Put the warning before the label

Published September 10, 2026.

Customers need the data warning before they pack or hand over a device. State whether repair or replacement may erase local data, whether the business can access stored content, and which preparation steps are required. Use approved instructions for the exact product.

Separate required and optional steps

Explain backup, account sign-out, activation-lock removal, removable-media removal, and factory reset in the right order. Note when a customer cannot complete a step because the device is damaged. Do not ask for passwords or invite customers to send credentials in a case note.

Confirm that the return authorization identifies the device without displaying unnecessary personal information. Pair this process with a record minimization routine.

The NIST Privacy Framework supplies broader risk context. Connect device handling to the sensitive attachment review.

Record the warning accurately

Log when and how the warning was delivered, which instructions were provided, and any step the customer could not complete. Avoid a checkbox that implies the customer completed actions they only received. Escalate questions about secure handling to the privacy or repair owner.

FAQ

Can an agent guarantee that returned-device data will be deleted?

Only if an approved process provides that guarantee. Otherwise describe the actual handling and retention controls.

What if the device will not turn on?

Record the limitation and follow the secure-return path for inaccessible devices.