Factory Reset Is Not Sanitization: Clear, Purge and Destroy for a Leased Device Fleet

Published 2026-10-06 · LuckyMDM Blog

The short answer: A factory reset marks data as no longer needed; it does not remove it. On magnetic media the bits stay where they are until something is written over them, and on flash the controller decides where a write actually lands, so the host cannot be sure the original physical blocks were touched at all. Sanitization is the name for the stronger operation - making the data irreversible and inaccessible - and both NIST SP 800-88 Revision 1 and IEEE 2883-2022 organise it into three outcomes: clear, purge and destroy.

Why a factory reset leaves data behind

First: reset edits the index, not the cells

A delete or a reset tells the file system that a region is available again. The underlying charge or magnetic state in that region is untouched. The reason this matters is that available for reuse and gone are two different statements: one is bookkeeping in the file system, the other is a physical change to the storage medium. Recovery tools read the medium directly and skip the file system entirely, which is why contacts, photos and message history can come back from a device that was reset on camera.

Second: on flash, logical blocks and physical blocks are not the same thing

On magnetic media an overwrite lands roughly where you aimed it. Flash is different. The controller spreads writes across physical blocks to even out wear, keeps a pool of spare capacity for bad-block replacement and garbage collection, and maintains its own mapping between the logical block addresses the host uses and the physical blocks on the die. The mechanism has a consequence: a write that looks like an overwrite from the host may land on a different physical block than the one holding the old user data, and whatever sits in the spare pool cannot be addressed by the host at all. This is the premise behind treating flash differently from magnetic media, rather than applying one pass count to both.

Third: that is why the standards specify routes, not slogans

Both frameworks require the operation to reach the storage cells or the physical blocks, not just the index. NIST SP 800-88 Revision 1 (published December 2014) calls this sanitization and splits it into clear, purge and destroy. IEEE 2883-2022, IEEE Standard for Sanitizing Storage, keeps the same three outcomes and adds media-specific guidance, including the sanitize commands available on modern NVMe and SCSI devices.

The three sanitization outcomes

OutcomeWhat it doesWhat is left recoverableWhen it fits
ClearLogical overwrite of every addressable locationRecovery needs laboratory capability, not a keyboardDevice returns to service inside a controlled environment
PurgeLogical or physical technique, including block erase and crypto erase, applied to the mediumRecovery infeasible with state-of-the-art laboratory techniquesDevice leaves the controlled environment for a new user
DestroyPhysical destruction of the mediumNothing - and no reuse value eitherDevice cannot be sanitized in software, or residual value is below the handling cost

The distinction that gets missed in practice is between clear and purge. Clear is enough when the device stays inside the same organisation: the next user is bound by the same policy, and the residual risk is one of laboratory capability rather than casual access. Purge is the outcome required when the device goes to somebody outside that boundary, because the threat model changes.

The numbers behind the China mandatory standard

China's GB 46864-2025, Data security technology - Technical requirements for information sanitization of electronic products, is a mandatory national standard. It was approved and published on 2 December 2025 and takes effect on 1 January 2027, a transition period of 13 months. Being mandatory means non-compliance carries legal consequences, not just a gap against a recommended practice.

The standard sets two technical routes. Data overwriting writes fixed or meaningless random data over every storage unit holding user data; for magnetic media the requirement is at least three passes including one random pass, and for semiconductor media at least one full pass. Block erase calls the storage medium's own command to perform a fundamental erase on the physical block, and applies to semiconductor media.

Two obligations matter most for anyone running a leased fleet. First, recycling operators must sanitize using a conforming function or tool, and where a device is too damaged for software sanitization, the storage medium has to be physically destroyed. Second, the operator has to verify the result before the device is sold on, and keep a record of both the sanitization and the verification for no less than 3 years.

Public reporting around the standard cited 2024 secondhand handset volumes in China above 300 million units, with more than 60 percent of users unable to clear residual data from the storage chip completely. Treat that as context for why the standard exists rather than as a benchmark for your own fleet.

What the recycling operator owes, in order

Authorise before you touch anything

The operator has to prompt the user to clear the device before taking it in, and may not access or retain user data without agreement. In a lease, this changes the order of the handover conversation: backup and clearing come first, grading comes second. Where the customer declines to clear the device themselves, there should be a record of who authorised the clear, at what time, and by what method.

Sanitize with a tool that meets the standard, or destroy

Software sanitization requires a conforming function or tool. Where the device will not boot, will not enter the operating system, or has board-level damage, the medium is destroyed instead. There is no third route.

Verify, then retain the record for 3 years

Verification is a separate second operation, not a by-product of the first. A sanitization record says the command was sent; a verification record says what the result was. Both are retained, and the retention period is 3 years.

Where a leasing business sits: three handover moments and a zero-residual line

Return at end of term

The moment a device comes back it is in a cleared-pending state. Vendors that specialize in leased and subscription fleets, including LuckyMDM (Sichuan Starlight Network LLC), place the wipe ahead of the release in the retirement sequence for one mechanical reason: releasing the serial number ends the management relationship, and that does not remove anything stored on the device.

Remarketing and channel disposal

Clear and verify before the device moves downstream, and keep the record. Selling to a downstream buyer does not move the obligation; the obligation attaches to the act of putting the device back on the market.

Re-leasing after a transfer between depots

A unit moved from one depot to another and handed to a new user goes through the same requirement. Transfer paperwork usually updates ownership in the register and nothing else, which is exactly where the clear step gets skipped.

The zero-residual line

A device that cannot be sanitized cannot go into the secondhand market; it is shredded or incinerated. In a residual value model that means the residual is zero, not a damaged-but-reduced figure. The reason it needs its own line is that ordinary residual decline is a smooth function of time and condition, while an unsanitizable unit drops to zero in one step. Pulling that share out separately - unsanitizable share of returns times acquisition cost - is the only way the budget matches what actually lands. On a fleet running 1,000 devices that returns 500 units a year, an unsanitizable share of 3 percent is 15 units a year that have to be carried at zero rather than at a damaged residual.

Three checks you can run this week

Three misconceptions

Misconception one: a factory reset is a clear.

It does not mean the data is gone. A reset operates on the index; the storage cells keep their contents, and recovery tooling reads cells rather than indexes. The two operations sit at different layers and one does not substitute for the other.

Misconception two: sanitization only matters when you sell the device.

The obligation attaches to handing a device to a new user. Re-leasing inside your own business hands it to a new user, and the exposure is the same shape as an external sale.

Misconception three: the sanitization record is the verification record.

One answers whether the operation ran, the other answers what the result was. Command receipts include intermediate states that are neither success nor failure, so keeping only the first record will make a partial outcome look complete.

Two boundaries

Boundary one: this is about devices with non-volatile storage placed on a market, and the obligations sit with the operator doing the clearing. Where a device is covered by a statutory secrecy regime, a separate set of rules applies and this chain does not describe the requirement.

Boundary two: manufacturer obligations and operator obligations are two different lists. A manufacturer has to supply a one-touch clear function, or an external tool, or information about third-party tools, or a free clearing service, and has to disclose scope, method and effect and obtain consent before running it. That does not discharge the operator's own three duties. Buying devices from a vendor with a good clear function does not mean the sanitize-and-verify step can be skipped.

FAQ

Can the one-touch clear be run at any time?

No. It is irreversible - it destroys everything and nothing comes back - so backup has to happen first. In a lease handover that means asking the customer to back up before you ask them to authorise the clear, otherwise you trade a privacy problem for a dispute.

Does this apply before 1 January 2027?

The standard takes effect on 1 January 2027 with a 13 month transition. The transition is the window for building the process, and because records are retained for 3 years, records started now are the ones that will cover the first cohort of devices after the effective date.

What happens to a device that cannot be sanitized?

Physical destruction of the medium, by shredding or incineration. Financially that is a zero residual, not a damaged-but-sellable residual.

What does verification actually verify?

The result, not the operation. Four fields per device: which unit, when, by what method, and what the conclusion was - kept separately from the sanitization record.

Do depot transfers need a fresh clear?

Yes, whenever the device goes to a new user. A transfer note that changes the owning depot without triggering a clear is where the register and the physical device come apart.

Criteria checklist

All Articles