Data Protection through Data Destruction
General Data Protection Regulation
In May 2018, legislation regarding the handling of general and personal data came into effect across Europe. Organisations know it as the General Data Protection Regulation (GDPR), and it aims to give individuals more control over their personal data.
GDPR applies to all businesses that handle personal data of EU citizens, regardless of where the business is located. It is important for businesses to understand their obligations under the GDPR and take steps to ensure compliance.
"The General Data Protection Regulation (GDPR) significantly increases the obligations and responsibilities of organisations and businesses in how they collect, use and protect personal data. At the centre of the new law is the requirement for organisations and businesses to be fully transparent about how they are using and safeguarding personal data, and to show accountability for their data processing activities."
How does this affect businesses?
GDPR (General Data Protection Regulation) affects businesses in various ways. First and foremost, it requires businesses to get consent from individuals before collecting and processing their data. Additionally, businesses must implement measures to ensure the security of the data. Non-compliance can cause serious fines. However, GDPR also provides opportunities for businesses to build trust with their customers. For example, by being transparent about their data practices and respecting individuals’ rights to privacy.
It is the responsibility of businesses and organisations to dispose of data in a secure and appropriate manner and to inform individuals about how their data is being used. Overall, GDPR has the potential to improve data protection and privacy for individuals, while also promoting accountability and transparency for businesses. Failure to comply with GDPR can have serious consequences for businesses, including reputational damage and financial penalties. Therefore, it is important for businesses to understand and comply with GDPR regulations to protect both their customers and their own interests.
Retention Periods
Under GDPR, personal data should only be kept for as long as it is needed for the purpose it was collected for. Retention periods vary depending on what the information is and what it is being used for. Some data must be kept for a set number of years to meet legal or regulatory obligations, while other data should be disposed of as soon as it has served its purpose. What matters is that once data is no longer needed, it is securely destroyed.
Our role in the process
As a data controller, you decide what information your organisation holds and how long you need to keep it. When that data reaches the end of its retention period, it should be securely destroyed by a certified destruction company. This is what DGD Shredding & Technology does.
We maintain the highest level of shredding standards through the ISO 9001 Quality Management System and comply with EN15713 Secure Destruction of Confidential Data Code of Practice, registered with the FSQS, and every member of our team is Garda vetted, so your data is handled with the security and accountability that regulated organisations depend on.
In addition, we also maintain the ISO 14001 Environment Management System, which covers all environmental aspects of our activities.
The confidential information is tracked through a full chain of custody, from collection to destruction. On completion, you receive a Certificate of Destruction as proof that your data has been securely destroyed.
How does this affect you?
As an individual, GDPR gives you more control over your personal data and how it is used by organisations. You have the right to know what information is being collected about you, how it is being used, and who it is being shared with. You also have the right to request that your data be deleted or corrected if it is inaccurate. It is important to be aware of your rights under the GDPR and to exercise them if necessary. It also means that organisations have a responsibility to dispose of that information when it is no longer required, relevant, or has served its purpose.
DGD Shredding & Technology's Commitment
DGD Shredding & Technology takes GDPR very seriously, which is why we have in place measures to give you peace of mind when disposing of sensitive data.
“We make it our business to make sure nobody knows your business”
By choosing DGD Shredding & Technology, you can be assured that your confidential information is being handled with the utmost care and attention to detail. Our commitment to GDPR compliance means that your data is always protected, and our secure shredding services ensure that it is completely destroyed and cannot be accessed by anyone else. With DGD Shredding & Technology, you can focus on running your business, knowing that your sensitive information is in safe hands. All our staff, be they drivers, the sales team, or management, are all Garda vetted and trained in GDPR legislation.
DGD Shredding & Technology ensures ALL data is destroyed to the highest industry standards and provides Certificates of Destruction for all data shredded and destroyed. We have been operating for over 28 years, setting the standards for the shredding industry in Ireland, and are one of the largest Secure Destruction Specialists in the country, providing services in all four provinces.
Our GDPR specialists

Liam Garvey
Managing Director

Michael Garvey
Head of Operations & Compliance

Louise Tsang
Business Development Manager
FAQs about GDPR
There is no single retention period under GDPR. How long you keep data depends on what it is and what it is being used for — some records must be held for a set number of years to meet legal or regulatory obligations, while other data should be disposed of as soon as it has served its purpose. As the data controller, you decide the appropriate retention period; we provide the secure destruction once that period ends.
Yes. Every collection is tracked through a full chain of custody, and on completion you receive a Certificate of Destruction confirming that your confidential material has been securely destroyed. This gives you documented, auditable evidence that your data has been disposed of properly.
We comply with EN15713, the Secure Destruction of Confidential Data Code of Practice, and operate an ISO 9001 Quality Management System and an ISO 14001 Environmental Management System. We are also registered with the FSQS, and every member of our team is Garda vetted.
Yes. Under the storage limitation principle, personal data must not be kept longer than necessary, and once it is no longer needed it must be disposed of securely. Simply discarding or deleting confidential material is not sufficient — secure destruction ensures the data cannot be recovered or accessed.
Yes. We provide secure destruction for confidential paper documents as well as certified data wiping and destruction of end-of-life IT equipment and hard drives, so your data is handled securely across every format.
Yes. We operate nationwide, providing secure destruction services across all four provinces.






