Practical privacy
Before You Let Go of an Old Device, Close the Privacy Loop
A practical sequence for backing up, signing out, erasing, and checking an old phone or computer before it changes hands.

An old phone or computer may look empty after the obvious files are gone, yet it can still be tied to photos, messages, payment information, saved sessions, cloud accounts, and recovery methods. Before a device is sold, donated, traded in, or recycled, privacy deserves its own closing routine. The goal is not simply to make the home screen look clean. It is to preserve what you need, end the device’s relationships with your accounts, and use the maker’s supported erasure process before the device leaves your control.
Start with a verified backup
Back up before deleting anything, then confirm that the important material is actually available somewhere else. Open a few transferred photos and documents, check contacts and calendars, and make sure any authenticator or password-manager migration is complete. Some app data may not move automatically. Google’s current Android switching guidance tells users to back up first and, after a transfer, check texts, photos, videos, and other data before clearing the old device. Apple’s iPhone and iPad handoff guidance, updated May 29, 2026, similarly puts backup and transfer before removal of personal information.
This order matters because erasure should be treated as a one-way step. A quick glance at the new device is not always enough: locally stored notes, downloaded files, health records, or app-specific exports may need separate attention. Keep the old device until the new one can perform the tasks you depend on.
Untangle accounts and accessories
Next, review the connections that can outlive the device itself. Sign out of the primary platform account using the manufacturer’s instructions. Unpair watches and other accessories, remove payment cards where the platform requires it, transfer or remove cellular service, and take out physical SIM and removable memory cards. If the device was managed by an employer or school, ask its administrator to remove the management profile and follow the organization’s return process.
Do not manually delete synchronized photos, contacts, or documents one by one while the device is still connected unless you understand how that service handles deletion. Apple warns that manually removing synchronized items while signed into iCloud can also remove them from iCloud and connected devices. A supported sign-out and erase sequence is safer than improvising.
Use the correct reset, not just file deletion
Deleting visible files or uninstalling apps is not the same as preparing a whole device for transfer. Use the full-device erase or factory-reset process specified for the exact model and operating system. Android’s official guidance says to clear data and reset to factory settings before recycling, donating, or trading in a device, but only after confirming the data was copied. It also directs users to the device maker and carrier because procedures can vary.
For Windows PCs, Microsoft’s Reset your PC guidance distinguishes “Keep my files” from “Remove everything.” For a sale, donation, or recycling, Microsoft recommends “Remove everything” with “Clean data” enabled, which is intended to make removed files harder to recover. Microsoft also cautions that this consumer feature does not meet government or industry erasure standards. Back up first and retain the BitLocker recovery key if the instructions say it may be needed during reset.
Match the method to the risk
A household device containing ordinary personal material and an organization’s drive containing regulated, confidential, or highly sensitive information are not identical disposal problems. The September 2025 final NIST SP 800-88 Revision 2 defines media sanitization in terms of making access to target data infeasible for a given level of effort. It tells organizations to select techniques and controls according to the media and the sensitivity of the information. That framework is useful because it avoids a universal promise that one reset method fits every storage technology or risk level.
If a device held sensitive client, employee, financial, medical, legal, or institutional information, follow the responsible organization’s retention and sanitization policy. Qualified IT or security personnel may need to verify the process, document it, or destroy media that cannot be reliably sanitized. When a device no longer works well enough to complete the supported erase, do not assume that broken means unreadable; consult the manufacturer, organization, or a reputable recycling program about secure handling.
Finish with a clean-start check
After the erase completes, restart the device without entering personal credentials. It should present the initial setup experience, not your profile, apps, files, or notifications. Check the relevant account’s device list from another trusted device and remove the old hardware if it remains attached. Confirm that cellular or eSIM service has moved, and keep a trade-in or recycling receipt when one is offered.
This final check turns a vague intention into a verifiable handoff. A device can have a useful second life without carrying someone else’s private life with it. The best routine is simple: back up, verify, disconnect, erase with the supported method, and confirm the result before letting go.
General educational information, not legal or security advice. Device procedures and organizational requirements vary. Sources checked September 11, 2026.