Contact Us: (206) 322 - 8461
Email: mark@pacificnwshredding.com
Address: P.O. Box 59773 Renton, WA 98058 US
Though Pacific Northwest Shredding has a reputation for competitive pricing, customers should never hire any shredding service based on price alone.
When a customer wants to hire a company to destroy old computer equipment, they typically use the Internet to find a few local service providers and go with the lowest bid.
Unfortunately, while it sounds logical, it’s also illegal.
Really? Illegal?
Yes, today’s data protection regulations, such as HIPAA, GLBA, FACTA, and at least 19 new state laws, require organizations to scrutinize potential data destruction service providers to make sure they have a sufficiently high level of security and meet regulatory compliance requirements. As a result, hiring a provider just because they have the lowest price violates those regulations. In fact, if ever there were to be breach or a regulatory audit, regulators would automatically want to see selection criteria used to hire such service providers.
Keep in mind, because data protection and privacy regulations are enacted by governmental authority and are enforceable by law, violating them literally constitutes an illegal act. The fact is, however, though it is technically illegal to use pricing to make the decision, it is not the only reason for reviewing the compliance and security of any future shredding service.
Unfortunately, there are too many shredding services with little or no security or regulatory compliance. Their continued operation is based solely on the fact that their customers neglect their legal obligation to look under the hood. And, while their low prices might seem attractive, those prices are often because they are not spending time and resources on employee screening and training, or proper insurance, or keeping up with constantly changing regulatory requirements. Often, they would be hard-pressed to define what appropriate security and compliance even looks like. Compounding the risk, should a shredding service cause a data security breach, the same regulations that require vendor selection due diligence would also hold their customers 100% responsible for breach notification costs. Even worse, when regulators learn that the service provider was hired without proper scrutiny, the customer would be found negligent, liable, and subject to further penalties and sanctions.
WHAT SHREDDING SERVICE DUE DILIGENCE LOOKS LIKE
1. Verify the Service Provider’s Certification
Certainly, requiring industry certifications, like NAID AAA Certification, can help with due diligence. But remember, such certifications are a floor not a ceiling. They represent the minimum that should be required, not the maximum. So, while requiring NAID AAA Certification should without question be a part of any shredding service due diligence, there are other things customers should be examining.
2. Verify the Service Provider’s Professional Liability Insurance
The question here is straightforward; do they have professional liability coverage? Most service providers don’t. Ironically, firms that have the capacity to indemnify their customer for the service provider’s error and omissions are often the least likely to need it. The point of requiring it is not that there is heightened risk of a problem, but rather that it is a best practice for customers to expect shredding service to have a reasonable, limited capacity to indemnify the customer for their mistakes. And, by verify, we mean get proof. Too often a service provider says they have it, while they may not even know what it is. General business insurance policies do not cover a vendor’s errors and omissions.
3. Verify the Service Provider’s Regulatory Expertise
The customer has the right to expect their shredding service to be the expert in secure disposition and regulatory compliance, not the other way around!! The simplest way to determine whether a shredding service is capable and trustworthy is to evaluate qualifications of the person on their team who is responsible for their regulatory compliance. In the past few years alone, 19 states have enacted new data protection regulations that have impacted shredding services. In fact, many international regulations now impact large customers doing business around the world. No service provider could be expected to respond to these changes without internal expertise driving their compliance program. Many shredding services lack the capability or willingness to make such accommodations, preferring to take an “off-the-shelf” and “one-size-fits-all” approach. This inevitably puts the customer at risk. Clearly, we hope customers choose Pacific Northwest Shredding to meet their shredding needs. But, if that’s not in the cards, we want them to know how to best protect themselves. Please don’t hesitate to contact us at any time with questions or concerns. We pride ourselves on our internal compliance expertise and are pleased to be of assistance to any organization looking to do the right thing.
Contact Pacific Northwest Shredding today. We can make performing the required due diligence on our service simple and easy.
© 2025 Pacific Northwest Shredding – All rights reserved.
The National Association for Information Destruction (NAID) enforces the highest standard of security for document destruction companies. NAID ensures all procedures surpass strict security guidelines before they grant certification. learn more
The National Association for Information Destruction (NAID) enforces the highest standard of security for document destruction companies. NAID ensures all procedures surpass strict security guidelines before they grant certification. learn more
Contact Us: (206) 322 - 8461
Email: mark@pacificnwshredding.com
Address: 3215 Lafayette Ave. South, Seattle, WA 98144
Contact Us: (206) 322 - 8461
Email: mark@pacificnwshredding.com
Contact Us: (206) 322 - 8461
Email: mark@pacificnwshredding.com
Contact Us: (206) 322 - 8461
Email: mark@pacificnwshredding.com
Address: P.O. Box 59773 Renton, WA 98058 US
Copyright © 2024 Pacific Northwest Shredding, Inc. | All Rights Reserved | Privacy Policy | Designed and Managed by JLT Web Design & Digital Marketing.
Copyright © 2024 Pacific Northwest Shredding, Inc. | All Rights Reserved | Privacy Policy |
Designed and Managed by JLT Web Design & Digital Marketing.
Copyright © 2024 Pacific Northwest Shredding, Inc. All Rights Reserved
Designed and Managed by JLT Web Design & Digital Marketing.