There’s probably a drawer somewhere in your home — or a box in the closet, or a forgotten laptop bag under the desk — holding devices you stopped using years ago. An old phone, a retired hard drive, a laptop that got too slow to bother with. And on every single one of them, there’s data you probably think is gone.
The thing is, “gone” and “deleted” aren’t the same thing. Not even close. And if you work from home — handling client files, employee records, or company data on devices that eventually get replaced — those old devices aren’t just clutter. They’re an exposure you haven’t accounted for.
Device Disposal
WFH Security
Digital Clutter
The Data You Thought You Erased
When you drag a file to the trash and empty it, or hit “format” on a drive, the operating system doesn’t actually scrub the data. It marks that space as available for reuse. The ones and zeros that made up that spreadsheet, that photo, that password list — they stay put until something new happens to overwrite them. The National Institute of Standards and Technology has spelled this out clearly in its guidelines on data sanitization: simple deletion and standard formatting don’t meet the bar for making data unrecoverable. You need specific, verified processes — cryptographic erasure, overwriting with multiple passes, or physical destruction — to actually eliminate what’s on a drive.
That’s not abstract. The Verizon Data Breach Investigations Report 2025 consistently finds that human error and asset mismanagement are among the leading causes of data exposure. A drive that walks out of an office — or out of a home office — with client records, financial information, or login credentials still readable on it is a breach waiting for an opportunity.
The Device Graveyard in Your Closet
Here’s the part that’s easy to miss: the risk isn’t just from devices you actively dispose of. It’s from the ones you keep. That old laptop in the guest room closet, the drawer of phones you never traded in, the external hard drive you stopped trusting but never wiped — they’re all sitting there with whatever data was on them when you stopped using them.
Industry guidance from IT asset disposition specialists points out that storage creates exposure in ways people don’t anticipate. No documented chain of custody, no serialized tracking, no destruction certification, no audit trail. If a device disappears from storage — and it happens more often than you’d think — there’s no way to prove what happened to the data on it. Repowered, an ITAD provider, emphasizes that without formal asset disposition processes, the documentation simply doesn’t exist.
Login credentials, saved passwords, email archives, client files, financial records, browser history, cached documents, cloud account tokens, and in many cases, enough personal information to reconstruct a digital identity. The older the device, the more likely it holds data you’ve forgotten about entirely.
And then there’s the compliance angle. If you handle healthcare data, HIPAA requires patient information to be fully erased from retired devices. Financial institutions under GLBA have similar obligations. Government contractors working with federal data need to follow NIST guidelines for sanitization. These aren’t optional best practices — they’re regulatory requirements. A misplaced drive with protected health information or financial records can trigger fines, legal action, and reputational damage that takes years to undo.
Why Factory Reset Is Security Theater
This is where things get uncomfortable. Most people believe that hitting “factory reset” on a phone or laptop wipes it clean. The reality is more complicated, and depending on the device, the data may still be recoverable with tools anyone can download.
A detailed analysis published by cybersecurity researchers showed that a factory reset on an Android 11 phone left over 233,000 files recoverable using standard forensic procedures. Not with specialized government equipment — with consumer software costing $40 to $70, or free tools and a YouTube tutorial. The reset had deleted the file allocation table — the map of where data lives — but the actual data remained on the flash storage chips, intact and reconstructable.
The mechanism behind this is technical but worth understanding. Flash memory uses a technique called wear leveling, which spreads writes across the storage chips to extend their lifespan. That means old data gets left in physical locations that the system hasn’t reused yet. You can fill the phone with new data, reset it again, and still not overwrite the original fragments. The data persistence is unpredictable, and it’s baked into how the hardware works.
There is one critical divider, though: encryption. Modern smartphones — Android 6.0 and later, iOS 8.0 and later — encrypt data by default. When you factory reset an encrypted device correctly, the system deletes the encryption keys. The orphaned data fragments are still there on the chip, but they’re cryptographically inaccessible. Without the key, recovery is effectively impossible. That’s the important nuance: the reset itself doesn’t erase the data, but on an encrypted device, it renders it unreadable.
The problem is that many older devices — and some budget or custom-ROM devices — don’t have encryption enabled. A phone from 2014 or earlier, or any device where encryption wasn’t turned on manually, will leave all its data recoverable after a factory reset. The same goes for external hard drives and USB drives that were never encrypted in the first place.
This is one of those things that feels like it should be simple but isn’t. A factory reset on a properly encrypted modern phone is genuinely secure — the encryption keys get deleted, and the data becomes unrecoverable. A factory reset on an unencrypted device leaves everything readable. The difference isn’t in the reset process. It’s in whether encryption was ever turned on. And most people don’t know which category their old devices fall into.
Peer-reviewed research published in Computers & Security adds another layer: the study by Lenz, Bozakov, Wendzel, and Vrhovec found that privacy concern about improper access to personal information on older smart devices is associated with switching intention — people are more likely to upgrade when they’re worried about data exposure. But the same study found that switching costs (the hassle and expense of replacing devices) often override that concern. People keep using old devices even when they know the devices are no longer receiving security updates, because upgrading feels like more trouble than it’s worth.
What Actually Works: A Realistic Protocol
So what do you actually do with the devices you’re ready to let go of? The answer depends on the device, the data on it, and who might want that data. But there’s a practical sequence that covers most situations.
Check Encryption Status
On Android, go to Settings > Security and look for “Encrypt phone” or “Encryption.” If it says “Encrypted,” you’re good. If it shows “Encrypt phone” as an action you can take, run encryption before doing anything else — this takes an hour or more and requires the device to be plugged in with sufficient battery. On iOS 8.0 and later (iPhone 6 onward), encryption is automatic. Verify by checking Settings > Face ID/Touch ID & Passcode for “Data protection is enabled.” Without encryption, no subsequent step fully protects your data.
Remove All Accounts
Sign out of iCloud or your Google account before wiping. This prevents the device from remaining locked to your account (Activation Lock on iPhone, Factory Reset Protection on Android) and ensures the next owner can’t access your cloud data through cached credentials. Remove SIM and microSD cards separately — factory reset doesn’t touch them.
Factory Reset Correctly
On Android: Settings > System > Reset Options > Erase all data. On iPhone: Settings > General > Transfer or Reset iPhone > Erase All Content and Settings. Stop at the setup screen — don’t connect to Wi-Fi or sign in. If the device is encrypted, this step is sufficient for most threat models.
Overwrite Free Space (Android Only)
For Android devices, consider using a data shredding app like Shreddit or iShredder to write random data across the available storage, then delete and repeat. This addresses the wear-leveling problem by forcing reuse of storage cells. For iPhones, this step isn’t necessary — the Secure Enclave key deletion makes data cryptographically inaccessible.
Wipe Cloud Backups
This is the step most people miss. Old device backups stored in iCloud or Google Cloud often contain the same data you just wiped from the device. Delete old backups from your cloud storage settings, and clear location history and synced data from accounts you no longer use.
For devices with particularly sensitive data — or for situations where the consequences of exposure are severe — physical destruction is the only fully reliable option. Drilling through the memory chips of a hard drive or SSD, or using a certified destruction service that meets NIST SP 800-88 standards, guarantees that the data cannot be recovered by any means. Professional destruction services typically cost $50 to $150 per device and provide a certificate of destruction.
The Work Device Complication
If you work from home using a company-issued laptop, the calculus shifts. You don’t own the device, but you’re responsible for the data on it. The National Law Review notes that terminated remote employees sometimes delay returning company laptops for months, even when provided with prepaid return boxes. During that gap, they may continue accessing sensitive data stored locally on the device. Organizations need remote wipe capability and clear return procedures, but those protections only work if they’re actually enforced.
Company-issued printers and scanner-copiers are an especially overlooked category. Many contain hard drives that save every scanned document. When an employee leaves and the company lets them keep a “worthless” printer, the scanned documents — contracts, invoices, personnel forms — remain on the device’s drive. It’s the kind of exposure that doesn’t make headlines but regularly appears in data breach postmortems.
For your own devices that cross paths with work — a personal laptop used for email, a phone that accesses company Slack — the safest boundary is separation. If that’s not possible, treating the device as a work asset when it’s time to retire it means applying the same sanitization standards you would to a company machine.
There’s good practical guidance on this in our home office privacy guide, and the encryption overview for remote teams covers the technical side of keeping data unreadable even if a device ends up in the wrong hands.
The Timing Problem
Here’s a tension that doesn’t get enough attention: technology refresh cycles are accelerating. Organizations upgrade devices every three to five years, and individuals follow a similar pattern. More devices are being retired every year, which means more drives holding sensitive data, which means more exposure if disposal isn’t handled correctly. The volume of potential risk grows annually.
Meanwhile, the value of old equipment drops rapidly. Aging servers, laptops, and phones sitting in storage lose market value the longer they sit. The common instinct to hold onto devices “just in case” works against both security and resale value. By the time you finally decide to deal with them, they’re worth less and have been accumulating risk longer.
I’m not sure there’s a clean solution to this timing problem. The practical answer is probably to set a schedule — twice a year, go through the devices you’re not using and either wipe them or commit to a disposal plan. The window between “no longer useful” and “security liability” is shorter than most people realize.
The devices in your closet aren’t going to get more secure with time. They’re going to get older, more vulnerable, and harder to remember clearly. Whatever data is on them now will still be there when you finally open that drawer — unless you do something about it before then.