Skip to main content
Surveillance
Self-Defense

How to: Delete Your Data Securely on Windows

Last Reviewed: August 24, 2018

We are in the process of updating several guides, including this one, and are aware that some of this information is out of date.

Download location:  https://www.bleachbit.org/download/windows

Computer requirements: Windows XP or later

Versions used in this guide: BleachBit 2.0

License: GPLv3

Level: Beginner

Time required: 10 minutes to several hours (depending on size of files/disks to be securely deleted)

The instructions below should only be used for securely deleting data from spinning drives. These instructions apply only to traditional disk drives, and not to Solid State Drives (SSDs), which are standard in modern computers, USB keys/USB thumb drives, or SD cards/flash memory cards. Secure deletion on SSDs, USB flash drives, and SD cards is very hard! This is because these types of drives use a technique called wear leveling and do not provide low-level access to the bits as stored on the drive. (You can read more about why this causes problems for secure deletion here.) If you’re using an SSD or a USB flash drive, jump to this section below.

Did you know that when you move a file on your computer into your computer's trash folder and empty the trash, the file is not completely erased? Computers normally don't “delete” files; when you move a file to the trash, your computer just makes the file invisible and allows the space it took up to be overwritten by something else sometime in the future. Therefore, it may be weeks, months, or even years before that file is overwritten. Until this happens, that “deleted” file is still on your disk; it’s just invisible to normal operations. And with a little work and the right tools (such as “undelete” software or forensic methods), that “deleted” file can be retrieved.

So, what’s the best way to delete a file forever? Ensure it gets overwritten immediately. This makes it difficult to retrieve what used to be written there. Your operating system probably already has software that can do this for you—software that can overwrite all of the “empty” space on your disk with gibberish and thereby protect the confidentiality of deleted data.

On Windows, we currently suggest using BleachBit, an open-source secure deletion tool for Linux and Windows. BleachBit can be used to quickly and easily target individual files for secure deletion, or to implement periodic secure deletion policies. It is also possible to write custom file deletion instructions. You can find further information in the documentation.

Installing BleachBit anchor link

You can get BleachBit on Windows by downloading the installer from the BleachBit download page

Click on the BleachBit installer .exe link. You'll be taken to the download page.

Many browsers will ask you to confirm whether you want to download this file. Microsoft Edge 40 shows a bar at the bottom of the browser window with a blue border.

For any browser it is best to first save the file before proceeding, so click the “Save” button. By default, most browsers save downloaded files in the Downloads folder.

Keep the Windows Explorer window open and double-click on BleachBit-2.0-setup. You'll be asked if you want to allow the installation of this program. Click the “Yes” button.

A window will open asking you to select an installation language. Select the language you want and click the OK button.

The next window will show you the GNU General Public License. Click “I Agree.”

In the next window BleachBit shows some customization options. You may leave the options as they are. We recommend removing the check mark from the Desktop option. Click the Next button.

Now BleachBit will ask you to confirm where you want to install. Click the Install button.

Finally, the BleachBit installer shows a window telling you the installation is complete. Click the Next button.

The last window in the installer asks whether you want to run BleachBit. Remove the checkmark from the Run BleachBit option. Click the Finish button.

Using BleachBit anchor link

Go to the Start menu, click the Windows icon, and select BleachBit from the menu.

A small window will open and confirm you want to open BleachBit. Click the "Yes" button.

The main BleachBit window will open. BleachBit will detect several commonly installed programs and show special options for each program.

Using Presets anchor link

BleachBit can wipe the traces Internet Explorer leaves behind using the Internet Explorer preset. Check the box next to Internet Explorer. Notice how all the boxes belonging to Cookies , Form history, History, and Temporary files are also checked. You can uncheck them as needed. Click the Clean button.

BleachBit will now clean up certain files and show you the progress.

How to Securely Delete a Folder anchor link

Click the File menu and select Shred Folders.

A small window will open. Select the folder you want to shred.

BleachBit will ask you to confirm whether you want to permanently delete the files you selected. Click the Delete button.

BleachBit will now show you the files you deleted. Notice that BleachBit securely deletes each file in the folder, then securely deletes the folder.

How to Securely Delete a File anchor link

Click the File menu and select Shred Files.

A file selection window will open. Select the files you want to shred.

BleachBit will ask you to confirm whether you want to permanently delete the files you selected. Click the Delete button.

BleachBit has a number of other features. The most useful one may be wiping free space. This will attempt to remove any traces of files you have already deleted. Often Linux will leave all or part of the data from deleted files in the remaining free space left on the hard drive. Wiping free space will overwrite these supposedly empty parts of the hard drive with random data. Wiping free space can take a lot of time, depending on how much spare capacity your drive has.

A Warning About the Limitations of Secure Deletion Tools anchor link

Remember that the advice above only deletes files on the disk of the computer you’re using. None of the tools above will delete backups that were made to somewhere else on your computer, another disk or USB drive, a “Time Machine,” on an email server, in the cloud, or sent to your contacts. In order to securely delete a file, you must delete every copy of that file, everywhere it was stored or sent. Additionally, once a file is stored in the cloud (e.g. via Dropbox or some other file-sharing service) there’s usually no way to guarantee that it will be deleted forever.

Unfortunately, there’s also another limitation to secure deletion tools. Even if you follow the advice above and you’ve deleted all copies of a file, there is a chance that certain traces of deleted files may persist on your computer, not because the files themselves haven't been properly deleted, but because some part of the operating system or some other program keeps a deliberate record of them.

There are many ways in which this could occur, but two examples should suffice to convey the possibility. On Windows or macOS, Microsoft Office may retain a reference to the name of a file in the “Recent Documents” menu, even if the file has been deleted (Office might sometimes even keep temporary files containing the contents of the file). LibreOffice may keep as many records as Microsoft Office, and a user's shell history file may contain commands that include the file's name, even though the file has been securely deleted. In practice, there may be dozens of programs that behave like this.

It's hard to know how to respond to this problem. It is safe to assume that even if a file has been securely deleted, its name will probably continue to exist for some time on your computer. Overwriting the entire disk is the only way to be 100% sure the name is gone. Some of you may be wondering, “Could I search the raw data on the disk to see if there are any copies of the data anywhere?” The answer is yes and no. Searching the disk will tell you if the data is present in plaintext, but it won't tell you if some program has compressed or otherwise coded references to it. Also, be careful that the search itself does not leave a record! The probability that the file's contents may persist is lower, but not impossible. Overwriting the entire disk and installing a fresh operating system is the only way to be 100% certain that records of a file have been erased.

Secure Deletion When Discarding Old Hardware anchor link

If you want to throw a piece of hardware away or sell it on eBay, you'll want to make sure no one can retrieve your data from it. Studies have repeatedly found that computer owners usually fail to do this―hard drives are often resold chock-full of highly sensitive information. So, before selling or recycling a computer, be sure to overwrite its storage media with gibberish first. And even if you're not getting rid of it right away, if you have a computer that has reached the end of its life and is no longer in use, it's also safer to wipe the hard drive before stashing the machine in a corner or a closet. Darik's Boot and Nuke is a tool designed for this purpose, and there are a variety of tutorials on how to use it across the web (including here).

Some full-disk encryption software has the ability to destroy the master key , rendering a hard drive's encrypted contents permanently incomprehensible. Since the key is a tiny amount of data and can be destroyed almost instantaneously, this represents a much faster alternative to overwriting with software like Darik's Boot and Nuke, which can be quite time-consuming for larger drives. However, this option is only feasible if the hard drive was always encrypted. If you weren't using full-disk encryption ahead of time, you'll need to overwrite the whole drive before getting rid of it.

Discarding CD- or DVD-ROMs anchor link

When it comes to CD- or DVD-ROMs, you should do the same thing you do with paper―shred them. There are inexpensive shredders that will chew them up. Never just toss a CD- or DVD-ROM in the garbage unless you're absolutely sure there's nothing sensitive on it.

Secure Deletion on Solid-state Disks (SSDs), USB Flash Drives, and SD Cards anchor link

Unfortunately, due to the way SSDs, USB flash drives, and SD cards work, it is difficult, if not impossible, to securely delete both individual files and free space. As a result, your best bet in terms of protection is to use encryption. That way, even if the file is still on the disk, it will at least look like gibberish to anyone who gets ahold of it and can’t force you to decrypt it. At this point in time, we cannot provide a good general procedure that will definitely remove your data from an SSD. If you want to know why it’s so hard to delete data, read on.

As we mentioned above, SSDs and USB flash drives use a technique called wear leveling. At a high level, wear leveling works as follows. The space on every disk is divided into blocks, kind of like the pages in a book. When a file is written to disk, it’s assigned to a certain block or set of blocks (pages). If you wanted to overwrite the file, then all you would have to do is tell the disk to overwrite those blocks. But in SSDs and USB drives, erasing and re-writing the same block can wear it out. Each block can only be erased and rewritten a limited number of times before that block just won’t work anymore (the same way if you keep writing and erasing with a pencil and paper, eventually the paper might rip and be useless). To counteract this, SSDs and USB drives will try to make sure that the amount of times each block has been erased and rewritten is about the same, so that the drive will last as long as possible (thus the term wear leveling). As a side effect, sometimes instead of erasing and writing the block a file was originally stored on, the drive will instead leave that block alone, mark it as invalid, and just write the modified file to a different block. This is kind of like leaving the page in the book unchanged, writing the modified file on a different page, and then just updating the book’s table of contents to point to the new page. All of this occurs at a very low level in the electronics of the disk, so the operating system doesn’t even realize it’s happened. This means, however, that even if you try to overwrite a file, there’s no guarantee the drive will actually overwrite it, and that’s why secure deletion with SSDs is so much harder.