Secure mobile data erasure and a factory reset are not quite the same business control. On a modern encrypted smartphone, a correctly completed manufacturer reset can be highly effective. For recyclers, refurbishers, trade-in operators and IT asset-disposal teams, the harder question is how to prove that the right process happened on every device.
A consumer preparing one iPhone or Android handset for sale can follow the manufacturer’s erase procedure and, in most cases, achieve an appropriate result. A business processing hundreds or thousands of devices has a different problem: it needs consistency, evidence, reporting and a reliable way to handle devices that do not follow the normal path.
That distinction is why professional data-erasure tools still matter — and why businesses should place erasure alongside device-status checks, diagnostics and asset protection rather than treat it as an isolated final step.
The short answer
A factory reset is not inherently insecure. On many modern encrypted phones, the manufacturer’s erase process can make user data inaccessible. For a business, however, simply assuming that every handset completed the correct reset provides little evidence that the required sanitisation actually took place.
Is a factory reset enough to erase a phone?
For many modern smartphones, yes — provided the correct manufacturer erase procedure completes successfully.
That is an important correction to a common misconception.
The UK’s National Cyber Security Centre says that, in nearly all normal cases, the built-in Restore, Factory Reset or Erase All Content and Settings feature provides the erasure needed before a modern device returns to use or sale.
Apple goes further in its technical documentation. On supported Apple devices, Erase All Content and Settings removes the relevant encryption keys from effaceable storage, making the existing user data cryptographically inaccessible.
Google similarly states that an Android factory reset removes the data stored on the phone, although exact behaviour can depend on the manufacturer and additional storage such as removable SD cards.
Therefore, the right question for a professional device business is not simply:
A better question is:
Why a factory reset alone may not be enough for a business
The difference is assurance.
Imagine an individual selling one personal phone. They know the handset, perform the reset themselves and can see the setup screen when the process finishes.
Now imagine a recycler receiving 2,000 mixed devices from several suppliers.
Some arrive unlocked, while others still contain user accounts. Damaged screens are common, and a few devices will not boot normally. Different Android manufacturers may also handle reset processes differently, while removable storage or eSIM configuration can introduce further considerations.
In that environment, “somebody factory-reset it” is not much of a control.
Businesses need repeatability
Staff should put every appropriate device through the same defined process, regardless of who handles it, which site processes it or how busy the operation becomes.
Businesses need evidence
If a customer, corporate client or compliance team asks what happened to a particular handset, the organisation should be able to answer with more than somebody’s recollection.
Businesses need exception handling
A good process identifies devices that fail to erase successfully and prevents them from moving through the workflow unnoticed.
Businesses need oversight
Management should be able to establish which devices staff processed, when erasure took place and whether the process produced the required result.
Factory reset and secure data erasure are not opposites
Professional data sanitisation does not necessarily require an entirely different physical method from the one built into the phone.
Modern smartphones rely heavily on encryption. As a result, cryptographic erasure — making encryption keys unavailable so the stored information cannot be read — now forms an important part of modern sanitisation.
NIST’s current SP 800-88 Rev. 2, published in September 2025, defines media sanitisation as rendering access to target data infeasible for a given level of effort.
Significantly, the new revision places much more emphasis on building a managed sanitisation programme, selecting appropriate methods and validating the result.
That approach suits modern device businesses better than the old assumption that secure erasure simply means overwriting every storage location repeatedly.
What about the old advice to overwrite data several times?
Advice about repeatedly overwriting a drive comes largely from an earlier generation of storage technology.
Businesses should not treat it as a universal rule for modern smartphones.
Flash storage, encryption and modern mobile operating systems work differently from traditional magnetic hard disks.
NIST’s latest guidance no longer centres its recommendations on arbitrary numbers of overwrite passes. Instead, it focuses on appropriate sanitisation techniques, cryptographic erase where suitable, standards-based methods and validation.
For businesses, the important outcome is not how dramatic the wiping process looks. What matters is whether the organisation can demonstrate that its sanitisation process made the target data inaccessible to the required level of assurance.
What does UK data-protection guidance actually require?
Data-protection compliance is another area where overly simple claims can cause confusion.
UK GDPR does not contain a rule stating that every second-hand smartphone must receive a particular branded wipe or a specific number of overwrite passes.
It does, however, require organisations to protect personal information appropriately.
The Information Commissioner’s Office states that organisations should destroy electronic records using appropriate methods that prevent disclosure before, during and after disposal.
The ICO specifically warns that insecurely destroyed personal information may remain recoverable and could breach the security principles in UK GDPR Articles 5(1)(f) and 32.
Documentation matters
The ICO’s organisational guidance also recommends documenting secure disposal methods.
That matters particularly for businesses processing devices on behalf of corporate customers, networks, insurers, retailers or recycling partners.
Being able to demonstrate the process can matter almost as much commercially as performing the process itself.
What can go wrong with a factory-reset workflow?
The main business risk is not necessarily that every correctly reset phone secretly contains easily recoverable photographs.
The real operational risks are more mundane — and therefore easier to overlook.
The reset never completes
A damaged or unstable handset may fail partway through the process.
Someone chooses the wrong reset option
On an iPhone, for example, Reset All Settings is very different from Erase All Content and Settings. Apple explicitly states that resetting settings leaves photos, messages, applications and documents on the handset.
Staff overlook removable storage
Android guidance notes that some erase processes may not remove information from removable SD cards. Businesses therefore need a separate handling policy for removable media where present.
The device still has an activation lock
Data erasure and ownership locks solve different problems. An erased phone may still have little commercial value if Apple’s Activation Lock or Android Factory Reset Protection remains active.
Nobody records the outcome
A successful erase with no device record may work technically while still leaving the business unable to demonstrate what happened later.
What should a professional mobile-data-erasure workflow look like?
A good process starts before anyone presses the wipe button.
Step 1
Identify the device
Capture the correct IMEI, serial number and transaction or batch reference so every later result belongs to the correct physical handset.
Step 2
Check its commercial status
If the business is acquiring the device, investigate relevant IMEI, blocklist, loss, theft, finance or activation-lock information before investing further processing cost.
Step 3
Test the handset
Establish whether the device functions correctly and identify faults that may change its eventual route.
Step 4
Perform the appropriate erasure
Apply the sanitisation method that suits the device, operating system and organisation’s policy.
Step 5
Verify the outcome
Confirm that the process completed successfully and send any exceptions for investigation rather than assuming they passed.
Step 6
Keep the record
Retain the relevant device-level evidence so the business can demonstrate what happened later.
Where MobiWIPE fits
MobiWIPE is MobiCode’s secure mobile-data-erasure application for Android and Apple devices.
MobiCode currently describes MobiWIPE as ADISA-approved for organisations handling pre-owned mobile devices.
More importantly for a commercial processing environment, MobiWIPE supports repeatable erasure and reporting rather than leaving staff to reset every handset as an isolated manual task.
Process multiple devices
MobiWIPE can process multiple handsets, which becomes increasingly important as device volumes grow.
Keep device-level records
MobiCode’s reporting environment records erasure activity and helps businesses retain evidence of the processing they carried out.
Build erasure into the workflow
For recyclers and refurbishers, this is one of the biggest advantages: data erasure becomes a controlled stage in a wider process rather than a separate job at the end of the bench.
Where MobiONE fits into secure device processing
MobiONE connects data erasure with the other decisions a used-device business needs to make.
MobiONE works alongside MobiCHECK, MobiTEST and MobiWIPE to provide a broader device-processing workflow.
Organisations can therefore combine due diligence, diagnostics, grading, workflow controls and secure erasure instead of moving manually between unrelated systems.
Why that matters at scale
A documented procedure is useful. A workflow that guides staff through the procedure is stronger.
Configurable alerts and Workflow Blocks can stop or flag devices when relevant exceptions appear instead of allowing them to move automatically to the next stage.
For multi-site recyclers, retailers and trade-in operators, that consistency can reduce human error and make it easier to prove that staff followed policy.
Data erasure should not start before device due diligence
Before spending time wiping and preparing a handset for resale, a business buying the device should first establish whether it makes commercial sense to process it.
MobiCHECK provides live IMEI and device-status due diligence.
MobiCHECK checks IMEIs against multiple independent datasets, including the GSMA Global Blacklist Registry, and can surface relevant information relating to network blocks, lost or stolen status, finance and insurance.
That matters because a perfectly erased phone can still be a poor purchase.
Different questions:
MobiCHECK: should we buy or process this device?
MobiTEST: does this physical handset work properly?
MobiWIPE: did the erasure process remove the previous user’s data appropriately?
Diagnostics still matter after due diligence
Secure data erasure says nothing about whether the screen, microphones, cameras, sensors or connectivity actually work.
MobiTEST provides guided diagnostics across hardware, display, sound, sensors and connectivity.
MobiCode states that its guided workflow can test a handset in under two minutes while supporting consistent test standards and reporting.
Combining status checking, diagnostics and erasure gives the business a much clearer picture of the device:
- is it safe to acquire?
- does it function correctly?
- did the process remove previous-user information?
- is it ready for its next route?
What does MobiBLOCK have to do with data erasure?
MobiBLOCK solves a different part of the device-protection problem — and the distinction matters.
Data erasure protects the information stored on a handset.
IMEI blocking and device-status flagging address the handset itself.
A stolen phone may need more than a wipe
If a business-owned, rented or leased handset becomes stolen or a customer fails to return it, removing stored data can protect sensitive information.
Erasure does not necessarily remove the resale value of the physical device.
MobiBLOCK gives eligible organisations another device-level response by allowing them to block or flag appropriate stolen, lost, fraudulently retained or unreturned handsets.
MobiBLOCK does not replace MobiWIPE
Blocking an IMEI does not erase photographs, messages, documents or account information.
Equally, securely erasing a handset does not communicate that the device is stolen, unreturned or subject to an active finance, rental or lease interest.
The two controls therefore address different risks.
| Risk | Relevant MobiCode tool |
|---|---|
| Previous-user data remains on the device | MobiWIPE |
| Device may be blocked, stolen, financed or otherwise high risk | MobiCHECK |
| Hardware functionality needs checking | MobiTEST |
| Business needs consistent processes across staff and sites | MobiONE |
| A stolen, lost or unreturned asset needs device-level protection | MobiBLOCK |
MobiBLOCK and MobiCHECK can also protect the next buyer
MobiBLOCK becomes particularly relevant once devices move through the second-hand supply chain.
An eligible organisation can use MobiBLOCK where evidence provides a legitimate reason to block or flag an at-risk handset.
If that handset later reaches a recycler, retailer or refurbisher, MobiCHECK can show relevant MobiBLOCK blocks or flags during due diligence.
That creates a useful separation of responsibilities:
An eligible business protects or flags an at-risk device.
A downstream buyer investigates the handset before purchasing or processing it.
MobiWIPE then handles the separate data-protection stage through secure erasure.
A practical example: processing a corporate phone return
Consider a business returning several hundred employee smartphones through a recycling or ITAD programme.
1. Identify each incoming device
Staff link each handset to its IMEI, serial number and relevant asset or batch record.
2. Check its status
Where the business is acquiring or reselling devices, MobiCHECK can identify relevant status risks before further commercial processing.
3. Test the hardware
MobiTEST establishes functional condition and supports a consistent grading process.
4. Sanitise the data
MobiWIPE provides the controlled erasure stage and associated reporting.
5. Separate any exceptions
Staff should route any handset that fails to wipe, remains activation-locked or cannot complete the required process for investigation rather than approve it automatically for resale.
6. Keep the result connected to the device
MobiONE can bring these stages into a more consistent overall workflow.
7. Manage later asset risk
If the business also deploys, rents or leases devices and one later becomes stolen or unreturned, MobiBLOCK provides a separate route for appropriate blocking or flagging.
What about phones that cannot be reset normally?
Professional processes become particularly important when a handset cannot follow the standard route.
Some devices arrive damaged, locked or unable to complete a normal boot cycle.
The NCSC advises organisations to choose sanitisation methods that suit the device, encryption state and sensitivity of the information.
In some circumstances, the organisation may decide that reuse creates too much risk and choose a stronger sanitisation or destruction route.
The correct decision therefore depends on the device and the organisation’s risk requirements rather than a blanket rule that every handset should receive exactly the same treatment.
Does secure erasure mean the phone can automatically be resold?
No.
Data erasure answers only one part of the resale decision.
A professionally wiped handset could still:
- have a network block;
- have an activation lock;
- carry a lost or stolen report;
- carry a finance or other status warning;
- have faulty hardware;
- have an incorrect grade.
That is why a mature used-device workflow combines data protection with due diligence and diagnostics.
The real difference is not “reset versus wipe”. It is assurance.
Modern iPhone and Android factory-reset mechanisms can provide effective data erasure when organisations use them correctly and allow the process to complete.
For businesses handling devices at scale, however, the challenge is making sure every handset follows the right process, staff catch exceptions and the organisation can demonstrate what happened.
That is where professional tooling adds value: MobiCHECK for device-status due diligence, MobiTEST for diagnostics, MobiWIPE for controlled data erasure, MobiONE for the wider workflow and MobiBLOCK for protecting stolen, lost, fraudulently retained or unreturned assets.
Build secure erasure into the full device lifecycle
MobiCode develops software for businesses that buy, process, recycle, refurbish, sell, rent and manage mobile devices.
Rather than treating wiping as a standalone action, the wider MobiCode suite can connect the major decisions around a handset.
Live IMEI and device-status due diligence before purchase or processing.Explore MobiCHECK →
Guided functional diagnostics and consistent device testing.Explore MobiTEST →
Secure mobile data erasure and reporting for pre-owned devices.Explore MobiWIPE →
Connected workflows for due diligence, testing, grading and erasure.Explore MobiONE →
Device blocking, flagging and asset protection for eligible organisations.Explore MobiBLOCK →
Reviewing your device-erasure process?
Talk to MobiCode about building secure data erasure, device-status checks, diagnostics and asset protection into a consistent used-device workflow.
Frequently asked questions
Does a factory reset completely erase an iPhone?
Apple’s Erase All Content and Settings process removes the relevant encryption keys and makes user data cryptographically inaccessible. This differs from choosing Reset All Settings, which leaves personal content on the device.
Does a factory reset erase Android phone data?
Google states that a factory reset erases the data stored on an Android phone. Businesses should still follow manufacturer-specific instructions and consider additional storage such as removable SD cards.
Why use professional data-erasure software if factory reset works?
Businesses processing devices at scale need more than the technical erase itself. They may need repeatable workflows, verification, exception handling, device-level reporting and evidence that the required process completed.
What is MobiWIPE?
MobiWIPE is MobiCode’s secure mobile data-erasure application for Apple and Android devices. It supports organisations handling pre-owned devices and connects erasure activity with MobiCode reporting.
Does MobiBLOCK erase data from a phone?
No. MobiBLOCK and data erasure solve different problems. MobiBLOCK helps eligible organisations block or flag appropriate stolen, lost, fraudulently retained or unreturned devices, while MobiWIPE handles secure data erasure.
How do MobiBLOCK and MobiCHECK work together?
MobiBLOCK can create relevant blocks or flags for at-risk devices, while MobiCHECK allows another business to investigate device status before buying or processing that handset. MobiCHECK can show devices that MobiBLOCK has blocked or flagged.
Sources and further reading
- UK National Cyber Security Centre — Erasing devices
- UK National Cyber Security Centre — Secure sanitisation and disposal of storage media
- Information Commissioner’s Office — Disposal and deletion
- NIST SP 800-88 Rev. 2 — Guidelines for Media Sanitization
- Apple Platform Deployment — Erase Apple devices
- Apple Support — Erase and factory reset iPhone or iPad
- Google Android Help — Reset an Android device to factory settings
- MobiCode — MobiWIPE secure mobile data erasure
- MobiCode — MobiCHECK device-status due diligence
- MobiCode — MobiTEST mobile diagnostics
- MobiCode — MobiONE device-processing workflow
- MobiCode — MobiBLOCK device blocking and asset protection


