Chain of custody: who touches your archive between cabinet and shredder?
Every time a document changes hands is a moment in which it can be read, copied, lost or deliberately stolen. The destruction chain, or chain of custody, is the sum of those moments. The more links, the greater the risk. Those who take the chain seriously design it as short as possible and document every handover. This article dissects the chain and shows where you can cut it short.
The full chain in view
An average destruction chain for business archives, from ‘ready to dispose of’ to ‘unreadable’:
- Inventorying. Someone decides which folders can go.
- Removing from the cabinet. Physical transport within the building.
- Brief intermediate storage. Boxes in a corridor, in an office, in a meeting room.
- Handing over to the supplier. At reception, on the loading dock, in the waiting area.
- Intermediate transport in the car or truck. Between your location and the shredder site.
- Waiting at the shredder site. Sometimes hours to days on the pallet.
- Processing in the shredder.
- Compaction to a bale and transport to the paper mill.
- Pulping at the paper mill. Only here is it truly unreadable.
That is nine links. On-site destruction eliminates four or five of those steps, because steps 4 through 7 happen together at the kerbside.
The ‘waiting time’ step is the most dangerous
Step 6 (waiting at the shredder site) is rarely discussed explicitly, but it is where most compromise occurs. A pallet with numbered boxes full of personal data sits at offsite destruction on average half a working day to several days before it is processed. Authorised staff walk by, cleaners, transport workers, sometimes other customers. With on-site destruction this step does not exist.
We work out the chain debate between on-site and offsite more extensively in on-site versus offsite shredding.
Who are all the hands?
- Own staff. Sometimes dozens, especially during large clear-outs where department managers sort through the archives themselves.
- Cleaners. Often overlooked in security overviews, but they do have access to meeting rooms where collected boxes are stored in the interim.
- Supplier transport workers. One or two people loading your archive into a truck.
- Personnel at the shredder site. Incoming sorting, weighing staff, shredder operators.
- Intermediate drivers. Truck drivers and any subcontractors on offsite routes.
- Paper-mill staff. Here the material is already bale-anonymous; no further risk.
With on-site destruction the entire chain can be limited to 2 people: your contact and our operator. Everything else happens in the truck.
Documentation: the evidence of the chain
Auditors do not want stories, they want traces. Watertight chain-of-custody evidence contains:
- Inventory list at pickup: number of boxes, weight or kilos, with handover signature.
- Timestamp of each link: when picked up, when processed.
- Operator identity for those who carried out the destruction.
- Method and DIN level.
- Destination of residue. Which paper mill or energy recipient received the material.
These elements belong on the destruction certificate. If in doubt, ask for an extended variant instead of a sticker; you pay nothing extra for the details.
What if something goes wrong in the chain?
A lost box en route, a truck where boxes burst open somewhere along the way, a pallet that ends up at the wrong location: these incidents happen. The question is: what then? Under the GDPR a data breach must be reported within 72 hours. Read our article on reporting a data breach within 72 hours for the step-by-step plan. The chain duration is relevant here: the longer the chain, the larger the window in which an incident can occur and the harder it is to reconstruct afterwards exactly what happened.
Recommendations for your internal procedure
- Document handover moments. Not pro forma; actual signatures with date.
- Keep internal transport within working hours. No boxes left on site after closing.
- Use locked consoles in the office, not open bins (more on that in a follow-up article on locked consoles).
- Request on-site destruction for sensitive clear-outs, so the chain stays short.
- Keep certificates for 5 years. In case of doubt or audit you can reconstruct every link.
Short chain = manageable risk.
Our on-site service minimises the number of hands in the chain: from archive cabinet to truck to bale in one visit, with a certificate on the spot.
Request a quoteWhat does your destruction chain currently look like? Email us via desnipperaar.nl. We will look for free at where the chain can be shorter.