Mark has just replaced his phone and his laptop. The old ones still work well: the phone is going to his nephew, the laptop will be sold through an online listing, and in a drawer there is an external drive he no longer uses and will sooner or later take to the local e-waste collection point. Before letting them go, he deleted his photos and emptied the bin. “There’s nothing left on them now,” he thinks.
It’s a reasonable belief, and a common one. But a device used for years holds far more than what you see when you open its folders: saved passwords, sign-ins that are still active, links to accounts and services, files you thought you had deleted. So the useful question isn’t “who would bother looking?”, but a different one: if this device ended up in someone else’s hands exactly as it is, what would be touched?
This post answers it by looking at the three aspects by which the security of any information is measured: that it stays private, that it stays correct, and that it stays available. They are the practical translation of three technical words — confidentiality, integrity, availability — and they help you see that the risks of data left on old devices go well beyond “someone might see my photos”.
It expands on the recommendation about wiping data before passing on a device: selling, giving away, sending for repair or disposing of a phone, a computer or a drive only after it has truly been emptied, and not just in appearance.
Three questions to measure an impact
For any device that is about to leave your home, the right questions are these:
- What could the person who receives it read? — this is the confidentiality question.
- What could they do or change in my name, even without meaning to? — this is the integrity question.
- What would I no longer be able to use, and what couldn’t the new owner use? — this is the availability question.
Applied to an old USB stick, they often produce a modest answer; applied to the phone you used every day for five years, almost always the same one: a lot. The point is that the impact isn’t measured by what you remember saving, but by everything the device has gathered and connected over time, often without you noticing.
1. Confidentiality: information stays with the people entitled to see it
Confidentiality is the guarantee that information can be read only by those who are authorised to read it. A device passed on without a complete wipe weakens it quietly: nobody has to break into anything, because the data is already in someone else’s hands.
A practical example
Mark’s old laptop holds scans of his passport and payslips, his photos, chats synced from his phone, and a browser with saved passwords and his email still open. Mark deleted the most obvious folders. But on most systems, deleting a file mainly means marking the space it took up as “free”: the content often stays where it is until something else overwrites it.
What the incident looks like
Whoever buys the laptop switches it on and finds, without even looking, Mark’s email already open in the browser. Or the “free” space on the disk is examined with common recovery tools, which bring back documents that were thought to be gone: the mechanism is described in the post on recovering data from second-hand devices. Simply reading identity documents, private conversations or work files is already a harm, and it goes unnoticed: nobody receives an alert.
What to watch for
- the device switches on and still shows your name, your wallpaper or your apps;
- the browser fills in addresses and passwords by itself when you visit a site;
- opening the email or messaging app doesn’t ask you to sign in;
- you deleted your files, but never did a full reset or a secure wipe of the disk.
What to do
Think of the device as an archive, not an object: the data needs to be made unreadable, not just hidden. Encrypting your personal devices helps a great deal, because an encrypted disk — one whose contents have been turned into a form that can only be read with a key — becomes useless to anyone who doesn’t hold that key. The step-by-step how is in the post on how to wipe your data securely.
2. Integrity: information stays correct
Integrity is the guarantee that data isn’t altered by anyone without the right to do so. Here it’s no longer about what someone can see, but about what they can do or change in your name through a device that online services still consider yours.
A practical example
The phone Mark gives to his nephew is still linked to his cloud account, the online storage space that keeps his photos and documents. His nephew, in perfectly good faith, deletes “Uncle Mark’s old photos” to free up space. Syncing — the mechanism that keeps the device and the cloud matched — does its job: it copies the deletion to Mark’s online archive, where his nephew’s photos are meanwhile piling up.
What the incident looks like
In the less fortunate case, the person who receives the device isn’t acting in good faith. An open session — the “stay signed in” state of an app or a website — lets them write messages from your social media profile, reply to emails, buy things from an online shop with your saved card, or change an account’s settings. To the services, every action comes from a recognised device; to your contacts, the messages come from you, and that is exactly why they seem believable.
What to watch for
- the device you passed on still appears in the list of devices linked to your accounts;
- you receive sign-in or activity notifications from a device you no longer have;
- files you don’t recognise appear in your cloud storage, or others go missing;
- someone tells you about strange messages or requests sent from your profile.
What to do
Before passing on a device, sign out of your accounts and remove it from the list of linked devices, from within each service. If the device has already gone, do it now from the computer or phone you use today: in most services, removing a device remotely closes the sessions left open on it. Changing the password for your main services makes the ones saved on the old device useless.
3. Availability: you can get in when you need to
Availability is the guarantee of being able to use your data and your tools when you need them. In this topic it has a particular feature: it concerns both you and the person who receives the device.
A practical example
Mark restores his old phone to its factory settings, which means taking it back to the state it was in when it came out of the box. Only afterwards does he realise that it held years of chats never saved anywhere else, and the app that generates codes for multi-factor authentication, the second check some services ask for on top of the password. Meanwhile, his nephew switches on the phone and finds a screen asking for Mark’s account: the anti-theft protection linked to the manufacturer’s account is still active.
What the incident looks like
On Mark’s side, wiping the phone without backing up photos and videos turns a protective step into a loss: whatever wasn’t copied elsewhere won’t come back. And without the second-factor codes, getting back into some accounts means going through lengthy recovery procedures. On the receiving side, the device stays unusable until the previous owner can be tracked down: easy if it’s a relative, much less so if it’s a buyer you’ve never met.
What to watch for
- you don’t know for sure when you last backed up the device;
- the old phone holds the verification code app, or it’s where you receive confirmation texts;
- the device is still registered with the manufacturer’s location and lock service;
- the person who received the device contacts you because it’s asking for your account.
What to do
The order matters more than the speed: first copy your data, then move your second factor to the new device, then sign out of your accounts and the anti-theft service, and only at the end wipe the device. A device handed over “clean” should be clean for the person who receives it, but not at your expense.
| Aspect | What can happen with the device you pass on | Why it matters |
|---|---|---|
| Confidentiality | The new owner reads documents, photos, chats and saved passwords, even recovering deleted files | The harm happens without traces and without alerts |
| Integrity | Open sessions and linked accounts let someone act in your name or alter your archives | It involves your contacts and data you thought was safe in the cloud |
| Availability | You lose data and codes that weren’t copied; the new owner finds a locked device | The harm can be permanent for you, and the device stays unusable for the other person |
One scenario that brings them together
Mark sells his old laptop to someone he found through an online listing. Before handing it over, he deletes the “Documents” folder, empties the bin and leaves everything else as it is: his user account, the browser, the cloud sync software.
The buyer is an honest person. He switches on the computer and finds the browser with Mark’s email open (confidentiality). To tidy up, he deletes the folders he assumes the previous owner left behind: syncing copies the deletion to Mark’s cloud, and the files change or disappear there too (integrity). A few days later Mark looks for a contract in his online archive and can no longer find it (availability).
Three different impacts, a single cause: a device passed on without a clear order of steps. And nobody in this story had bad intentions.
The impacts that show up later
Not every effect appears on the day you hand the device over, which is why “I sold it months ago and nothing has happened” isn’t a reliable check.
- Devices that stay “trusted”. Many services remember the devices you sign in from and stop asking for the second factor. Until the old device is removed, it remains a door with the key already in the lock.
- Codes that arrive somewhere else. If your phone number or SIM card stays with the device you passed on, verification and recovery texts may reach someone else.
- Storage that resurfaces. A drive forgotten in a drawer can change hands years later — in a house move, in a bag of e-waste — with data you no longer remember.
- Other people’s data. Contacts, photos of friends and family, documents from clients or colleagues: what stays on the device also concerns people who never chose to entrust it to you. The concrete fallout is the subject of the consequences of selling a device without wiping it.
This isn’t a reason to keep old devices locked in a cupboard. It’s the reason protection has to come first: a complete wipe, done in the right order, reduces all four of these effects, including the ones you’ll never see.
Not all devices weigh the same
The impact depends on what the device holds and on which accounts and services are still linked to it.
| Type of device | Main impact | Why |
|---|---|---|
| Smartphone | All three, with a multiplier effect | Chats, photos, verification codes, recovery accounts: it’s often the key to everything else |
| Laptop or desktop computer | Confidentiality and integrity | Years of documents, a browser with passwords and sessions, syncing with the cloud |
| External backup drive | Confidentiality | Holds complete copies, often with no password or encryption |
| USB sticks and memory cards | Confidentiality | Small and forgotten: photos, scans, work files “just passing through” |
| Smart TVs, games consoles and smart home devices | Integrity | Shopping and payment accounts still linked |
| Faulty device that won’t switch on | Confidentiality, high precisely because it can’t be wiped | The data is still on the storage and can be read with the right tools |
The last row is the one that counts: the most delicate device to pass on is often the one that seems to hold nothing any more, simply because it won’t switch on.
Why half-finished wipes matter too
Almost everyone does something before passing on a device. But each step, on its own, closes one risk and leaves another one open.
| What you did | Why it isn’t enough on its own |
|---|---|
| Deleted files and emptied the bin | The space is marked as free, but the content often remains recoverable |
| Quick format of the drive | It rebuilds the index but doesn’t erase the contents: the difference is explained in the recommendation on choosing a full format |
| Factory reset without signing out of accounts | The data may become unreadable, but the anti-theft lock and the links to your accounts remain |
| Signed out of accounts without wiping | The sessions close, but files, photos and chats stay on the device |
| Complete wipe without a backup | The device is clean, but your data no longer exists anywhere |
| Drive removed and put in a drawer | The risk isn’t removed: it’s only postponed |
If the data is encrypted, a full reset makes it unreadable in practice, because the key is deleted: the reason is explained in how secure data erasure works.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Recognising that a device you pass on carries data, sign-ins and links with it, not just the visible files |
| Skills | Being able to read confidentiality, integrity and availability as three concrete questions to ask before selling, giving away or disposing of a device |
| Secure Behaviour | Following a clear order — backup, signing out of accounts, complete wipe — and checking the list of linked devices |
Reference level: FL2 — Beginner. This is the level at which you move from “I’ll wipe it before I sell it” to “I understand what stays behind if I wipe it badly, or too soon.” To see where you stand on your other digital habits, you can take the digital resilience self-assessment.
Summary
- Confidentiality is about what the new owner could read: photos, documents, chats, saved passwords, files you thought you had deleted.
- Integrity is about what could be done or changed in your name: open sessions, linked accounts, cloud archives altered by syncing.
- Availability is about what nobody can use any more: your data wiped without a copy, lost verification codes, a device locked for the person who receives it.
A device passed on without wiping doesn’t produce just one impact: it can touch all three, for you and for the person who receives it.
One thing to do today. Open the security settings of your main email account and your cloud storage, and look at the list of linked devices. If a device you no longer have appears there, remove it. It takes about five minutes, and it reduces all three impacts even for the devices you have already passed on.
Related content
- Wiping data before passing on a device — the recommendation this expands on
- Consequences of selling a device without wiping it — from technical impacts to concrete effects on work, money, reputation and relationships
- Signs your data was not fully erased — how to notice that a device you passed on is still tied to you
- How to wipe your data securely — what to do, in order, for your phone, computer and external drive
Related resources
Short pieces from the Resources section, for anyone who wants to focus on a single aspect:
- The Final Step: How to Log Out of Your Accounts
- Data Backup: The Only Protection That Works Afterwards
- Data Encryption: Already On, and Worth Understanding
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



