Five Days to Beijing: Destroying a China Office's Drives Without Shipping Them Out
A composite scenario: a foreign-invested group's China engineering centre retires ninety workstations and eleven servers, and its group process says ship the drives to Hong Kong. Why that one routing decision creates three separate problems, and why the destruction capability can travel instead.
Published
Short answer: Retired drives held in a mainland China office do not have to leave the country to be destroyed to a certified standard. Brocent's degaussing equipment is based in Beijing and ships to the job in three to five business days within China — five to ten if it has to reach Hong Kong. The hardware stays put; the destruction capability travels.
A composite scenario, built from the shape of problem Brocent sees regularly in mainland China rather than from any one named client: a foreign-invested automotive-components group runs an engineering and test centre of about eighty people in the Yangtze River Delta. A three-year refresh cycle comes due — roughly ninety workstations, eleven rack servers, a handful of NAS units and two decommissioned test-bench controllers. The workstations hold CAD models and validation data for parts that are still in production at three customers. The group has a standard process for this, written by corporate IT, and it says: collect retired assets, ship them to the regional disposal partner, receive certificates.
The regional disposal partner is in Hong Kong. The local IT manager reads the process twice, and the thing that stops him is not a compliance clause. It is arithmetic. He is being asked to put ninety drives containing live customer engineering data into a shipment, move them across a border, and have them out of his custody for an unknown number of days while somebody else's paperwork catches up.
Why does a China office's hardware refresh stall at the disposal step?
Because group disposal processes are almost always written for wherever the group's disposal vendor happens to be, and then applied to every site as though geography were a detail. For most sites it nearly is. For a mainland China site it is not, and the reason is that the step "ship the assets to the processing facility" quietly changes character when the shipment crosses a customs border carrying storage media that still holds data.
Three separate problems get bundled into that one line of process, and because they arrive together they are usually mistaken for one problem that someone else is handling.
The data is still on the drives while they are in transit. This is the part that should stop a security-minded reader first. In the ship-it-out model, destruction happens at the destination. Everything before that — collection, packing, the truck, the border, the receiving warehouse — is a period during which drives holding customer engineering data are outside the company's premises and not yet destroyed. The documentation covering that window is the only thing standing between "properly disposed" and "we shipped ninety drives of customer data somewhere and hoped."
The schedule is not yours. Customs timing for a cross-border shipment of used IT equipment is not something the local IT manager controls or can forecast reliably, and whether a particular batch of retired hardware can be exported at all — and under what declaration — is a question for the company's customs broker rather than for its IT department. A refresh that has a floor-space deadline attached to it does not cope well with an open-ended step in the middle.
The cross-border question is a legal one that nobody asked. Moving storage media that holds personal or customer data out of mainland China raises questions under China's data-protection regime that are genuinely for the company's own counsel to answer, not for a disposal vendor and not for this article. We will come back to this honestly below, because the useful point is not a legal opinion — it is that the in-country option makes the question moot for this batch of hardware rather than requiring it to be answered under time pressure.
Notice what all three have in common: they are created by the routing decision, not by the destruction requirement. Nothing about destroying a drive to a certified standard requires the drive to move to another jurisdiction. That is an artifact of where the vendor is.
The scenario: ninety workstations, eleven servers, and a process written for somewhere else
What the local team actually faced, set out plainly:
- A mixed fleet. Roughly ninety workstations, most with spinning disks but about a third already on SSD or NVMe; eleven rack servers with a mix of SAS drives; two NAS units; two embedded test-bench controllers nobody could positively identify the storage type of without opening them.
- Live customer data. The CAD and validation data belonged, contractually, to three customers whose own audit requirements were the real reason this could not be casual.
- A deadline with a floor plan attached. The new fleet was arriving on a known date. The old fleet had to be out of the building, because the building did not have room for both.
- No current inventory. The asset register had not been reconciled in two years. Nobody could state with confidence how many drives there were, which is a different and worse problem than having too many.
- A group process that assumed a Hong Kong destination. Including certificate formats and a reporting template built around that vendor's output.
- No local chain-of-custody documentation at all. There was a courier booking process. There was not a sealed-bin, tagged, logged, photographed handover process, and the difference between those two things is the whole of what an auditor will ask about.
The fact that changes the answer: the degausser is in Beijing, and it travels
Here is the operational detail that reframes the problem, and it is worth stating precisely because the precise version is more useful than the approximate one.
Brocent's IT Asset Disposal service lists six destruction methods, each with its real availability and lead time published rather than implied. One of them is degaussing — a certified degauss device that exposes a hard disk to a powerful magnetic field, permanently destroying the magnetic domains that hold the data. It is irreversible and verifiable. And its availability line reads: available, Beijing, China. Its lead time reads: three to five days' shipment.
The published lead-time table is more specific still. Shipping the degauss device costs three to five days within China, and five to ten days if it has to reach Hong Kong. Read that the right way round and it is the argument: the capability is a physical tool that lives in mainland China and moves to where the hardware is. For a site in the Yangtze River Delta, the destruction equipment is three to five days away, domestically, with no border in the path. For the Hong Kong office of the same group, the same tool is five to ten days away — which is the cost of the border, paid by the tool rather than by ninety drives of customer data.
This inverts the routing decision. The group process moved the data to the capability. The in-country option moves the capability to the data. Every one of the three problems above is produced by the first arrangement and absent from the second: the drives never leave the premises or the country, the schedule becomes a known three-to-five-day lead time rather than an open-ended customs question, and the cross-border data question does not arise for this batch because nothing crosses a border.
It is also, bluntly, the kind of fact that is hard to claim and easy to check. Plenty of providers will tell you they can handle China disposal. The useful question is where the equipment physically is and how many days it takes to arrive, and that is published.
What degaussing covers, and what it does not
A caution that matters for a mixed fleet, because getting this wrong is the most common way an in-country plan slips.
Degaussing works by destroying magnetic domains. That makes it appropriate for hard disk drives and inappropriate for flash storage, which does not store data magnetically. About a third of the composite company's workstations were already on SSD or NVMe, and those drives need a different route: certified software erasure to a standard such as NIST 800-88 Purge or a cryptographic erase, physical destruction by mechanical bending, or industrial shredding.
The published availability lines matter here too, and they are the reason scoping has to happen early rather than at collection time. Blancco certified software erasure runs on a per-project licence with two to three days' order processing. Mechanical bending of flash media is a special order from the USA with a one-to-two-week lead time. Industrial shredding runs via a certified third party, also one to two weeks. HDD physical drilling — an electric drill applied three times to the platter — is available with two days' preparation and can be done on site when the requirement is that data never leaves the premises at all.
The practical consequence: on a mixed fleet, the degausser is not the long-lead item. The flash-media path is. A plan that books the degausser and discovers the SSD route afterwards has bought itself a two-week surprise against a deadline that has a floor plan attached to it. This is why the scoping checklist asks which HDD and SSD disposal method is required as an explicit question rather than inferring it — and why the honest sequence is to inventory the media types first and choose methods second.
Comparison: three ways to retire a China office's drives
Ship the retired hardware out of mainland China
- What is appealing: It matches a process the group already has, with a vendor corporate IT already trusts and certificate formats the reporting template already expects. No new approvals.
- What it actually costs: A transit window during which undestroyed drives holding customer data are outside your premises and outside your country. A schedule you do not control. And a cross-border data question that has to be answered, under deadline, by people who were not expecting to answer it.
- What it is good at: Consolidating small volumes from several markets into one processing run, where the data sensitivity genuinely is low.
- Where it breaks: Exactly here — meaningful volume, live customer data, a fixed deadline.
Use a generic local recycler
- What is appealing: Fast, cheap, local, and someone will collect this week. For pure e-waste with no data on it, this is a perfectly sensible answer.
- What it actually costs: Usually no per-device destruction evidence. A collection receipt for a pallet is not a record that drive number such-and-such was destroyed by a named method on a named date, and a pallet receipt is what an ISO 27001 auditor or a cyber-insurance questionnaire will decline to accept.
- What it is good at: Monitors, chairs, cabling, chassis without storage — the genuinely data-free majority of a refresh by volume.
- Where it breaks: Anything with a serial number and a storage device in it.
Certified in-country destruction, with the degausser brought to the site
- What is appealing: The hardware does not leave China. The lead time is published and domestic. The evidence is per-device rather than per-pallet.
- What it actually costs: It needs real scoping, several weeks before the refresh date, including a media-type inventory, a decision on method per media type, and the long-lead flash path booked early. It is a project with a plan, not a phone call.
- What you get: A documented chain of custody from collection; an individual destruction certificate per device carrying serial number, destruction method and date; photo and video evidence of physical destruction; a final Certificate of Disposal listing every asset with its method, date and certificate reference; and certified e-waste recycling afterwards with zero landfill and ESG certificates.
- Where it is the right answer: A mainland China site with real data sensitivity, real volume, and a date it has to be finished by. Which is the common case, not the exotic one.
What an in-country destruction run actually looks like
The disposal process runs in ten stages, and it is worth reading in order because the order is the part that most disposal quotes leave out.
- Onsite asset inventory. Engineers arrive and tag, photograph and log every device against the asset register before anything moves. For the composite company, this was the stage that mattered most, because the register was two years stale — the inventory *is* the deliverable at this point, not a formality before the real work.
- Un-rack and pack. Devices are de-racked or collected from desks, packed with bubble film against physical damage, and placed in secure sealed bins with padlocks.
- Secured transport. A dedicated van or cargo vehicle moves the sealed bins to the processing facility, with chain-of-custody documentation maintained throughout transit.
- Offsite warehouse intake. Assets are received and stock-checked. Blancco licences and USB boot tools are prepared and assigned per batch.
- Lab setup and data wipe. A local processing lab with network access is set up, and certified erasure runs device by device. Each wipe generates a tamper-proof erasure report carrying serial number, method and timestamp.
- Photo and video evidence. Photographs and short videos are taken of each device during and after destruction — particularly for drives that are physically destroyed alongside or after wiping.
- Network device reset. Routers, switches and firewalls get a professional factory reset over a console cable, clearing configuration, VLAN tables and stored credentials. This is the step people forget; a decommissioned firewall with its configuration intact is a map of your network.
- Report review and QA. The erasure report is reviewed against the inventory to confirm nothing is missing or failed. Gaps are escalated and resolved before the batch is cleared, which is the only point in the process where "we are not sure about drive 57" is cheap to fix.
- Pack for shipment or disposal. Processed devices are re-packed to shipping standards and routed either to the certified e-waste recycler or to the client's designated address.
- Certificate of Disposal issued. The final report lists every asset with serial number, asset tag, device type, destruction method, destruction date and individual certificate reference.
For an in-country run, stages three and four stay inside mainland China, and the degauss device is what arrives rather than what the drives depart towards. Where the requirement is that data never leaves the premises at all, on-site physical destruction by drilling moves the destruction step into stage two, at the cost of a slower per-device rate.
What you get at the end, and what it is actually good for
The output of a certified disposal run is evidence, and evidence is only useful if it answers the question someone will actually ask you.
The per-device destruction certificate — serial number, method, date — answers "prove this specific drive was destroyed." The comprehensive Certificate of Disposal, listing every asset with its certificate reference, answers "prove you know how many there were and that none went missing," which is the harder question and the one a stale asset register makes unanswerable. Together they are what an ISO 27001 audit, a cyber-insurance questionnaire and a customer's own supplier audit are looking for. The service supports 27 or more erasure standards, including NIST 800-88 Clear and Purge, DoD 5220.22-M and its ECE variant, TCG cryptographic erasure and the HMG Infosec Standard 5 levels, so the standard can be the one your customer's contract names rather than the one the vendor prefers.
There is also a commercial side worth raising with finance before the hardware is destroyed rather than after. Assets that retain market value can be remarketed or traded in, offsetting disposal cost and reducing environmental impact through reuse rather than recycling. A three-year-old workstation fleet is usually past the interesting part of that curve, but eleven relatively recent servers may not be — and the decision has to be taken before the drives are destroyed, not after, which means it belongs in scoping.
On cost, we will not invent a figure. The page publishes the eleven factors that drive the scope instead — device quantity, dimensions and weight, site location, destination location, data-centre conditions, work schedule including overtime and non-business hours, disposal methods and tooling, inventory and audit requirements, packing materials, and warehouse storage — and the reason that list exists is that two disposal quotes for the same fleet can differ substantially and both be honest, because they are scoping different work. A quote that arrives without having asked about most of those eleven things is not cheaper; it is less specified.
The question this does not answer
One thing needs saying carefully. Whether moving storage media that holds personal information out of mainland China is permitted in a given case, under what conditions, and with what internal approvals, is a legal question under China's data-protection framework. It depends on what the data is, whose it is, and the company's own position — and it is a question for your counsel and your compliance function. Nothing here is legal advice, and nothing in this article asserts a threshold, an approval requirement or a compliance verdict for any specific configuration. Our MLPS and PIPL compliance checklist for foreign companies in China sets out the shape of the wider framework, and it is a starting point for a conversation with counsel rather than a substitute for one.
What we can say is operational, and it is the honest reason to raise the topic at all: the in-country route means this particular question does not have to be answered against a refresh deadline, because nothing crosses a border. That is a scheduling and risk-surface argument, not a legal one. If the group's policy requires the cross-border route anyway, that is a legitimate decision — it just needs to be a decision someone took with the transit window in view, rather than a default inherited from where a vendor happens to be.
Where hardware lifecycle actually belongs
The composite company solved its immediate problem. Ninety workstations, eleven servers and the awkward test-bench controllers were inventoried, destroyed in-country by the method appropriate to each medium, and certificated per device. The new fleet arrived on schedule and the floor space was clear.
But the reason the problem was stressful had nothing to do with disposal being hard. It was that the asset register was two years stale, that nobody had checked whether a process written around a Hong Kong vendor made sense for a mainland site, and that the question only got asked because a refresh forced it. Those are not disposal failures. They are the absence of anyone whose ongoing job is hardware lifecycle — knowing what you own, when it retires, and what happens to it when it does.
That is what a managed IT plan is supposed to cover. The per-user plans include a named vCIO and technical roadmap alongside 24/7 NOC monitoring, help desk, patch management, managed firewall, backup and DR and SLA guarantees, and mainland China pricing is published per user per month next to Hong Kong, Singapore and the US. Asset disposal sits inside that as one of the things the plan handles when it comes due — and when a refresh arrives, the inventory already exists, the method matrix is already known, and the long-lead items are already booked. The argument is not that you should buy disposal from us as a product. It is that a refresh should not be the event that discovers your asset register is wrong.
If a decommission is happening alongside a move rather than a straight refresh, IT relocation and disposal are usually one project rather than two, and scoping them together avoids moving hardware that was always going to be destroyed. The pricing page has the plan figures, and you can get in touch if you want a China site looked at specifically — Brocent has operated in mainland China since the business was founded in Beijing in 2007, with operations centres in Shanghai, Beijing and Guangzhou.
Frequently asked questions
Does hardware have to leave mainland China to be securely destroyed?
No. Certified destruction can be performed in-country, and for data-bearing media that is usually the better route. Brocent's degauss device is based in Beijing and ships to site within China in three to five business days; software erasure, on-site physical drilling and certified third-party shredding are also available domestically. The hardware staying in China removes the transit window, the customs uncertainty and the cross-border data question in one decision.
How fast is the Beijing turnaround compared with shipping hardware abroad?
The published lead time for shipping the degauss device is three to five business days within China, and five to ten days if it has to reach Hong Kong. Those are firm, domestic logistics figures. A cross-border shipment of retired hardware is not comparable in kind, because the variable is customs rather than distance — which is exactly why it is hard to plan around when a refresh has a fixed date.
What does the destruction certificate include?
Each device gets an individual destruction certificate carrying its serial number, the destruction method applied and the date. At the end of the batch, a comprehensive Certificate of Disposal lists every asset with serial number, asset tag, device type, method, destruction date and individual certificate reference. Photo and video evidence is captured during physical destruction. The combination is what ISO 27001 audits, cyber-insurance questionnaires and customer supplier audits generally ask for.
Does this cover locations outside Beijing?
Yes — Beijing is where the degauss equipment is based, not the only place it can be used. The device ships to site, which is what the three-to-five-day domestic lead time covers. Collection from multiple offices can be coordinated as a single project, which matters for a group retiring hardware across several China sites in one refresh cycle.
Is degaussing the same as physical shredding?
No, and the difference matters when choosing a method. Degaussing destroys the magnetic domains on a hard disk with a powerful magnetic field — irreversible and verifiable, and appropriate for magnetic media. Shredding physically reduces media to fine particles and is the highest level of physical destruction, suitable for government and financial-institution requirements; it runs through a certified third party on a one-to-two-week lead time. Flash media cannot be degaussed at all and needs certified software erasure, mechanical bending or shredding instead.
Can this be combined with a hardware refresh or procurement project?
Yes, and it generally should be, because the two have the same deadline and the same inventory. Scoping them together means the old fleet's collection is planned against the new fleet's arrival date, residual-value recovery is assessed before anything is destroyed, and a decommission that coincides with an office move is handled as one project rather than two overlapping ones.
What happens to the hardware after destruction — is it recycled?
Yes. After data destruction, hardware is processed through certified e-waste recyclers with zero landfill disposal, in line with local environmental regulations in Hong Kong, mainland China, Japan and Singapore, and ESG recycling certificates are provided. Where assets still hold market value and the company wants to pursue it, remarketing or trade-in can be arranged instead — but that decision has to be made before destruction, which is why it belongs in the scoping conversation.
Share:
Ready to take action?
Turn these insights into a roadmap for your business.
Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.
Free Checklist
10 Critical Checks Before Expanding IT to Greater China
PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.
Request the checklist →📬 Monthly Asia IT Insights
China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.
No spam. Unsubscribe anytime.