A hundred staff smartphones are about to leave your company in a fleet buyback. Each one holds emails, client contacts, photos and, quite often, sign-in tokens for internal tools. Until that data is gone, it remains your responsibility, even once the device has left the building.

In short: certified data erasure is the complete, verified removal of data from every device, backed by a certificate that lists each unit by IMEI or serial number. Swiss law requires personal data to be destroyed or anonymised once it is no longer needed, and the GDPR says the same for EU operations. The certificate is how you prove you did it.

What is certified data erasure?

Certified data erasure is a process that makes the data on a storage medium unrecoverable, followed by a check and a written record. It differs from three common but insufficient practices:

  • Deleting files: the data stays in memory until it is overwritten.
  • A factory reset done by an employee: it may work technically, but nobody can prove it happened, or on which device.
  • Physical destruction without an inventory: the device is gone, yet no document links what left the company to what was destroyed.

The reference most often cited in the market is NIST Special Publication 800-88, Guidelines for Media Sanitization, published by the US National Institute of Standards and Technology. Revision 2, released in September 2025, replaced the 2014 edition and puts more weight on running sanitisation as an organisation-wide programme. It keeps three sanitisation methods: Clear (protects against simple software recovery), Purge (protects against laboratory recovery while leaving the device reusable) and Destroy (the medium can no longer be used). For a fleet destined for reuse, Purge describes the goal: unrecoverable data on a device that keeps its value.

NIST is a market reference, not a legal requirement in Switzerland or the EU. It helps you describe what you expect from a provider.

What do Swiss law and the GDPR say about erasure?

Switzerland's revised Federal Act on Data Protection (FADP, often called the nFADP or revFADP, and nLPD in French) came into force on 1 September 2023. Like the GDPR, it names no software and no method. Both texts set outcome and diligence duties, and your company must be able to show it meets them.

DutySwiss FADPEU GDPR
Delete what is no longer neededArt. 6 para. 4: data destroyed or anonymised once no longer required for the purposeArt. 5(1)(e): storage limitation
Secure the processingArt. 8: technical and organisational measures appropriate to the riskArt. 32: security of processing
Oversee the service providerArt. 9: the controller ensures the processor can guarantee data securityArt. 28: sufficient guarantees and a written contract
Report a breachArt. 24: notify the FDPIC as soon as possible when there is a high riskArt. 33: notify the authority within 72 hours

Sources: Federal Act on Data Protection, SR 235.1 (English translation on Fedlex) and Regulation (EU) 2016/679 on EUR-Lex. The FDPIC is the Federal Data Protection and Information Commissioner, Switzerland's supervisory authority.

The practical point is Article 9 FADP and its EU counterpart, Article 28 GDPR. When you hand devices to a buyback provider, that provider processes your data for as long as it takes to erase it. You remain accountable for choosing that provider, and you should be able to show you chose it for its guarantees. Note that English translations on Fedlex are for information only: the German, French and Italian versions are legally binding.

Why a company smartphone is a sensitive medium

A laptop holds files. A work smartphone often holds more: synchronised mail, calendars, client contacts, messaging apps, two-factor authentication codes, photos of documents and sometimes VPN profiles or company certificates.

Three situations raise the risk:

  1. Dormant devices. Phones left in a drawer for two years, never reset, whose contents nobody remembers.
  2. Staff departures. The phone is returned, set aside and then mixed with other stock with no record of what it held.
  3. Broken devices. A cracked screen erases nothing. Internal storage can still be read by a technician, even when the device looks useless.

This is why erasure must cover every unit, including faulty ones, and why the whole batch must be documented. An IMEI inventory is the backbone of that proof.

What should a data erasure certificate contain?

A useful certificate is not a general statement. Your data protection officer or auditor must be able to link every device that left your fleet to an erasure operation. Check for these elements:

ElementWhy it matters
Your company and the batch referenceTies the document to one specific operation
List of devices by IMEI or serial numberLets you reconcile against your outgoing inventory
Status per device (erased, not erasable, for parts)Flags special cases instead of hiding them
Processing dateMarks the end of the period during which the data still existed
Legal framework referred to (FADP, GDPR)Shows the basis on which the work was done
Identity of the providerNames the party responsible for the erasure

A certificate stating "150 devices erased" with no itemised list cannot answer the question that matters: was this particular iPhone, returned by this particular employee, erased?

Five questions to ask a buyback provider

Ask these questions in writing before you sign. The answers become part of your documentation under Article 9 FADP.

  1. Is erasure carried out device by device? Bulk processing without unit checks leaves gaps.
  2. Does the certificate list every IMEI or serial number? Without it, reconciliation is impossible.
  3. What happens to a device that no longer switches on? You need a clear answer for broken units.
  4. Where are the devices processed? The location matters for your data transfer rules.
  5. Who receives the documents, and when? The certificate should arrive with the payment, not on request three months later.

To compare how different types of provider answer, read our analysis of independent versus carrier buyback.

Everlink is an independent Swiss partner based in Zug and Basel that buys back and re-equips corporate mobile and IT fleets. Erasure is part of the buyback, not an optional extra.

  • Full erasure, device by device, compliant with the GDPR and the Swiss FADP.
  • An erasure certificate issued to your company, per batch, with the IMEI inventory attached.
  • All relevant devices: smartphones, tablets, laptops and smartwatches, including broken units, which are valued for parts.
  • No preparation on your side: hand the devices over as they are. Administrative unlocking is worked through with you, and resets and certified erasure are handled for you.
  • Paperwork with the payment: a Swiss QR invoice, the full inventory and the erasure certificate.

You end up with a single file: what left the fleet, in what condition, and proof that the data was erased. If you are also selling laptops, the same file covers the buyback of company laptops and IT equipment.

Before pickup: what you can do internally

Certified erasure is the final step. A few actions beforehand make your records stronger:

  • Export your MDM inventory with serial numbers and IMEIs. It becomes the reference for reconciliation.
  • Flag devices of former employees and those that held particularly sensitive data (management, HR, finance).
  • Keep the devices in a locked room between internal collection and pickup.
  • File the certificate with your record of processing activities, so you can find it during an audit or when an employee asks.

For the rest of the procedure, our guide to end-of-lease mobile devices sets out a typical timeline.

Frequently asked questions

Is a factory reset enough to comply with the FADP?

On a recent encrypted smartphone, a factory reset can make the data inaccessible. But the FADP also expects you to be able to demonstrate it. Without a record of the operation for each device, you cannot prove it took place.

Neither the FADP nor the GDPR uses the word. They require you to delete data you no longer need and to take appropriate security measures. A certificate is the simplest way to document that you met those duties.

What about a phone with a broken screen?

The internal storage of a broken device still holds the data, so it must be processed and documented like any other. At Everlink, broken devices are accepted, valued for parts and listed in the inventory.

Everlink carries out full erasure, device by device, in compliance with the GDPR and the FADP, and issues a certificate per batch. If your internal policy requires a specific standard, state it in your request.

Does the GDPR apply to a Swiss company?

It can, for example if you process data of people in the EU through a subsidiary. Erasure that meets both frameworks saves you from running two procedures.

Hand over your fleet with a certificate per batch

Describe your fleet (models, quantities, rough condition) through the contact form, by email at info@everlink.ch or on WhatsApp at +41 78 220 72 80. You receive an offer promptly, and the erasure certificate comes with the payment.