Data Security, Physical Security & Logistics

Contact us with your details and You can expect a prompt response from Monday to Friday, between 8:30 AM and 5:00 PM to assist you with your questions and requirements.

    Name

    Email

    Company Name

    Phone Number

    Your Message

    Marketing Preference:


    DATA SECURITY

    CRUK acknowledge and accept that it is processing the Controller Data as a service provider and Processor and that, as between the parties, the Controller Data and all intellectual property rights in the Controller Data shall belong to the Controller absolutely.
    Upon collection of the Equipment from the controller, an Asset transfer note is signed by CRUK (Processor) & Controller which will indemnify Controller against any breach of Data Protection Laws including the unforeseen release or publication of any aforesaid Controller Data into the public domain. Such liability is covered by CRUK Professional Indemnity Insurance Policy which will not exceed £1,000,000.

    CRUK are entrusted to ensure anything data bearing has it’s data destroyed, irrespective of whether the product is working or not. This is a very serious subject since we must adhere to Data Protection Laws, and supported by our ADISA certification, the UKs only ICO approved GDPR certification scheme which confirms our services meet legal UK GDPR compliance when handling redundant data bearing devices.

    Data Risks (source: IBM Cost of a Data Breach Report 2023).
    The average cost of a data breach in 2023 is USD $4.45 million
    In 2023, the average cost per record involved in a data breach is USD $165.
    Costs include informing victims and regulators that a breach has occurred, costs of investigating and fixing the source of the data breach, consequent loss of business.

    The 2 methods of Data Destruction used by CRUK, are Data Erasure and Data Shredding. CRUK are ADISA Standard 8.0 certified, and can provide a UK GDPR compliant ITAD DIAL 2 level of service at DISTINCTION, and meet the current recognised data sanitisation guidelines of NIST 800-88 rev 1 and IEEE2883:2022.

    DATA ERASURE

    Data Erasure is completed using independently certified Software, for all Solid-State Drives (SSD), Magnetic Hard Drives (HDD), Network Switches, iOS & Android smartphones & tablets, within a secure password entry only area of Computer Recyclers UK facilities.

    CRUK performs NIST 800-88 purge data commands, which identified and handles all hidden HPA and DCO areas, remapping all sectors of the drives with 10% verification, making forensic recovery impossible, from all Solid-State Drives, Magnetic Hard Drives.

    For all iOS & Android smartphones & tablets, CRUK performs a single overwrite on iOS & Android devices using cryptographic sanitisation.

    Data Shredding is completed using our U-15 Ulster Shredder which enables us to shred data bearing media down to 6mm shred size without leaving clients premises or at CRUK premises too.

    CRUKs Ulster 15H Hydraulic Disintegration Shredder treats all Business Impact levels including TOP SECRET (BIL6), in accordance to NIST 800-88 rev 1, IEEE2883:2022 guidelines, HMG IA Standard No.5 and the advised shred size models identified in the CPNI standard.

    CRUK provide clients with a listing of serial numbers of all devices shredded and Certificates of Data Destruction. The certificate makes reference to the fact that the hard drives have been destroyed to 6mm shred size.

    With both options of Data Erasure and Data shredding available at CRUK, all data is securely destroyed and no data can be retrieved or reconstructed by any further method or technique after going through CRUK secure Data Destruction process.

    Computer Recyclers UK are one of few UK companies accredited ADISA IT Asset Recovery Standard 8.0

    ADISA Standard 8.0 certification is the UKs only UKAS-accredited, ICO approved GDPR certification scheme, with a 200+ assessment criteria, confirming Computer Recyclers UK can provide a UK GDPR compliant ITAD DIAL 2 level of service at DISTINCTION and meet the current recognised data sanitisation guidelines of NIST 800-88 rev 1 and IEEE2883:2022.

    Computer Recyclers UK clients, releasing their redundant data bearing assets are assured of compliance with the law, not because their supplier tells them, not because ADISA does, but because the data regulatory themselves verifies compliance through certification.

    PHYSICAL SECURITY OF VEHICLES AND COLLECTION PROCESS
    All collections are made by CRUK with CRUK staff. No dedicated collection companies are used.
    CRUK vehicles have GPS trackers installed. The trackers allow CRUK to monitor the vehicles transport in real time and the GPS trackers data is stored for a minimum of 12 months.
    Each vehicle is alarmed, deadlocked, solid sided, non-branded, and have solid bulkheads.
    Multi-point collections include physical separation of loads by using wooden crates and cages to separate loads.
    All CRUK drivers follow the CRUK Driving for Work Policy which can supplied if required.
    All CRUK staff wear Computer Recyclers Limited Polo Shirts
    Every collection of Equipment is dedicated as standard, whether the Equipment contains data or not.

    MITIGATION OF RISK DURING TRANSPORTATION
    CRUK drivers have Photo ID available at every collection to identify themselves to the client as the person responsible for collecting Equipment.
    An Asset transfer note is always provided with every collection, listing what has been collected. A signature is always required on the Asset transfer note from the client and CRUK, releasing the Equipment to CRUK to process.
    All CRUK staff are vetted in accordance with BS7858, with full DBS checks.
    Each driver has their driving licence or permit checked annually. Driving licences are checked on an annual basis in an adhoc way.

    EXTERNAL SITE SECURITY

    No Equipment is left on any CRUK vehicle overnight
    CRUK Vehicles are unloaded within a secure area or inside the facilities, of which are all covered with of CCTV.
    All Equipment once unloaded is taken inside the premises immediately where there is further CCTV coverage.
    CRUK have an intruder alarm installed to PD6662 standard, monitored by an approved BS5979 alarm receiving centre.
    CRUK have an intruder alarm on all external pedestrian access points.
    CRUK have an intruder alarm with Passive Infrared (PIR) coverage.
    CRUK Facility is wholly located within its own compound with physical security fencing barrier around all perimeters.

    INTERNAL SECURITY
    CRUK CCTV covers;
    – Unloading and loading areas
    – All access points to the building
    – Data processing area.
    CCTV coverage is backed up weekly onto an external drive and stored off site which is away from CCTV recording device.
    All CRUK staff are vetted in accordance with BS7858, with full DBS checks
    The data processing facility has controlled access via 6 key access locks and fob access.
    CRUKs facilities have controlled access such as;
    – Only Authorised staff are allowed into CRUKs data processing area
    – Visitors are escorted into the processing areas. Badges are issued to all visitor and all visitors are signed in when entering CRUK premises.
    – No visitors or unauthorised staff are allowed into data processing areas unless they have their identification verified using photo ID and it is recorded.
    – CRUK Staff are required to keep personal items in their canteen area. No bags, coats or mobile phones allowed in the processing area.
    All CRUK visitors wear clearly visible badges and/or vests which identify them as being non-staff and are escorted through processing areas at all times.