Data destruction for banks, credit unions, insurers, and lenders
Account records, loan files, and card data retire on branch PCs, ATMs, and core servers. GLBA, the FTC Safeguards Rule, FACTA, and PCI DSS all require the data to be unrecoverable before the hardware leaves your control. Our founder spent part of his career inside banking technology; we know where the drives are.
What the rules require
- GLBA and the FTC Safeguards RuleFinancial institutions must protect customer information through disposal, with a written program and a designated qualified individual accountable for it.
- FACTA Disposal RuleConsumer report information must be disposed of by measures that make it unrecoverable. Physical destruction with a certificate is the measure examiners recognize.
- PCI DSS 4.0 Requirement 9.4Media with cardholder data is destroyed when no longer needed, and electronic media is rendered unrecoverable.
- SOX and examiner expectationsRegulators ask for the record. The certificate and media log are written to be that record.
How we handle it
Branch consolidations and core conversions generate identical devices by the hundred; we inventory by serial against your fixed-asset list and destroy on-site so nothing leaves a branch with data on it.
ATMs, teller cash recyclers, and check scanners carry drives and flash that most vendors miss. We open them, remove the storage, destroy it, and log the machine as inspected.
The certificate and log give your examiner method, machine, date, serial, and witness for every item, with a three-year audit right on the letter.
“Fantastic experience with Mansfield Technologies. Their attention to detail and quality of work are top-tier. They delivered exactly what was promised with excellent communication throughout the process. Will definitely be using them again.”
Vendor due diligence, done once
- Your third-party risk program under the 2023 interagency guidance wants the same packet from every vendor. Ours is assembled: capability statement, certificate of insurance with cyber and privacy coverage, W-9, sample Certificate of Destruction, security summary, equal opportunity statement, and a named contact for questionnaires.
- The examiner-facing documents are on the due diligence kit; the ones with your organization's name on them come by email before the job.
Where we do it
Cleveland, Columbus, Pittsburgh, Cincinnati, Detroit, Louisville, Buffalo, Erie, and everywhere else we go.
Read next
Questions from financial services
Can you destroy ATM and cash-recycler storage?
Yes. We remove the drives and flash from the machine at your branch, destroy them, and record the ATM by serial as inspected.
Do you provide documentation for GLBA and FFIEC exams?
The certificate and media log are written for that purpose and have been accepted in examinations. Keep them with your information security program.
Can branch staff witness?
Yes, and the branch manager's name goes on the log as the customer approval.
Do you resell our equipment?
Never whole. Storage is destroyed and only parts with no data path are resold, and only if your agreement allows it.
Can you complete our vendor questionnaire?
Yes. Send it and we return it with the supporting documents from the due diligence kit, usually within a week.
