Tech Behind ThingsHow the ordinary machinery actually works

Data & Privacy

What actually happens when you delete something

Deletion usually removes a reference rather than the data, and the copies you did not make are the ones that persist.

Iron gate with a padlock securing a closed entrance in Portland, Oregon.
Photograph by Kevin Bidwell via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

Comparisons of data deletion usually pick a winner. This one picks the circumstances, which is more useful.

The difference in one place

  • Deleting a file typically unlinks it rather than overwriting the contents.
  • Flash storage cannot overwrite in place, so old data lingers until reclaimed.
  • Online deletion starts a retention timer rather than removing data immediately.

Unlinking is not erasing

A filesystem deletion removes the entry pointing at the data and marks the space as available. The contents remain on the medium until something else is written over them, which is why recovery tools work.

On a busy device that may be minutes; on a large drive it may be years. This is a performance decision, since erasing every deleted file would make deletion as slow as writing.

Flash storage complicates it further

Flash cannot overwrite in place, so an edited file is written to a new location and the old copy is orphaned. Wear levelling deliberately spreads writes, which means multiple stale copies can exist in places the operating system cannot address.

The short version: a command exists for the operating system to tell the drive which blocks are no longer needed so it can erase them during maintenance. That erasure happens on the drive schedule, not yours, which is why overwriting free space is unreliable on flash.

Encryption makes deletion tractable

When a whole device is encrypted, destroying the key renders every block unreadable regardless of whether it was overwritten. This is what a secure erase on a modern device actually does, and it completes in seconds rather than hours.

It is also why enabling full-device encryption at setup, rather than before disposal, is the decision that matters. For a device that was never encrypted, physical destruction remains the only reliable answer for sensitive data.

Online deletion is a retention timer

Services typically mark an item deleted, hide it, and remove it from live systems after a defined period. Backups and replicas are usually purged on their own cycle, which can be considerably longer. Data protection regimes in several jurisdictions grant a right to erasure with defined response periods and explicit exceptions for legal and accounting obligations.

The practical consequence is that deletion is a request with a schedule rather than an event.

Copies you did not make

Content shared with others exists on their devices, in their backups and in message archives you cannot reach. Search engines and archive projects retain copies of public pages independently of the original.

Analytics and advertising systems may retain derived records about an item long after the item itself is gone. Anything genuinely sensitive should be treated as permanent from the moment it leaves your control.

Firmware updates change this behaviour more often than hardware does.

Disposing of a device properly

Confirm encryption was enabled, then perform the manufacturer erase, then sign out of accounts before wiping rather than after. Remove memory cards and check for a second internal drive, both of which are routinely forgotten. Deauthorise the device from account services, since a wiped device may still hold an activation lock or count against device limits.

Under load, for drives holding genuinely sensitive material, physical destruction is cheap insurance against every uncertainty above.

Side by side

ConsiderationWhat it means in practice
Unlinking is not erasingDeleting a file typically unlinks it rather than overwriting the contents.
Flash storage complicates it furtherFlash storage cannot overwrite in place, so old data lingers until reclaimed.
Encryption makes deletion tractableOnline deletion starts a retention timer rather than removing data immediately.

The takeaway

Deletion removes the pointer. Encryption first is what makes it a real erasure later.

The constraint is almost always physical, and marketing rarely mentions which one.

Questions readers ask

Do I need to overwrite a drive several times?

On modern magnetic drives a single pass is generally considered sufficient, and on flash storage overwriting is unreliable regardless. Destroying the encryption key is the effective approach.

Is deleted really deleted on a cloud service?

Eventually, on the provider schedule, including backups. Check the stated retention period, which is usually documented and often longer than users expect.

Data & Privacydeletionstorageretentionbackups
Mikkel Aas
Editor, Tech Behind Things

Mikkel edits Tech Behind Things and has taken apart more devices than he has successfully reassembled.

Also by Mikkel Aas