Deleting a file does not destroy it. When you move something to the Recycle Bin and empty it, the operating system marks the space as available for reuse but doesn’t overwrite the data — the file content remains on the storage medium until new data happens to occupy that exact space. Anyone with a free recovery tool can retrieve recently-deleted files with a few clicks. If you want the full context, see our Complete Guide to Online Security and Privacy.
For sensitive files — tax returns, legal documents, financial records, personal identification, business-sensitive data — secure file deletion requires deliberate action beyond the standard delete process. The method needed depends on whether the drive uses traditional spinning platters (HDD) or flash-based solid-state storage (SSD), because the physics of data writing and overwriting differ fundamentally between the two technologies.
HDDs — overwriting is reliable
Traditional hard disk drives store data by magnetising specific physical sectors on spinning platters. Secure deletion on an HDD is well-understood: overwrite the sectors that contained the sensitive file with random data, and the original content is destroyed. NIST guidelines (SP 800-88) indicate that a single overwrite with random data is sufficient for modern HDD density levels — multiple passes add time without commensurate security benefit for non-classified commercial use cases.
On Windows: Eraser (eraser.heidi.ie, free) is the most widely-used tool. Install → right-click any file or folder → Eraser → Erase. The default method uses a single pseudorandom overwrite, which is sufficient for most purposes. Eraser also provides “Erase Free Space” — overwriting all unallocated sectors on the drive, which destroys previously-deleted files without erasing current data. This is the most comprehensive option for a drive that has been in use for some time with sensitive files previously deleted using standard deletion.
On macOS: the built-in rm -P /path/to/file command in Terminal performs a secure overwrite before removal. For a graphical approach, Permanent Eraser provides right-click secure deletion.
SSDs — a fundamentally different challenge
Solid-state drives present a problem that overwrite-based methods cannot reliably solve. SSDs use flash memory with wear-levelling algorithms that spread writes across cells to prolong the drive’s lifespan. When a file is “overwritten,” the SSD doesn’t write new data to the same physical cells — it writes to fresh cells and marks the old cells for garbage collection. The old cells may contain the original data for an indefinite period until garbage collection runs. Traditional overwrite-based secure file deletion methods don’t reliably destroy data on SSDs.
The reliable approaches for SSDs:
Full-disk encryption from setup (most important): if the drive has been fully encrypted from the start (BitLocker, FileVault, VeraCrypt), then deleting a file means the wear-levelling copies contain only encrypted ciphertext that cannot be decrypted without the key. This is why enabling full-disk encryption at device setup is the approach that retroactively solves the SSD secure file deletion problem for all future files — not because it deletes them, but because deleted files on an encrypted drive become unrecoverable without the key.
ATA Secure Erase: the SSD manufacturer’s built-in secure deletion command that instructs the drive’s controller to cryptographically erase all data — bypasses the wear-levelling problem by operating at the hardware level. Available through tools like Samsung Magician (Samsung SSDs), Crucial Storage Executive (Crucial SSDs), and HDParm (Linux). Used for whole-drive sanitisation, not individual files.
For individual files on an unencrypted SSD: the honest answer is that perfect individual-file secure deletion on unencrypted SSDs isn’t reliably achievable through software. The practical approach: enable BitLocker or FileVault going forward (solves the problem for all future files), and plan to use ATA Secure Erase when the drive is eventually retired.
Device preparation for sale or donation — the highest-stakes scenario
A device sold to a stranger puts data in the hands of someone with the time, motivation, and free tools to recover it. Proper sanitisation before transfer is the complete secure file deletion operation that addresses all data on the drive.
Windows PC with HDD: Settings → System → Recovery → Reset this PC → Remove everything → Change settings → enable “Data erasure: On” → Reset. This overwrites all data with zeros as part of the reset process — more reliable than a standard factory reset that leaves data recoverable.
Windows PC with SSD: BitLocker-encrypt the drive (if not already encrypted) → Reset this PC → Remove everything → Reset. Because the drive is encrypted, the reset erases the encryption key — all data on the drive becomes cryptographically inaccessible. For belt-and-suspenders assurance, add ATA Secure Erase via the drive manufacturer’s tool after the reset.
Mac (Apple Silicon): Recovery Mode provides a hardware-based Secure Erase function that reliably erases the internal SSD regardless of prior encryption status. Boot into Recovery Mode (hold power button) → Erase All Content and Settings.
Mac (Intel): ensure FileVault is enabled → Erase Mac in System Settings → Erase All Content and Settings. The FileVault encryption means the erasure destroys the key, making remaining data unrecoverable. For additional assurance: boot into Recovery Mode → Disk Utility → Erase the startup drive.
Smartphones: both iOS and Android use full-device encryption by default on current hardware. Performing a factory reset via Settings destroys the encryption key — all data becomes unrecoverable. iOS: Settings → General → Transfer or Reset iPhone → Erase All Content and Settings. Android: Settings → General Management → Reset → Factory Data Reset.
Cloud files and digital footprint
Secure file deletion extends beyond local storage to cloud services where copies may exist:
- Google Drive: Move file to Trash → Empty Trash. Also check “Computers” in Google Drive for any files synced from old devices that may still be present.
- OneDrive: Move to Recycle Bin → Empty Recycle Bin. Files shared with others remain in their drives — revoke sharing access before deleting if the file is truly sensitive.
- Dropbox: Move to Trash → Permanently Delete (in the Deleted files section). Dropbox keeps previous versions for 30 days (180 days on extended plans) — contact Dropbox support if permanent deletion of version history is required.
- Email attachments: deleting a sent email doesn’t delete the recipient’s copy — if a sensitive file was emailed, the deletion is only from your side. Search your inbox for any attachments containing sensitive data and delete the emails from both Sent and Inbox.
- Backups: secure file deletion from primary storage doesn’t affect backups. If a specific file needs to be permanently destroyed, identify and delete it from backup copies as well — or accept that the backup retains the file.
Temporary files and application artifacts
Opening a sensitive document creates additional copies beyond the primary file — temporary files, application cache, thumbnail previews. These are often overlooked in secure file deletion processes.
- Windows temp files: Settings → Storage → Temporary files → select and clean; or
%temp%in Run dialog → select all → delete - Browser download history and cache: files downloaded through the browser leave entries in download history even after deletion from the download location
- Application-specific cache: Office opens recent documents from cache directories; PDF readers may cache recent documents
BleachBit (Windows and Linux, free) and CleanMyMac (macOS, paid) provide comprehensive cache and artifact cleaning that complements targeted secure file deletion of individual sensitive files. For the most thorough approach: combine targeted secure overwrite of the specific sensitive file, BleachBit/equivalent cache cleaning, and Eraser’s Erase Unused Disk Space function (HDD only) to eliminate both the primary file and the temporary copies created during its use.
GDPR and data deletion obligations
The right to erasure (GDPR Article 17) requires organisations to securely delete personal data when it’s no longer needed or when a deletion request is received. This has direct implications for secure file deletion practices: organisations must know where personal data lives (primary storage, backups, email archives, cloud storage, third-party systems) and be able to apply secure deletion to each location systematically.
Implementing secure file deletion as a standard end-of-retention-period process — rather than a one-time response to deletion requests — is the approach that makes compliance operationally sustainable. Our guide on protecting personal data covers the data minimisation practices that reduce the volume of sensitive data requiring secure file deletion over time.
Physical destruction — when software isn’t enough
For drives containing particularly sensitive data — classified business information, personal data at significant breach cost, health records — physical destruction of the storage medium is the only approach that provides absolute certainty. A hard drive that has been shredded, degaussed, or incinerated contains no recoverable data regardless of how many software-based deletion passes were applied.
Commercial media destruction services provide certificates of destruction for compliance purposes. For individual users retiring a single drive: drilling multiple holes through the drive platters (HDDs) or through the circuit board and NAND chips (SSDs) provides physical destruction that defeats recovery. For most consumer secure file deletion scenarios, full-disk encryption combined with ATA Secure Erase is sufficient. Physical destruction is the definitive answer for situations where any uncertainty about software-based methods is unacceptable. For NIST’s official media sanitisation guidance covering the decision process for choosing between clearing, purging, and destruction based on data sensitivity and media type, NIST SP 800-88 Rev. 1 provides the authoritative technical reference.
Secure file deletion decision guide — which method to use
| Scenario | Drive type | Recommended method | Reliability |
| Delete individual sensitive file — Windows HDD | HDD | Eraser (single pseudorandom overwrite) | High |
| Delete individual sensitive file — macOS HDD | HDD | rm -P filename in Terminal or Permanent Eraser | High |
| Delete individual sensitive file — SSD (any OS) | SSD | Full-disk encryption active? Rely on that. Otherwise: no reliable individual-file method. | High (if encrypted) / Low (if not) |
| Destroy all previously-deleted files on HDD | HDD | Eraser → Erase Unused Disk Space | High |
| Prepare Windows PC (HDD) for sale | HDD | Reset this PC → Remove everything → Data erasure: On | High |
| Prepare Windows PC (SSD) for sale | SSD | BitLocker encrypt → Reset → Remove everything; optionally add ATA Secure Erase | High |
| Prepare Mac (Apple Silicon) for sale | SSD | Recovery Mode → Erase All Content and Settings | High (hardware-level) |
| Prepare Mac (Intel) for sale | SSD | FileVault enabled → Erase All Content and Settings | High |
| Retire SSD from service (maximum assurance) | SSD | ATA Secure Erase via manufacturer tool, then physical destruction if very sensitive | Highest |
| Classified or highly sensitive data (any) | Any | Physical destruction (shredding, degaussing, drilling) | Definitive |
The table maps the most common scenarios to the appropriate method. For everyday secure file deletion of individual sensitive files on a Windows HDD, Eraser takes 30 seconds. For preparing a device for sale, the built-in reset option with data erasure enabled is what most users need — no third-party tools required. The SSD scenarios are where the process is most nuanced, and where full-disk encryption from the beginning of device use pays dividends: an encrypted SSD that is factory-reset is effectively sanitised without requiring any additional steps. Our guide on Secure File Sharing covers an adjacent issue.
Secure file deletion is one of the habits that most people think about only when it’s too late — after a device has been sold, after a drive has been discarded, after a sensitive file has been deleted without any thought of who might recover it. Building the habit of secure deletion before it’s needed — and enabling full-disk encryption on all devices now, to solve the SSD deletion problem retroactively — addresses the gap before it becomes an incident. See also Secure Cloud Storage for a related case.







