Quick answer: A compliant IT asset disposal (ITAD) process must include certified data destruction with a certificate per device, a documented chain of custody from collection to final outcome, recognised third-party accreditation (such as ADISA or R2v3), and full compliance with GDPR and the WEEE Directive. If your current provider or donation route can't produce evidence of all four, your organisation carries the compliance risk — not them.
Every laptop, phone, or server that leaves your office carries two things: hardware value and data risk. The hardware is easy to account for. The data risk is where most businesses — and most well-meaning donation schemes — fall short. This checklist breaks down exactly what to verify before any device leaves your premises.
Improper IT asset disposal isn't a hypothetical risk. It's one of the most common — and most preventable — causes of data exposure:
Responsibility for a data breach doesn't transfer just because a device left your building. If your name is on the asset register, you need to be able to prove what happened to it next.
Use this checklist to assess any ITAD provider, recycler, or donation partner before handing over retired equipment.
Self-declared compliance isn't the same as independently audited compliance. Ask for certificate numbers and audit dates, not just a logo on a website.
Donating retired IT equipment to a charity or social enterprise can be a genuinely good outcome — reuse is better than landfill, and many organisations do valuable work extending a device's life. But donation and data destruction are two separate problems, and most donation routes are built to solve only the first one.
| Certified ITAD Provider | Typical Donation Route | |
|---|---|---|
| Data destruction certificate per device | Yes | Rarely |
| Independently audited (ADISA / R2v3) | Yes | Rarely |
| Documented chain of custody | Yes | Often informal |
| GDPR-compliant erasure process | Yes | Not guaranteed |
| Audit-ready reporting | Yes | Rarely |
| Device gets a second life | Yes, where eligible | Yes |
A device can be reused and be provably, certifiably clean of data — the two aren't a trade-off. But that's only true if the process behind it is built to prove it, in writing.
Is IT asset disposal legally required to be certified in Ireland and the UK? There's no single law that mandates a specific certification. However, GDPR requires organisations to ensure personal data is securely and verifiably destroyed, and the WEEE Directive governs how electronic equipment must be treated at end of life. In practice, working with a certified provider is the only reliable way to demonstrate compliance with both.
What happens if a data breach is traced back to a donated or improperly disposed device? Liability generally stays with the organisation that originally held the data, regardless of who physically disposed of the device. Without a certificate of destruction and a chain of custody, there's no way to prove the data was properly handled — which puts the full weight of a GDPR investigation back on your business.
What's the difference between ADISA and R2v3 certification? ADISA (Asset Disposal & Information Security Alliance) focuses specifically on data security throughout the disposal process, with audited standards up to Distinction level. R2v3 (Responsible Recycling) is a global standard focused on environmentally and socially responsible handling of electronics, including data security requirements. Providers certified to both cover data security and environmental compliance.
Can retired IT equipment be resold as well as securely wiped? Yes. Eligible devices can be data-sanitised to a certified standard, refurbished, and resold through trusted channels — recovering up to 30% of original value while remaining fully compliant. Certified data destruction and value recovery aren't mutually exclusive.
How long should disposal records be kept? This depends on your organisation's data retention policy, but most businesses retain destruction certificates and chain-of-custody records for a minimum of 6–7 years to align with standard audit and regulatory review periods.
What documents should I ask for before handing over old devices? At minimum: a certificate of data destruction per device (or per batch with serial numbers listed), proof of the provider's current accreditations (ADISA, R2v3, Cyber Essentials Plus), and a final disposal report showing the outcome of each asset (resold, recycled, or destroyed).
A compliant IT asset disposal process isn't complicated — but it does need to be provable. If your current disposal or donation route can't produce a certificate of destruction, a chain of custody, and third-party accreditation on request, that's a gap worth closing before your next refresh cycle.