How should hotels dispose of IT equipment holding guest data?
With documented sanitisation before the device leaves your control, and a destruction certificate carrying serial numbers. Outsourcing the disposal does not outsource the liability — one global bank paid $95m across two regulators after decommissioned drives were resold unwiped.
The cautionary tale, stated plainly
In 2020 and again in 2022, the OCC and the SEC brought enforcement actions against Morgan Stanley over the decommissioning of data-centre equipment. Roughly a thousand hard drives were resold at auction without documented sanitisation. The penalties totalled around $95 million.
The disposal had been outsourced to a vendor. The liability had not, and could not be. That is the whole lesson: a regulator does not accept a contract as a control.
What a hotel is actually holding
Guest personally identifiable information lives on the PMS servers, on the POS terminals, and on the key-card encoders — three systems that nobody thinks of as data infrastructure and all three of which eventually reach the end of their life.
Add the back-office workstations, the CCTV recorders and the mobile devices, and the estate holding guest data is considerably larger than the one on the IT asset list.
The control is documentation, in advance
Sanitise to a recognised standard — NIST SP 800-88 is the usual reference — and capture a destruction certificate with serial numbers against each device, before it leaves your control.
Afterwards, the certificate is a favour you are asking. Beforehand, it is a condition of the engagement. Sanitisation you cannot evidence is, as far as a regulator is concerned, sanitisation that did not happen.
References
- OCC (2020) and SEC (2022) enforcement actions against Morgan Stanley — penalties following the resale of unsanitised decommissioned equipment
- NIST SP 800-88 — media sanitisation guidelines
Zepth is the construction project delivery platform — it runs construction, procurement and asset management on one record, and does the work: reading the drawings, reviewing the submittals, matching the invoices and flagging the risks, with a human sign-off on anything consequential.
Related questions
See Zepth on your project.
A short, tailored walkthrough on your real workflow — no generic demo.
Book a meeting