in transit.
- Review the vendor chain. Pull the chain-of-custody log and destruction certificate to see where the process broke down.
- Contain and document. Preserve every record showing what your due diligence looked like before the incident, since that evidence shapes both your notification decision and your defense in a subsequent exam.
The institutions that come out of these incidents looking competent are the ones who can hand an examiner a complete paper trail within a day, not the ones who scramble to reconstruct what happened after the fact.
A 30/60/90-Day Plan to Build an Audit-Ready Program
Most disposal programs don’t fail because the destruction method was wrong. They fail because the paperwork behind it was thin, undated, or missing entirely. Fixing the records usually matters more than upgrading the shredder.
Days 1 to 30:
- Inventory all media types holding customer information and flag anything past the two-year default without a documented exception.
- Formally appoint or confirm your Qualified Individual and get the appointment in writing.
Days 31 to 60:
3. Rewrite or update your disposal SOP to name specific NIST 800-88 levels by media type.
4. Amend vendor contracts to require serialized certificates, chain-of-custody logs, and breach-notification language.
Days 61 to 90:
5. Schedule your first (or next) periodic vendor reassessment and set a recurring calendar date for future ones.
6. Run a mock exam response: pull a sample destruction certificate and confirm it has device serial, method, date, operator, and witness fields filled in.
Fields every SOP and certificate template should carry:
- Device serial number
- Sanitization method (clear, purge, or destroy)
- Date of disposal
- Operator name
- Witness signature
Assign an owner to each task with a hard deadline, not a “sometime this year” note. Our electronics disposal planning guide breaks these steps into a format you can hand directly to IT and facilities teams.
Lessons From the Field on Disposal Compliance
Working with financial institutions on device destruction turns up the same pattern over and over: the sanitization method is rarely the problem. On-site destruction with serialized, device-level reporting closes most gaps we see. What actually trips up an exam is a missing signature, an undated vendor review, or a lot receipt that can’t be traced to a single serial number. Fix the records, and the rest of the program holds up.
— Keith
How Usedcartridge Closes the Gaps in Your Disposal Program
Some providers offer device-serial certificates of destruction tied to a documented chain of custody, generated the same day the equipment leaves your building. That’s the exact evidence category examiners have started asking for since the 2023 Safeguards Rule amendments, and it’s the piece most in-house disposal processes are missing.

Some vendors handle both on-site and off-site destruction of hard drives, laptops, and networking equipment, with serialized reporting that matches each device to its destruction date, method, and operator. For institutions managing vendor reassessment requirements under §314.4(f), such documentation can serve as the dated evidence file for annual sign-off. Contract language, chain-of-custody logs, and destruction certificates may arrive as part of the service, not as an afterthought.
If your program is due for a vendor review, or you simply need your next batch of retired drives destroyed to a standard you can hand an examiner without hesitation, request an IT asset disposition quote and get the process moving before your next exam cycle.
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
Sources
- FTC — FTC Safeguards Rule: What Your Business Needs to Know
- NIST SP 800-88 Rev. 2 — Guidelines for Media Sanitization
- 16 CFR § 682.3 – Proper disposal of consumer information (Cornell LII)
FAQ
What Are the Three Key Rules Under GLBA?
GLBA’s three main components are the Financial Privacy Rule, which governs how institutions collect and share nonpublic personal information; the Safeguards Rule, which requires a written information security program including disposal procedures; and the Pretexting Provisions, which prohibit obtaining customer information through false pretenses.
What Is the Disposal Rule?
The Disposal Rule, found at 16 CFR §682.3, requires anyone maintaining consumer information for a business purpose to take reasonable measures against unauthorized access when disposing of it, with shredding, erasing, and vendor destruction contracts named as acceptable methods.
How Long Do You Have to Dispose of Customer Data Under GLBA?
The amended Safeguards Rule sets a default disposal window typically around two years measured from the last date the information was used, unless a documented business or legal reason justifies retaining it longer.
What Counts as Proper Disposal of Consumer Information Under the FCRA?
Proper disposal under the FCRA’s Disposal Rule means taking reasonable measures against unauthorized access, such as burning, pulverizing, or shredding paper records, erasing electronic media so data can’t practicably be read, or contracting a vetted record-destruction vendor.
Does a Vendor’s Certificate of Destruction Satisfy Examiner Requirements?
Generic lot-level receipts increasingly fall short. Examiners now favor serialized, device-level certificates of destruction paired with dated chain-of-custody logs, which is the documentation format Usedcartridge provides on completed jobs.