Skip to main content

This is a new website. Help us improve it and give your feedback.

FOI 0090 - Software erasure and IT equipment

Requested: 26 January 2026

Responded: 18 February 2026

Published: 8 June 2026

This is IBCA's response to a Freedom of Information (FOI) request.

Thank you for your email received on 26 January 2026 in which you made a request for access to certain information which may be held by the Infected Blood Compensation Authority.

The purpose of the Freedom of Information Act 2000 (“the Act”) is to allow a general right of access to information held at the time of a request, by a Public Authority (including the Infected Blood Compensation Authority), subject to certain limitations and exemptions.

We have now had the opportunity to fully consider your request and we provide a response for your attention.

Following receipt of your request, searches were conducted by the HR and Operations Directorates of the Infected Blood Compensation Authority.

You asked the following

Under the Freedom of Information Act 2000, please provide the following recorded information held by your department regarding assurance processes for software based data erasure of end of life IT equipment.

For clarity, this request relates solely to software-based data destruction.

Please exclude physical destruction methods such as shredding, crushing, degaussing or disintegration.

  1. Please confirm whether departmental policy, contractual terms or internal procedures require an explicit outcome based warranty or guarantee confirming that personal data has been rendered irretrievable through software based erasure, whether carried out internally or by an external provider.
  2. Where software based data destruction is performed internally, what recorded evidential assurance does the department rely upon to conclude that the final data state is irretrievable?
  3. Where software based data destruction is performed by a third party provider, does the department hold recorded information demonstrating that any warranty or assurance provided explicitly extends to the software erasure method used and its claimed effectiveness? If so, please confirm the recorded nature of that verification.
  4. Where no explicit outcome based warranty is required or provided, what recorded form of evidential assurance does the department rely upon to conclude that software based erasure has rendered personal data irretrievable?

I am not requesting technical configuration detail, security sensitive information or supplier specific vulnerabilities. I am seeking confirmation of the assurance model relied upon for software based data destruction.

Our response

We have now had the opportunity to fully consider your request and we provide a response for your attention.

We can confirm that the information you have requested is not held by the Infected Blood Compensation Authority.

You may wish to contact the Cabinet Office who own IBCAs IT, they may be able to provide you with the information you requested by sending an email to foiteam@cabinetoffice.gov.uk.

Help us improve the IBCA website

Tell us how we can improve this page.