Point of Sale Destruction

Data Destruction Inc. destroys retired point-of-sale terminals, PIN pads, and registers by sanitizing every component that stored cardholder data to NIST SP 800-88 r2 and PCI DSS Requirement 9.4.

A retired payment terminal is a compliance liability with a card reader attached. POS devices store cardholder data, encryption keys, and application data in flash and secure elements, and PCI DSS requires that media to be destroyed when it is retired. Deleting transactions or resetting the device does not satisfy that obligation.

Top 10 ways to protect privacy guide image dd - hard drive shredding | secure paper shredding | hdd wiping

TOP 10 WAYS TO PROTECT YOUR PRIVACY NOW!

DOWNLOAD YOUR FREE GUIDE

Related Destruction Services

Onsite-hard-drive-shredding-dark-blue

Computer Equipment Destruction

Computer equipment destruction sanitizes the back-office machines that run POS and payment software, extending cardholder-data protection beyond the terminal.

Data-destruction-services-dark-blue (2)

Network Equipment Destruction

Network equipment destruction sanitizes the routers and switches in the cardholder network, closing the infrastructure gap around a POS refresh.

Hard-drive-wiping-solutions-dark-blue

USB / Flash Drive Destruction

USB and flash drive destruction shreds the NAND media that POS terminals rely on, the same Destroy approach applied to embedded payment storage.

Witnessed-document-shredding-icon-dd (1)

Hard Drive Shredding

Hard drive shredding reduces POS register drives to particles below the 6 mm class, the core Destroy method for register storage.

What is point of sale destruction?

Point of sale destruction is the secure destruction of the data-bearing components inside payment terminals, PIN pads, card readers, and POS registers so cardholder data cannot be recovered. It applies both a NIST SP 800-88 r2 media sanitization outcome and the PCI DSS requirement to destroy media when it is no longer needed.

POS hardware stores data in embedded flash, secure elements, and sometimes internal drives on register systems. Because flash cannot be reliably overwritten and cannot be degaussed, physical destruction is the dependable outcome, with any conventional drives sanitized by their media type.

AttributeValue
Equipment classPOS terminals, PIN pads, card readers, registers
Data-bearing partsEmbedded flash, secure element, internal HDD or SSD
Flash and secure element destructionShred to small particle size
Register drive destructionShred, or shred or degauss for HDD
Data at riskCardholder data, encryption keys, transaction records
Governing frameworksPCI DSS Requirement 9.4 and NIST SP 800-88 r2

How does point of sale destruction work?

Point of sale destruction works by identifying every component that stored payment data, destroying each, and documenting the result for PCI evidence. Data Destruction Inc. follows a documented sequence.

  1. Inventory and scan terminals, capturing serials under documented chain of custody.
  2. Identify flash, secure elements, and any register drives.
  3. Shred flash and secure elements; shred or degauss register drives.
  4. Record serials, methods, particle sizes, and operator sign-off.
  5. Route residue to responsible downstream recovery, then issue the Certificate of Destruction.

Where POS registers use conventional drives, the drive-level methods are those on our Hard Drive Shredding page, applied inside a controlled workflow that produces PCI-ready evidence.

Why PCI DSS requires destruction, not deletion

PCI DSS requires destruction rather than deletion because deleted transactions and reset devices can still hold recoverable cardholder data. Understanding the requirement clarifies the control.

  • Requirement 9.4 calls for media containing cardholder data to be destroyed when it is no longer needed for business or legal reasons.
  • Flash retention means a reset or deletion can leave account data in reserve cells that a lab could recover.
  • Documentation is part of compliance, so a serialized certificate provides the evidence a QSA expects.

Because the storage is flash-class memory, it follows the same rule as USB / Flash Drive Destruction: physical destruction is the reliable path to a Destroy outcome for cardholder data.

How does point of sale destruction meet compliance obligations?

Point of sale destruction meets compliance obligations when every component that stored cardholder data is destroyed and the outcome is documented per device. The map below ties common rules to our process.

Standard or ruleRequirementData Destruction Inc. process
PCI DSS Requirement 9.4Destroy media with cardholder data when retiredDestroy POS flash, secure elements, and drives, serialized proof
NIST SP 800-88 r2Match method to media, verifyShred flash, shred or degauss drives, log serials
GLBA Safeguards Rule, 16 CFR Part 314Dispose of customer information securelySerialized destruction of payment hardware
FACTA Disposal Rule, 16 CFR Part 682Dispose of consumer report information properlyDestroy media holding consumer data with proof

PCI DSS is an industry standard rather than a federal regulation. For the government-published sanitization method, read our blank” rel=”noopener”>NIST SP 800-88 r2 guidelines and the FTC guidance on disposing of consumer report information.

Which industries need point of sale destruction?

Any business that accepts cards retires POS hardware, and three sectors carry concentrated exposure.

What you receive after point of sale destruction

Every engagement produces a PCI-ready documentation package.

  1. Serialized Certificate of Destruction, provided within 24 hours after the destruction event is complete.
  2. Chain-of-custody log from pickup through destruction.
  3. Asset inventory listing terminal serials and component types.
  4. Method record noting sanitization method and particle size.
  5. Downstream recovery record confirming responsible recycling.

See the blank” rel=”noopener”>Certificate of Destruction and blank” rel=”noopener”>Chain of Custody pages for details.

Frequently asked questions

Can't we just delete transactions from the terminal?

No. Deleting transactions or resetting a terminal can leave cardholder data in flash. PCI DSS Requirement 9.4 calls for the media to be destroyed, with documentation.

Does PCI DSS actually require destruction?

PCI DSS Requirement 9.4 requires media containing cardholder data to be destroyed when it is no longer needed. A serialized Certificate of Destruction provides the evidence for your assessment.

Do you destroy PIN pads and card readers too?

Yes. We destroy the flash and secure elements in PIN pads, card readers, and terminals, along with any drives in register systems.

Do you work on-site at store locations?

Yes. We offer on-site destruction with witnessed options and secure off-site service under chain of custody. Call (866) 850-7977.

What proof do we receive?

A serialized Certificate of Destruction, a chain-of-custody log, and an asset inventory with serials, ready for QSA review.

What happens to the hardware?

After the storage is destroyed, hardware is routed to responsible downstream recovery and recycling, recorded in your package.

Get Started

Retire payment hardware with PCI-ready proof. Schedule point of sale destruction at contact us or call (866) 850-7977.

LET US CONTACT YOU

DATA DESTRUCTION LOCATIONS

SHREDDING SERVICES DALLAS

1717 Mckinney Ave. Suite 700
Dallas, TX 75202-1236
(469) 949-2840

SHREDDING SERVICES NEW YORK CITY

100 Church Street. 8Th Floor
New York City, NY 10007-2630
(516)-990-4096

SHREDDING SERVICES SAN JOSE

2033 Gateway Place. 5Th Floor
San Jose, CA 95110
(408) 459-4418

SHREDDING SERVICES SAN DIEGO

350 10Th Avenue. Suite 1000
San Diego, CA 92101-7496
(619) 916-4696

SHREDDING SERVICES LOS ANGELES

633 West Fifth Street. 26Th And 28Th Floors
Los Angeles, CA 90071
(213) 205-3688

SHREDDING SERVICES IRVINE

7545 Irvine Center Drive. Irvine Business Center, Suite 200
Irvine, CA 92618
(949) 793-7178

SHREDDING SERVICES WASHINGTON

601 Pennsylvania Ave. Nw, South Building, Suite 900
Washington, DC 20004
(240) 266-3056

LEARN MORE ABOUT OUR SERVICES
Latest Blog posts

Posts not found

SEARCH LOCATION WITH ZIP CODE

download your free guide!

The Top 10 Ways to Protect Your Privacy Right Now!

Learn the secrets of our 50 destruction professionals as they delve into the top ways to protect your privacy. Whether your company is big or small, get FREE insider tips to protect your data.