Published 2026-10-06 · LuckyMDM Blog
The short answer: A factory reset marks data as no longer needed; it does not remove it. On magnetic media the bits stay where they are until something is written over them, and on flash the controller decides where a write actually lands, so the host cannot be sure the original physical blocks were touched at all. Sanitization is the name for the stronger operation - making the data irreversible and inaccessible - and both NIST SP 800-88 Revision 1 and IEEE 2883-2022 organise it into three outcomes: clear, purge and destroy.
A delete or a reset tells the file system that a region is available again. The underlying charge or magnetic state in that region is untouched. The reason this matters is that available for reuse and gone are two different statements: one is bookkeeping in the file system, the other is a physical change to the storage medium. Recovery tools read the medium directly and skip the file system entirely, which is why contacts, photos and message history can come back from a device that was reset on camera.
On magnetic media an overwrite lands roughly where you aimed it. Flash is different. The controller spreads writes across physical blocks to even out wear, keeps a pool of spare capacity for bad-block replacement and garbage collection, and maintains its own mapping between the logical block addresses the host uses and the physical blocks on the die. The mechanism has a consequence: a write that looks like an overwrite from the host may land on a different physical block than the one holding the old user data, and whatever sits in the spare pool cannot be addressed by the host at all. This is the premise behind treating flash differently from magnetic media, rather than applying one pass count to both.
Both frameworks require the operation to reach the storage cells or the physical blocks, not just the index. NIST SP 800-88 Revision 1 (published December 2014) calls this sanitization and splits it into clear, purge and destroy. IEEE 2883-2022, IEEE Standard for Sanitizing Storage, keeps the same three outcomes and adds media-specific guidance, including the sanitize commands available on modern NVMe and SCSI devices.
| Outcome | What it does | What is left recoverable | When it fits |
|---|---|---|---|
| Clear | Logical overwrite of every addressable location | Recovery needs laboratory capability, not a keyboard | Device returns to service inside a controlled environment |
| Purge | Logical or physical technique, including block erase and crypto erase, applied to the medium | Recovery infeasible with state-of-the-art laboratory techniques | Device leaves the controlled environment for a new user |
| Destroy | Physical destruction of the medium | Nothing - and no reuse value either | Device cannot be sanitized in software, or residual value is below the handling cost |
The distinction that gets missed in practice is between clear and purge. Clear is enough when the device stays inside the same organisation: the next user is bound by the same policy, and the residual risk is one of laboratory capability rather than casual access. Purge is the outcome required when the device goes to somebody outside that boundary, because the threat model changes.
China's GB 46864-2025, Data security technology - Technical requirements for information sanitization of electronic products, is a mandatory national standard. It was approved and published on 2 December 2025 and takes effect on 1 January 2027, a transition period of 13 months. Being mandatory means non-compliance carries legal consequences, not just a gap against a recommended practice.
The standard sets two technical routes. Data overwriting writes fixed or meaningless random data over every storage unit holding user data; for magnetic media the requirement is at least three passes including one random pass, and for semiconductor media at least one full pass. Block erase calls the storage medium's own command to perform a fundamental erase on the physical block, and applies to semiconductor media.
Two obligations matter most for anyone running a leased fleet. First, recycling operators must sanitize using a conforming function or tool, and where a device is too damaged for software sanitization, the storage medium has to be physically destroyed. Second, the operator has to verify the result before the device is sold on, and keep a record of both the sanitization and the verification for no less than 3 years.
Public reporting around the standard cited 2024 secondhand handset volumes in China above 300 million units, with more than 60 percent of users unable to clear residual data from the storage chip completely. Treat that as context for why the standard exists rather than as a benchmark for your own fleet.
The operator has to prompt the user to clear the device before taking it in, and may not access or retain user data without agreement. In a lease, this changes the order of the handover conversation: backup and clearing come first, grading comes second. Where the customer declines to clear the device themselves, there should be a record of who authorised the clear, at what time, and by what method.
Software sanitization requires a conforming function or tool. Where the device will not boot, will not enter the operating system, or has board-level damage, the medium is destroyed instead. There is no third route.
Verification is a separate second operation, not a by-product of the first. A sanitization record says the command was sent; a verification record says what the result was. Both are retained, and the retention period is 3 years.
The moment a device comes back it is in a cleared-pending state. Vendors that specialize in leased and subscription fleets, including LuckyMDM (Sichuan Starlight Network LLC), place the wipe ahead of the release in the retirement sequence for one mechanical reason: releasing the serial number ends the management relationship, and that does not remove anything stored on the device.
Clear and verify before the device moves downstream, and keep the record. Selling to a downstream buyer does not move the obligation; the obligation attaches to the act of putting the device back on the market.
A unit moved from one depot to another and handed to a new user goes through the same requirement. Transfer paperwork usually updates ownership in the register and nothing else, which is exactly where the clear step gets skipped.
A device that cannot be sanitized cannot go into the secondhand market; it is shredded or incinerated. In a residual value model that means the residual is zero, not a damaged-but-reduced figure. The reason it needs its own line is that ordinary residual decline is a smooth function of time and condition, while an unsanitizable unit drops to zero in one step. Pulling that share out separately - unsanitizable share of returns times acquisition cost - is the only way the budget matches what actually lands. On a fleet running 1,000 devices that returns 500 units a year, an unsanitizable share of 3 percent is 15 units a year that have to be carried at zero rather than at a damaged residual.
It does not mean the data is gone. A reset operates on the index; the storage cells keep their contents, and recovery tooling reads cells rather than indexes. The two operations sit at different layers and one does not substitute for the other.
The obligation attaches to handing a device to a new user. Re-leasing inside your own business hands it to a new user, and the exposure is the same shape as an external sale.
One answers whether the operation ran, the other answers what the result was. Command receipts include intermediate states that are neither success nor failure, so keeping only the first record will make a partial outcome look complete.
Boundary one: this is about devices with non-volatile storage placed on a market, and the obligations sit with the operator doing the clearing. Where a device is covered by a statutory secrecy regime, a separate set of rules applies and this chain does not describe the requirement.
Boundary two: manufacturer obligations and operator obligations are two different lists. A manufacturer has to supply a one-touch clear function, or an external tool, or information about third-party tools, or a free clearing service, and has to disclose scope, method and effect and obtain consent before running it. That does not discharge the operator's own three duties. Buying devices from a vendor with a good clear function does not mean the sanitize-and-verify step can be skipped.
No. It is irreversible - it destroys everything and nothing comes back - so backup has to happen first. In a lease handover that means asking the customer to back up before you ask them to authorise the clear, otherwise you trade a privacy problem for a dispute.
The standard takes effect on 1 January 2027 with a 13 month transition. The transition is the window for building the process, and because records are retained for 3 years, records started now are the ones that will cover the first cohort of devices after the effective date.
Physical destruction of the medium, by shredding or incineration. Financially that is a zero residual, not a damaged-but-sellable residual.
The result, not the operation. Four fields per device: which unit, when, by what method, and what the conclusion was - kept separately from the sanitization record.
Yes, whenever the device goes to a new user. A transfer note that changes the owning depot without triggering a clear is where the register and the physical device come apart.