How to Read a Certificate of Destruction: What New York Businesses Should Know

certificate of destruction shredding document New York businesses

Every time New York Shredding completes a document destruction job, we provide our clients with a Certificate of Destruction. For many businesses, this document is filed away without much thought — but the Certificate of Destruction is one of the most important compliance documents your organization can hold. If your business ever faces a HIPAA audit, a New York SHIELD Act investigation, a PCI DSS examination, or a lawsuit involving the handling of sensitive records, your Certificate of Destruction is your proof that records were destroyed in compliance with applicable law and your internal policy. Understanding what the certificate contains — and how to use it — is essential for any New York business that takes data security seriously.

This guide explains what a Certificate of Destruction for shredding in New York includes, how to interpret it, where to store it, and how to present it during a compliance audit. Whether you’re a compliance officer at a Manhattan healthcare system, an HR director at a Long Island staffing firm, or the office manager at a Westchester law firm, this guide will help you get maximum value from your shredding documentation.

What Is a Certificate of Destruction?

A Certificate of Destruction (COD) is a formal document issued by a certified shredding company — typically after every service event — that certifies the destruction of specific materials on a specific date. It is the shredding industry’s equivalent of a receipt: documentation that a transaction (destruction) occurred under certified, chain-of-custody conditions.

The Certificate of Destruction serves multiple purposes simultaneously:

  • Compliance documentation: It satisfies the record-keeping requirements of HIPAA, PCI DSS, GLBA, the NY SHIELD Act, and other regulations that require businesses to document how and when sensitive materials were destroyed
  • Audit trail: In the event of a regulatory audit or investigation, the COD demonstrates that your organization took appropriate, documented steps to protect information through its final disposal
  • Litigation defense: If your business faces a lawsuit alleging improper handling of personal information, CODs demonstrate due diligence — helping establish that any breach was not due to negligent disposal
  • Third-party accountability: The COD creates a documented record of your shredding vendor’s performance and services — holding them accountable and protecting you if a dispute arises

Learn more about our compliance documentation services.

What Information Does a Certificate of Destruction Contain?

A properly issued Certificate of Destruction from a NAID AAA certified shredding company should contain the following information:

  1. Issuing company information: The name, address, and NAID certification number of the shredding company
  2. Client information: The name and address of the business whose materials were destroyed
  3. Service date: The exact date on which destruction occurred — essential for correlating with your document retention records
  4. Service type: The type of service performed (on-site shredding, off-site shredding, hard drive destruction, electronic media destruction)
  5. Description of materials: A description of what was destroyed — typically specified as weight (pounds or tons of paper), number of bins emptied, or specific serial numbers for hard drives
  6. Destruction method: The method used (cross-cut shredding, micro-cut shredding, physical hard drive destruction)
  7. Security level: The DIN 66399 security level achieved, or an equivalent designation
  8. Authorized signature: A signature from an authorized representative of the shredding company certifying the accuracy of the information
  9. Unique job/certificate number: A reference number that can be used to trace the specific job in the shredding company’s records

Our shredding services always include a compliant Certificate of Destruction meeting all these specifications.

How to Use Your Certificate of Destruction During a Compliance Audit

When your business faces a compliance audit — whether HIPAA, SHIELD Act, PCI, or otherwise — auditors will typically ask for documentation of your information disposal practices. Here’s how to present your Certificates of Destruction effectively:

  • Organize by date: Maintain a chronological file of all CODs, making it easy to demonstrate continuous compliance over any audit period
  • Cross-reference with your retention schedule: Be prepared to show that destruction dates on the CODs align with your documented retention schedule — demonstrating that materials were destroyed at the appropriate time
  • Match to document categories: If the audit involves specific document types (e.g., PHI for HIPAA), show how your shredding schedule addresses those categories
  • Present the vendor’s NAID certification: Supplement your CODs with documentation of your shredding vendor’s NAID AAA certification number, which auditors can verify through the NAID member directory
  • Produce your Business Associate Agreement (for HIPAA): Along with the COD, present the BAA signed between your organization and the shredding company

How Long Should You Keep Certificates of Destruction?

The retention period for Certificates of Destruction should match the applicable statute of limitations for the regulatory framework they support:

  • HIPAA: Six years from the date of the certificate (matching HIPAA’s documentation retention requirement)
  • NY SHIELD Act: Retain for the applicable statute of limitations for privacy violations in New York — typically three to six years
  • PCI DSS: At least one year (matching PCI’s audit log retention standard)
  • General practice: Many compliance professionals recommend retaining CODs for seven years as a conservative standard aligned with federal record-keeping periods

Store CODs both in physical form (in your compliance files) and digitally (scanned copies in a secure document management system). Contact New York Shredding to discuss service options, or check our how it works page for details on our COD issuance process.

Why New York Businesses Choose New York Shredding

For over a decade, New York Shredding Document Destruction, Inc. has helped businesses across New York City, Long Island, Westchester, and the Hudson Valley protect their sensitive information through certified, HIPAA-compliant shredding services. Our industrial-grade shredding equipment, locked on-site consoles, and Certificate of Destruction give your business the proof it needs for any compliance audit.

Whether you need scheduled shredding, a one-time purge, or hard drive destruction, we serve all five boroughs and surrounding areas with fast, reliable service. Request a free quote today and ensure every destruction event is backed by proper documentation.

Ready to get started? Contact New York Shredding for a free quote, or explore our full range of shredding services.

Scroll to Top