Factory Reset Is Not Enough (But It Nearly Is)
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Selling or handing on a phone raises a reasonable worry: is a factory reset actually enough, or is your data still sitting there for someone with the right tools?
The reassuring answer is that on any reasonably modern phone, a factory reset is genuinely sufficient — for a specific technical reason. The problems people actually run into are different, and more mundane.
Why the reset works
Modern phones encrypt their storage by default. Everything written to the device is stored encrypted, and the key is held in dedicated hardware.
A factory reset does not laboriously overwrite every block. It destroys the encryption key. Without it, the remaining data is indistinguishable from random noise — not "difficult to recover" but mathematically useless. This is why the old advice about overwriting a drive several times, which comes from the era of magnetic hard disks, does not apply here.
The practical caveat is age. Very old devices, or budget models from before storage encryption became standard, may not encrypt by default. If a phone is a decade old, treat the reset as less definitive.
The two steps people actually skip
Neither is about data recovery. Both cause real problems.
Signing out of the account first. Both major platforms link a device to its owner's account so a stolen phone cannot simply be wiped and reused. If you reset without signing out, the phone can remain locked to your account — leaving the buyer with a device they cannot activate, and you with a support conversation. Remove the device from your account before or during the reset, and confirm it is gone from your account's device list afterwards.
Removing the SIM and memory card. Obvious, routinely forgotten. A memory card is separate storage and is often not encrypted at all. It goes with the phone unless you take it out.
The order that avoids trouble
- Back up anything you want to keep, and confirm the backup restores before wiping. A backup you have never tested is a hope.
- Sign out of your account on the device, and turn off the activation-lock feature.
- Remove the SIM and any memory card.
- Factory reset from the settings menu.
- Check your account's device list and remove the phone if it is still listed.
- Unpair accessories — watches and earbuds can stay tied to the old device.
Laptops are a different problem
The same encryption logic applies, but only if encryption was switched on. On phones it is the default; on computers it has often not been.
Before wiping a laptop, check whether full-disk encryption was enabled. If it was, resetting is equally effective. If it was not, the data is written in the clear and a plain reinstall may leave much of it recoverable — that is the case where a secure-erase tool, or the drive manufacturer's own secure-erase command, is worth using.
For a solid-state drive, prefer the built-in secure-erase function over repeated overwriting. Overwriting a modern SSD is both slower and less reliable than the command the drive provides.
The mistake that locks you out of your own life
There is one failure here that is far more common than any data-recovery scenario, and far more painful.
If you use an authenticator app for two-factor codes, those codes live on that phone. Some authenticator apps sync to an account and reappear on a new device. Others deliberately do not, because storing them in the cloud is the thing they were designed to avoid.
Wipe the phone without migrating them and you have destroyed the second factor for every account that used it. Your password is still correct and still useless. Recovery then depends on backup codes you probably did not print, or on a support process that can take days and sometimes fails outright — and it fails hardest on exactly the accounts you care most about.
So before any reset:
- Move your authenticator to the new device first, using the app's own transfer or export process, and confirm a code works on the new phone before wiping the old one.
- Print or write down backup codes for your most important accounts, and keep them somewhere physical.
- Check for any account that texts codes to a number you are also changing, which produces the same lockout by a different route.
- Check what else only exists on the device — a payment wallet, transit passes, car keys, a work security app, offline notes never synced anywhere.
This step has nothing to do with the buyer and everything to do with you. It is the one people skip, and it is the one that ruins a week.
The activation-lock trap, from both sides
Both major platforms tie a device to its owner's account so that a stolen phone cannot simply be wiped and sold. The feature works, which is precisely why it causes trouble.
As a seller, resetting without signing out can leave the phone demanding your account credentials on first setup. The buyer cannot use it. You now have to prove ownership at a distance to a stranger, or accept the return. Worse, if you sold through a marketplace, you may be dealing with a dispute while the device is in someone else's hands.
As a buyer, this is the single check that matters most on a second-hand phone. Insist on seeing it powered on and taken through the initial setup screens, or at minimum out of the previous owner's account, before money changes hands. A phone that reaches a screen asking for someone else's account details is worth nothing and cannot be fixed by you. Sellers acting in good faith will not mind demonstrating it.
The safe order is: sign out of the account and disable the activation-lock feature while the phone still works, then reset, then confirm on your account's website that the device no longer appears in your device list. That last confirmation is the part that turns a hopeful assumption into a fact.
The counter-argument on trade-in programmes
Manufacturer and network trade-in schemes handle the wipe for you, which sounds like it removes the whole problem.
They usually do a proper job — the process is automated and the incentive to get it right is commercial. The catch is that you are handing over an unwiped device and trusting a chain of logistics with it, and the value offered is frequently lower than a private sale.
The reasonable position is that a trade-in is fine, provided you still do the parts that only you can do: sign out of your account, remove the device from your device list, move your authenticator, remove the SIM and memory card. Then the wipe itself is genuinely their problem. What you should not do is treat "they will wipe it" as covering the account and lockout issues, because it does not touch them.
If the device holds material you would not be relaxed about a stranger handling — work files, medical records, someone else's private information — do the reset yourself first anyway. It costs ten minutes and removes the trust question entirely.
When the device is broken
If the screen is dead and you cannot reach the settings menu, you cannot sign out or reset. If it was encrypted and you never disabled the lock screen, the data is already protected — but the activation lock will still be tied to your account, so remove the device from your account list through the platform's website.
If the device is genuinely at end of life and holds anything sensitive, physical destruction of the storage is the certain answer. Many local recycling centres handle this, and it is the one situation where the crude solution is the correct one.
Where this fits
The reason a reset is enough on a phone and often is not on a laptop comes down to encryption, and that logic is worth understanding once — deleting a file does not delete the file covers why full-disk encryption solves deletion, loss and disposal all at the same time. Before you wipe anything, back up your data and test that the backup restores. And if the phone is going because it was lost rather than replaced, what to do after a data breach covers the account cleanup that follows. The backup and encryption tools all of this depends on are compared in the security tool finder.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Continue reading
privacy
Give Every Company a Different Email Address
One address per service sounds like admin overhead. It takes seconds, kills spam at the source, and tells you exactly who leaked your data.
privacy
You Blocked the Cookies. They Still Know It Is You.
Fingerprinting identifies you from your browser configuration alone — no cookie, nothing stored. What it reads, why blocking it is harder than it sounds, and what genuinely helps.
guides
Small Business Security 2026: What Consumer Antivirus Misses
Consumer antivirus protects a laptop. A company also has to protect what its own people can copy or screenshot, and verify that the person it just hired is real.
