1. What the IT Act actually says
The relevant provisions are short and technology-neutral:
- Section 43A — a body corporate in possession of personal information, and failing to take reasonable security safeguards, is liable to pay compensation to the affected person. "Reasonable security safeguards" is the phrase everything hangs on.
- Section 70A — applies to bodies performing professional services, requiring security practices in line with information security standards.
- Section 70 & the IT (Reasonable Security) Rules — the rules set out what reasonable security should include, leaving the technology choices to the organisation.
- Section 72 — penalties for unauthorised access to a computer system, and for unauthorised disclosure of information contained in it.
None of these name a machine. All of them make the outcome the thing that matters: information in your custody must not end up in someone else's hands. A retired hard drive in an e-waste channel is a way for that to happen.
2. Why a degausser is a "reasonable safeguard"
Courts and regulators do not test whether you bought a specific product. They ask whether your controls were reasonable for the risk. A defensible control has four properties, and a degausser has all four:
- Appropriate to the medium. Magnetic media is purged magnetically; flash and optical media are physically destroyed. The method matches the risk.
- Repeatable and documented. A register per asset means you can evidence the control rather than assert it.
- Independent of the device's condition. A failed drive still gets sanitised. Software-based controls fail exactly when the media is most likely to be sensitive.
- Verifiable. Per-cycle field verification means the record can be trusted.
3. A compliant IT Act media process
| Stage | Control | Evidence |
|---|---|---|
| Acquire | Media is recorded in the asset register with classification | Asset register entry |
| Classify | Data classification determines the required sanitisation level | Classification on the asset record |
| Schedule | Retired media is queued for destruction, not stored indefinitely | Destruction queue / job ticket |
| Secure | Media held in a locked area until processed; general waste bins cannot accept media | Physical control, access list |
| Purge magnetic media | Degauss to NIST 800-88 purge level with per-cycle verification | Cycle verification value in the register |
| Destroy flash and optical | Shred or crush | Destruction register entry |
| Physically destroy | Crush the sanitised magnetic media | Destruction register entry |
| Dispose | Scrap through an authorised e-waste recycler | Recycler authorisation, weighment receipt |
| Retain | Register retained for at least the longest data retention period | Records management policy |
| Review | Periodic independent review of the disposal process | Internal / external audit report |
4. Section 43A in practice: what a court or customer asks
In a dispute or a customer due-diligence exercise, the questions are predictable. Prepare the answers in advance:
- What is your written information security and media disposal policy? Produce the document and its version history.
- What were the controls for decommissioned and failed media? Produce the process and the register.
- Can you show a specific asset was destroyed, by when, and with what evidence? Produce the register row with the cycle verification.
- How do you ensure third parties performing disposal follow your standard? Produce the contract, the audit rights and the sampled results.
- How do you prevent media reaching general waste? Produce the physical control description and the bin segregation arrangement.
5. IT Act and DPDP Act together
Most Indian organisations now run one documented media destruction process and map it to both statutes plus their contractual and certification obligations. That avoids duplicated work and — more importantly — avoids the gap where one policy covers one law and misses the other.
| Obligation | Source | What it needs from the destruction process |
|---|---|---|
| Reasonable security safeguards for personal information | IT Act s.43A, s.70A and Rules | Documented, appropriate, evidenced media disposal |
| Erasure and deletion of personal digital data | DPDP Act 2023 and Rules | Deletion that is complete, timely and provable, including on retired media |
| Media sanitisation to an international standard | NIST 800-88 (contractual / certification) | Purge for magnetic media, destroy for flash, with verification |
| NSA/CSS evaluated equipment | Government, PSU, defence tender clauses | Proton T-4 / T-5, PDS-75 / PDS-100 |
| Independent review of security arrangements | RBI / sectoral directions | A process that can be sampled and audited |
| E-waste handling and documentation | E-Waste (Management) Rules | Authorised recycler with a traceable downstream chain |
6. Practical steps for an Indian organisation this quarter
- Inventory every medium currently in a store room, a returned-hardware shelf and a scrap bin.
- Identify any medium holding customer or personal data that has not been sanitised.
- Segregate media bins from general waste, and label them.
- Write or revise the media disposal policy, naming the method per media type.
- Adopt a destruction register format and require it for every batch.
- Decide on equipment: buy, rent, or contract an ITAD vendor — and document the choice.
- Train and authorise operators; keep training records.
- Run a first sanitised destruction batch and close it out with a signed register.
- Add the review point to the annual audit plan.