Our Recycling Impact Since 2016

Click to see our real-time impact

Compliance Guide

BS EN 15713 Explained: What This Secure Destruction Standard Really Means for Your Business

Cross Cut Shredding
26 February 2026
10 min read

When researching professional document shredding services, you'll inevitably encounter BS EN 15713 certification. But what does this standard actually mean, and why should it matter when choosing a provider?

The answer has serious implications for your organisation. Under UK GDPR, you remain fully responsible for protecting personal data even after handing documents to a destruction provider. If they lose, mishandle, or inadequately destroy your confidential material, the Information Commissioner's Office (ICO) holds your organisation accountable—not the provider. Financial penalties for undertakings can reach the higher of £17.5 million or 4% of global annual turnover.

This guide provides BS EN 15713 explained in practical terms, helping you understand why this certification matters, what it actually requires from providers, and how to verify genuine compliance when selecting a shredding service.

What Is BS EN 15713? The Basics Explained

BS EN 15713 is the definitive British and European standard (British Standard / European Norm) for secure destruction services. Published in its current form in September 2023, it establishes comprehensive requirements for how organisations must collect, transport, store, destroy, and recycle confidential material.

The standard covers every type of confidential material requiring secure disposal: paper documents, hard drives, USB devices, optical media (CDs and DVDs), backup tapes, microfilm, and any other data-bearing items.

Crucially, BS EN 15713 isn't simply about the shredding equipment. It addresses the entire operational infrastructure—management systems, security protocols, personnel vetting, chain of custody documentation, and quality assurance frameworks.

Most importantly, BS EN 15713 requires independent certification through accredited certification bodies. Providers must maintain certification through regular surveillance audits. This third-party verification distinguishes genuine certified providers from competitors making unsubstantiated security claims.

When evaluating providers, always verify current BS EN 15713:2023 certification—the latest version with enhanced GDPR alignment and strengthened electronic media requirements.

Why BS EN 15713 Matters for GDPR Compliance

UK GDPR Article 5(1)(f) requires you to process personal data "in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage."

This security principle applies throughout the entire data lifecycle—including secure destruction.

When you transfer documents containing personal data to a shredding provider, you remain the data controller under GDPR. Legal responsibility stays with your organisation until irreversible destruction occurs. If your provider suffers a security breach—documents lost during transit, unauthorised access at their facility, inadequate destruction allowing reconstruction, or theft from insecure storage—the ICO investigates your organisation for failing to implement appropriate safeguards.

BS EN 15713 certification demonstrates you've conducted proper due diligence by selecting a provider with independently verified security controls. It provides documented evidence of "appropriate technical or organisational measures"—your primary defence if the ICO questions your supplier selection.

The ICO has consistently increased enforcement action for data protection failures. Organisations can no longer treat document destruction as an administrative afterthought. Selecting a BS EN 15713 certified provider isn't optional—it's essential risk management protecting your organisation from regulatory penalties and reputational damage.

For comprehensive guidance on your legal obligations, see our detailed guide on GDPR document destruction requirements.

What the 2023 Update Changed

The BS EN 15713:2023 revision introduced significant enhancements reflecting modern data protection requirements:

Explicit GDPR Integration: The revised standard directly references UK and European data protection legislation, clarifying that destruction services must actively enable client compliance with GDPR principles.

Strengthened Electronic Media Requirements: Enhanced specifications now cover degaussing equipment standards, physical destruction verification procedures, detailed certificates of destruction for electronic devices, and specific handling requirements for SSDs and encrypted storage. If you require hard drive destruction, verify your provider meets these 2023 requirements.

Enhanced Chain of Custody Standards: Updated traceability requirements mandate GPS tracking on all collection vehicles, real-time tracking options for high-security collections, more detailed consignment documentation, and stricter protocols for material awaiting destruction.

Environmental Management Integration: Certified providers must now demonstrate waste hierarchy compliance, maintain verified recycling credentials with documented downstream processes, and evidence sustainable practices including carbon reduction initiatives.

Stricter Ongoing Certification Requirements: Enhanced surveillance audit protocols prevent compliance lapses between certification periods, ensuring continuous adherence rather than point-in-time compliance.

Core Requirements: What Certification Actually Demands

To understand BS EN 15713 explained properly, you need to know what certification actually requires in practice.

Complete Chain of Custody Protection

Certified providers must implement documented security procedures covering every stage:

  • Tamper-evident containers with secure locking mechanisms and unique identification
  • Sealed consignment bags or bins with clear visual indicators if accessed during transit
  • GPS tracking systems on all collection vehicles with documented routes and timings
  • Complete chain of custody documentation recording every transfer point and handler
  • Secure storage facilities meeting defined physical security standards (access control, CCTV, intrusion detection)
  • Certificates of destruction issued after every collection with full traceability

These measures ensure your confidential documents cannot be accessed, lost, diverted, or compromised between collection at your premises and final destruction.

Rigorous Personnel Vetting

The human element represents the greatest security vulnerability. BS EN 15713 requires:

  • Criminal record checks (DBS checks) and employment history verification for all personnel
  • Documented security awareness training with regular refresher sessions
  • Signed confidentiality agreements from every employee and subcontractor
  • Strictly controlled visitor access with mandatory escort requirements
  • Regular compliance audits and unannounced spot checks
  • Clear disciplinary procedures for security breaches

Your documents are only as secure as the people handling them. These vetting requirements eliminate insider threats whilst ensuring personnel understand their data protection responsibilities.

Destruction Methods and DIN 66399 Security Levels

BS EN 15713 works alongside DIN 66399, the international standard defining destruction security levels. For paper documents, levels range from P-1 (basic strip-cut) through P-7 (maximum security):

  • P-3 (cross-cut): Suitable for internal business documents with moderate confidentiality
  • P-4 (cross-cut): Commonly used for documents containing personal data, providing smaller particle sizes than P-3
  • P-5 (cross-cut): For highly sensitive data including special category personal data
  • P-6 and P-7 (micro-cut): Reserved for classified material requiring maximum security

Many UK businesses handling customer or employee personal data operate at P-4 security level as the appropriate balance between effective protection and operational practicality. Cross Cut Shredding operates at P-4 security level as standard across all on-site and off-site shredding services.

Comprehensive Management Systems

Certification requires extensive documented management systems including:

  • Detailed risk assessments covering all destruction process aspects
  • Formal incident reporting and investigation procedures
  • Internal audit programmes with corrective action tracking
  • Regular management review meetings
  • Destruction certificate retention enabling full audit trails
  • Documented standard operating procedures for every operational aspect
  • Business continuity plans ensuring service continuity during disruptions

This documentation framework creates comprehensive evidence that your organisation has fulfilled its duty of care obligations under data protection legislation.

How to Verify Provider Certification

When evaluating potential shredding providers, apply these verification procedures:

Request Current Certification Documentation: Ask to see the actual BS EN 15713:2023 certificate and verify it's within its validity period. Check the issuing certification body holds proper accreditation. Verify the certificate scope covers the specific services you require.

Confirm Destruction Security Level: Verify the provider operates at an appropriate DIN 66399 security level for your requirements. P-4 provides robust cross-cut shredding suitable for most organisations handling documents containing personal data.

Review Certificate of Destruction Procedures: Establish they issue detailed certificates after every collection as standard practice, not just on request. Certificates should detail collection date, material description, destruction method, security level achieved, and recycling credentials.

Check Insurance Coverage: Confirm the provider maintains appropriate professional indemnity insurance and specific data breach insurance. Request evidence of current insurance certificates with adequate coverage limits—minimum £2 million recommended.

Assess Operational Transparency: Reputable providers welcome detailed questions about their certification, procedures, and security measures. Check independent customer reviews and verify transparent pricing without hidden charges.

Request Site Visit or Virtual Tour: For ongoing large-volume contracts, request a site visit to verify claimed facilities match certification requirements. Many providers now offer virtual facility tours demonstrating their security infrastructure.

Common Misconceptions About BS EN 15713

"All shredding companies are certified": False. Many providers operate without BS EN 15713 certification, relying instead on trade association membership or vague "industry best practices" lacking independent verification.

"Certification is just paperwork": False. Achieving and maintaining BS EN 15713 certification requires substantial investment in security infrastructure, staff vetting, tracking systems, and regular independent audits verifying actual compliance.

"On-site shredding doesn't need certification": False. Even with witnessed destruction, the shredded material must be securely handled, transported, and sent to verified recycling facilities. For a full comparison, see our guide on on-site vs off-site shredding.

"Small businesses don't need certified providers": False. UK GDPR applies to organisations of all sizes handling personal data. Small businesses face identical data protection obligations and ICO enforcement action as large corporations.

"Once certified, always certified": False. BS EN 15713 certification requires regular surveillance audits and periodic full recertification to maintain validity. Always verify current certification status.

The Risk Management Case for Certified Destruction

When you transfer confidential documents to a shredding provider, your GDPR responsibilities don't transfer with them. You remain the accountable data controller. If your chosen provider fails to protect your material, your organisation faces:

  • ICO enforcement action with substantial financial penalties
  • Mandatory breach notification obligations to the ICO within 72 hours
  • Direct notification requirements to affected individuals when breach results in high risk
  • Potential civil claims from data subjects seeking compensation
  • Serious reputational damage and loss of customer confidence
  • Possible director disqualification in serious cases
  • Loss of contracts requiring demonstrated data protection compliance

BS EN 15713 certification provides independently verified, documented evidence of appropriate safeguards. It demonstrates you've conducted proper due diligence when selecting a destruction provider—essential protection during compliance audits or ICO investigations.

Understanding what documents need shredding and how long to keep business records helps you implement compliant document lifecycle management from creation through secure destruction.

The modest cost difference between certified and uncertified providers becomes insignificant compared to potential financial and reputational consequences of a data breach resulting from inadequate destruction procedures.

Making Your Provider Selection Decision

Understanding BS EN 15713 explained empowers you to conduct proper due diligence when selecting a document shredding provider. This isn't bureaucratic box-ticking—it's a comprehensive framework protecting your organisation from data breaches, regulatory penalties, and reputational damage.

When evaluating potential providers, prioritise these essential criteria:

  1. Current BS EN 15713:2023 certification from an accredited, independent certification body
  2. Appropriate destruction security level (P-4 commonly used for personal data)
  3. Certificates of destruction issued after every collection as standard
  4. Comprehensive chain of custody procedures with GPS tracking
  5. Rigorous staff vetting including DBS checks and ongoing security training
  6. Operational transparency and willingness to answer detailed questions
  7. Strong independent customer reviews demonstrating consistent service quality
  8. Transparent pricing without hidden charges or unexpected surcharges
  9. Comprehensive insurance coverage including data breach insurance
  10. Additional services matching your requirements: home office shredding for remote workers, scheduled collections, or drop-in facilities

Cross Cut Shredding maintains BS EN 15713:2023 certification with P-4 security level shredding across all services, comprehensive chain of custody procedures, and transparent pricing. Our 5-star Google rating from 127+ reviews demonstrates consistent service quality and reliability.

For organisations requiring secure document destruction that meets GDPR obligations, BS EN 15713 certification isn't optional—it's essential risk management protecting your organisation, your customers, and your reputation.

Contact us today to discuss your secure destruction requirements and verify our current BS EN 15713:2023 certification.

Sources

Check If We Collect In Your Area

Enter your postcode to see our services available near you

Covering Somerset, Dorset and into Devon & Wiltshire