The quick answer: it hinges entirely on where the data lives. On a spinning hard drive the answer is no, and not by a narrow margin — the files come straight back with free tools. On an SSD it usually does go, though as a fluke rather than by intent. On a phone it genuinely does. And if you’re about to sell or scrap a device, that distinction is everything.
What a reset wipes is the index, not the data itself. Whether the data lives or dies then depends on the medium: a hard drive holds onto it, flash tends to clear it behind the scenes, and a phone discards the key.
It’s probably the costliest myth in everyday computing — and people bet on it daily.
A factory reset, Windows’ “Reset this PC”, or a quick format all amount to the same move: they strip out the file system’s index and mark the disk as empty. The data stays put. Every file, every picture, every stored password is still on the platters where it was first written, in the very same blocks, and perfectly readable.
Grab any free recovery utility and it lifts straight back off — you don’t need to be an expert, anyone can. An afternoon and no real skill is all it takes; it’s the same routine job as recovering ordinary deleted files. Sold or gave away a laptop with a spinning drive after “wiping” it like that? Whoever received it now holds your files, whether they know it or not.
SSDs are a different story, and the cause is TRIM.
Once a reset or format flags an SSD’s blocks as unused, the drive’s garbage collection wipes those cells for real in the background — frequently within minutes, regardless of what the machine is up to. So the data genuinely disappears, and getting it back really is a long shot.
But be clear on what that is: a by-product of how flash levels out wear, not a security measure. It’s unverified, uncertified, and no basis for a GDPR position. Nothing signals that it finished; nothing evidences that it ran at all. Fine for flogging an old laptop online — not fine for a machine that stored client records.
Modern phones are the outlier — and here the design is sound.
Since today’s iPhones and Android handsets encrypt their storage out of the box, a factory reset ditches the encryption key instead of trying to scrub the data. With no key, the data is mathematically out of reach — the fact that it’s physically still there is irrelevant. That’s a sound approach, and it’s exactly what lets an encrypted laptop be reset safely too.
It’s also the reason we don’t take on phone recovery: it’s a wholly separate craft, and we’d sooner decline the job than handle it poorly.
Hit reset by accident? Whether it returns falls into those same three buckets.
On a spinning hard drive, usually yes — often completely, since the reset only dropped the index. What counts is moving quickly: stop using the drive at once, because any fresh write can land on the blocks still holding your old data. That’s a routine single-drive recovery, from £300 +VAT once we’ve run a free diagnostic. On an SSD, usually not — TRIM has most likely cleared the cells by now. On a phone, no — the key’s already gone. Reset a drive holding something you can’t replace? Switch it off and get a straight diagnostic before another byte is written.
For the ordinary cases, yes — bar a handful of genuine exceptions.
A reset reinstalls the OS and clears the user partition, where the vast bulk of malware sits, so it sees off the everyday infections. The exceptions are worth having in mind: anything lodged in firmware or a hidden recovery partition can ride through a reset, and — the classic way people get reinfected — restoring an infected backup right afterwards simply hands it back. Reset, then rebuild from data you know is clean, and you’re on firm footing. Stubborn or business-critical cases warrant proper virus and malware recovery.
Four scenarios where “I ran a factory reset” doesn’t cut it.
Selling a laptop that has a hard drive? A quick reset won’t do — the disk has to be overwritten properly or physically destroyed. Retiring business kit? UK GDPR requires you to show that personal data was disposed of correctly, and “we ran a factory reset” proves nothing; what you need is a certificate listing the drive serial numbers. Throwing out a failed drive? A disk that won’t boot is not a disk that can’t be read — failed drives are precisely what we recover day in, day out, and so can anyone who fishes one from a skip. Encrypt from day one — the honestly simplest fix: with BitLocker or FileVault on since the machine was new, a reset kills the key and the data goes with it. When disposal has to stand up to scrutiny, our certified data destruction delivers erasure or physical destruction backed by a certificate.
It hinges on the drive fitted. With a mechanical hard drive, no — the reset only takes out the index, and free software brings the files back. With an SSD, usually yes, since TRIM clears the cells in the background. Either way the reset alone is no guarantee of erasure, so don’t lean on it for selling or disposal.
Often, on a hard drive — frequently in full, because the reset only dropped the index. Stop using the drive right away so nothing overwrites the old data, then get a diagnostic; that’s a routine single-drive recovery from £300 +VAT. On an SSD it’s usually lost to TRIM, and on a phone it’s lost with the encryption key.
Yes. Modern phones encrypt their storage by default, so a reset throws away the encryption key rather than scrubbing the data. With no key the data can’t be reached mathematically, which is what makes a reset genuinely work on a phone — unlike on a spinning hard drive.
Usually, for the common cases — the reset reinstalls the OS and clears the partition where most malware lives. What survives is malware buried in firmware or a hidden recovery partition, and restoring an infected backup afterwards, which just reinfects the machine. Reset, then rebuild from data you know is clean.
No. A reset is not a certified wipe — on a hard drive it leaves everything recoverable, and even on an SSD the erasure is an unverified side effect with nothing to confirm it ran. Selling safely or meeting a GDPR disposal duty calls for a verified overwrite or physical destruction, plus a certificate listing the drive serial numbers.
Two dependable routes. Encrypt the drive from day one — with BitLocker or FileVault on from new, a reset discards the key and the data with it — or, for a drive left unencrypted, overwrite it properly or have it physically destroyed. On a mechanical hard drive, a reset by itself is never sufficient.
Clearing out business equipment, or selling a machine that held sensitive data? We’ll wipe or physically destroy the drives and hand you a certificate bearing the serial numbers — the proof a factory reset simply can’t give.