Tech-for-good · London

How to Dispose of an Old Laptop: Data First, Then Recycling

Before you dispose of an old laptop, wipe the storage drive completely — not just with a factory reset. Laptops hold months or years of personal and business data that standard deletion leaves recoverable. Once the data is destroyed, certified WEEE recycling or a reuse donation is the legal and responsible next step under the WEEE Regulations 2013.

Business tech → someone's new start

Certified data destruction
WEEE-registered
Fully insured
Proudly London

One problem on each side. One simple loop.

The UK throws away around 1.65 million tonnes of electronic waste a year — the fastest-growing waste stream. At the same time, up to 19 million adults live in digital poverty, without the device they need to work, learn or stay connected.

Too much waste

Working devices stockpiled or sent to landfill, while their value and materials are lost.

Too little access

Millions can't afford a device to get online, find work, or reach health and public services.

Recycle4Charity closes the loop: redundant business tech becomes someone's new beginning.

For business

Compliant, certified IT disposal with zero hassle — and a social-impact report you can use.

For people

Free, refurbished devices for digitally-excluded Londoners, through trusted local partners.

For the planet

Every device reused or responsibly recycled. Less landfill, lower carbon.

How it works

1

Book a collection

Tell us roughly what you have.

2

We collect & log

We pick up and record every asset.

3

Certified data wipe

Secure destruction + a certificate.

4

Refurbish & rehome

Reuse what we can, recycle the rest.

5

Your impact report

Proof of where it all went.

Our impact so far

0
Devices rehomed
0
People connected
0
E-waste diverted
0
CO₂ saved

Launching 2026 — numbers update as we grow.

Frequently asked questions

A factory reset alone is not sufficient if the laptop was not fully encrypted. It removes the operating system's record of files but does not overwrite the underlying data. Use certified overwrite software or arrange physical destruction of the drive.

You should retain a Waste Transfer Note (required by law for any transfer of controlled waste) and a data destruction certificate for each device. Both should be kept for at least two years.

No. Laptops are classified as WEEE and cannot go in any general or recycling waste stream, commercial or domestic. Doing so is an offence under the WEEE Regulations 2013.

Physical shredding of the storage drive provides the highest level of assurance, particularly for failed or encrypted-with-lost-key drives. Certified software overwrite is the standard method for functioning drives and is adequate for most business requirements.

Under UK GDPR, the data controller (your organisation) remains responsible for personal data until it is demonstrably destroyed. Handing an unwiped laptop to a recycler or charity does not transfer or extinguish this responsibility.

Upgrading your office IT?

Turn your old kit into compliance, ESG impact and digital opportunity for someone who needs it.

Why disposal of a laptop is not straightforward

Laptops combine two obligations that often catch businesses off guard: data security and environmental compliance. Get either wrong and the consequences range from ICO enforcement to Environment Agency penalties.

This guide works through both, in the correct order: data destruction first, then disposal.

Step one: secure data destruction

What is at risk on a laptop drive?

A typical laptop used for work or personal tasks may contain:
– Emails, contracts, and financial records
– Saved passwords and browser autofill data
– HR files, client details, or health information
– Login credentials cached in applications

Standard file deletion marks a file’s storage space as available for reuse but leaves the data intact until overwritten. A factory reset typically deletes the file allocation table rather than the underlying data. In both cases, freely available recovery software can restore files.

Methods for secure laptop data wiping

Certified software overwrite
This is the method of choice for drives that are still functioning. Software meeting HMG Infosec Standard 5 or NIST 800-88 makes multiple overwrite passes across every storage sector. At the end of the process, a certified ITAD provider issues a data destruction certificate naming the device’s serial number and confirming the erasure standard applied.

Factory reset with full-disk encryption
Modern laptops with full-disk encryption enabled (BitLocker on Windows, FileVault on macOS) can achieve an acceptable security level through a factory reset combined with destruction of the encryption key. This is less reliable on older machines, or those that were not encrypted for their entire working life.

Physical destruction (shredding)
Where a drive has failed or cannot be wiped by software, physical destruction is the definitive method. The drive is shredded to a particle size that makes data recovery impossible. A destruction certificate is issued for each device.

Under UK GDPR and the Data Protection Act 2018, organisations must be able to demonstrate that personal data has been destroyed. A data destruction certificate is the standard way to evidence this. The ICO has emphasised that passing a device to a third party without confirmed data destruction does not end the data controller’s liability.

For a detailed explanation of these methods, see our guide on what data destruction means.

Step two: dispose of the laptop legally

Once data has been dealt with, the laptop must be disposed of through a lawful route. The WEEE Regulations 2013 classify laptops as Waste Electrical and Electronic Equipment. This means:

  • They cannot go in general commercial or household waste.
  • They cannot go in office or kerbside recycling bins.
  • They must be transferred to an authorised WEEE treatment facility, with a Waste Transfer Note issued and retained by the business for at least two years.

Your disposal options compared

Route Data destruction included WEEE compliant Documentation Suitable for businesses?
Certified ITAD provider Yes (certificate issued) Yes Waste Transfer Note + destruction cert Yes
Manufacturer take-back Sometimes Yes Variable Sometimes
Council HWRC No Yes No No (household only)
In-store retailer take-back No Yes No No
General waste No No — illegal None No

Certified IT asset disposal (ITAD)

A certified ITAD provider collects laptops from your premises, wipes or destroys the drives, and either refurbishes the devices for reuse or processes the materials through licensed WEEE streams. For London businesses, Recycle4Charity provides this service free of charge for qualifying volumes, with full documentation.

Working laptops collected by Recycle4Charity are refurbished and donated to digitally-excluded Londoners, giving devices a meaningful second life before materials are eventually recovered. Our laptop recycling service for London businesses covers all London boroughs.

Donation

If your laptop is still functional, donation to a verified reuse scheme is preferable to recycling — the waste hierarchy in UK law prioritises reuse. The drive must still be wiped to certified standards before the device leaves your organisation. Do not assume a charity will handle this; confirm the process before handing over equipment.

Council Household Waste Recycling Centres

These are available to householders but not to businesses. They do not offer data destruction. Individual members of the public can use them for personal laptops after wiping their own devices.

What about the laptop battery and charger?

Both are WEEE. Laptop batteries are also subject to the UK Battery Regulations 2008 and must not enter general waste. Pass them to your ITAD provider together with the laptop, or use a dedicated battery drop-off point.

For more on battery disposal, see our article on how to recycle batteries from old devices.

Checklist before your laptop leaves the building

  • Data backed up to new device or secure storage
  • All accounts signed out (email, cloud, software licences deauthorised)
  • Drive wiped to certified standard or arranged for on-collection wiping
  • Data destruction certificate requested
  • Waste Transfer Note requested from recycler
  • Documentation filed for minimum two years

Ready to dispose of your business laptops?

Book a free collection with Recycle4Charity across London. We provide certified data destruction, a Waste Transfer Note, and a certificate of recycling or reuse. Visit our laptop recycling page to get started.

Why server disposal carries the highest data risk

A single server may contain terabytes of data across multiple hard drives or SSDs. Unlike a laptop or phone, a server’s storage is typically partitioned across a RAID array, which means data may be spread across drives in non-obvious ways. Simply wiping individual drives within a RAID may not remove all data unless the array is first broken down and each drive wiped individually.

Server types that require particular care include:
File servers — may hold years of staff files, HR records, financial documents
Database servers — may contain customer records, transaction histories, health data
Mail servers — may hold personal communications covered by UK GDPR
Backup servers and NAS devices — may hold copies of data from across the organisation, sometimes including data long since deleted from primary systems
Virtualisation hosts — may contain virtual machine images including guest operating systems and their data

Under UK GDPR and the Data Protection Act 2018, organisations must implement appropriate technical measures to protect personal data. The Information Commissioner’s Office (ICO) is clear that disposal of equipment containing personal data without confirmed destruction is a breach of these obligations. For context on your legal position, see our article on UK GDPR and old IT equipment.

Data destruction methods for servers

Certified software overwrite

The industry standard for functioning drives is software overwrite meeting NIST 800-88 (Guidelines for Media Sanitisation) or HMG Infosec Standard 5. For servers with multiple drives, each drive must be individually overwritten. The output is a certificate naming each drive by serial number and confirming the erasure standard and date.

Degaussing

A degausser applies a powerful magnetic field that destroys the magnetic domains storing data on HDDs and magnetic tapes. It is fast and reliable for hard disk drives but has no effect on SSDs (which use flash memory, not magnetic storage). Degaussed drives are permanently destroyed and cannot be reused.

Physical shredding

The most definitive method. Drives are fed through an industrial shredder and reduced to fragments below a specified particle size (typically 15mm or less for HDDs, smaller for SSDs). Certificates are issued listing each drive by serial number and confirming the shred particle size. This is the preferred method for end-of-life drives or drives that cannot be wiped by software.

On-site destruction

Where data sensitivity requires it, a certified provider can bring destruction equipment to your premises and destroy drives under your supervision. The certificate is issued on the spot. This eliminates the risk of data exposure during transit.

Chain of custody: why it matters

Chain of custody documentation traces each device from the moment it leaves your custody to confirmed destruction. For server disposal, this typically includes:

  1. Asset inventory — make, model, serial number, drive serial numbers, asset tag
  2. Collection manifest — signed by both your representative and the collection driver
  3. Waste Transfer Note — legally required for any transfer of controlled waste
  4. Data destruction certificate — for each drive, listing serial number, method, and standard applied
  5. Certificate of recycling or reuse — confirming the server chassis has entered a compliant WEEE stream

Keep all documentation for a minimum of two years. In the event of a regulatory enquiry or ICO investigation, this paperwork demonstrates due diligence.

Are servers classified as WEEE?

Yes. Servers, rack-mounted equipment, blade systems, storage arrays, and network infrastructure (switches, routers, firewalls) are all WEEE under the WEEE Regulations 2013. Businesses must not place this equipment in commercial waste. A Waste Transfer Note is required for every collection.

Preparing your server for disposal: a checklist

  • Document all devices: make, model, serial number, drive configuration
  • Back up any data still needed to a separate, secure system
  • Notify relevant teams: IT, legal, compliance, finance (for asset deregistration)
  • Decommission the server in your CMDB (Configuration Management Database) or asset register
  • Remove the server from rack infrastructure
  • Arrange certified data destruction (on-site or at a licensed facility)
  • Obtain data destruction certificate for each drive
  • Arrange WEEE collection with a certified ITAD provider
  • Obtain Waste Transfer Note and certificate of recycling
  • File all documentation

Can a decommissioned server be reused?

Where a server is relatively recent and in working order, reuse is preferable to recycling under the waste hierarchy. However, security requirements mean that business-grade server equipment is rarely suitable for direct donation — drives must first be destroyed. Refurbishers may install new drives and repurpose the chassis.

Recycle4Charity handles server disposals for London businesses, with certified data destruction for each drive and full WEEE compliance documentation. Visit our server recycling service page for more information.

What happens to a recycled server?

Server chassis are predominantly steel and aluminium, both of which have high recycling value. Circuit boards — including CPUs, memory modules, and network cards — are sent to specialist e-waste processors for precious metal recovery. Drives that have been shredded are processed for raw material recovery. Cables and power supplies are processed through separate WEEE streams.

Ready to dispose of your servers?

Recycle4Charity provides secure server disposal for London businesses, including certified data destruction, full chain of custody documentation, and WEEE-compliant processing. Contact us via our server recycling page to discuss your requirements.

Why SSDs are different from hard drives

A traditional hard drive stores data as magnetic patterns on spinning platters. Overwriting those patterns with new data — or demagnetising the platters with a degausser — destroys the original data. An SSD stores data in NAND flash memory cells. There are no magnetic fields, no platters, and no heads.

This difference has three important implications for data destruction:

Degaussing is useless. A degausser generates a magnetic field. NAND flash memory has no magnetic properties to disrupt. Running an SSD through a degausser has zero effect on the data it contains. The drive emerges intact, data fully readable. Any organisation that degausses SSDs believing this constitutes data destruction is not protected.

Standard overwrite tools may not reach all data. Because SSDs use a technique called wear levelling — distributing writes across all flash cells to extend the drive’s life — a conventional overwrite command may not address every cell that has held data. Over-provisioned cells (spare capacity maintained by the drive’s firmware) may be inaccessible to host-level write commands.

Specific firmware commands are required for reliable software sanitisation. The ATA Secure Erase command (for SATA SSDs) and the NVMe Sanitise command (for NVMe drives) instruct the drive’s own firmware to cryptographically or physically erase all cells, including over-provisioned areas. These are the correct software-based methods for SSD data destruction.

Method 1: ATA Secure Erase or NVMe Sanitise

For SSDs that will be reused or donated, firmware-level commands are the appropriate method. The process works as follows:

  1. Check compatibility: Confirm that the SSD supports ATA Secure Erase (SATA drives) or NVMe Sanitise (NVMe M.2 drives). Most modern SSDs do, but older or budget models may not. Consult the manufacturer’s documentation.

  2. Use certified software: Tools such as Blancco Drive Eraser and similar enterprise-grade products support these commands and produce a per-drive verification report. The report confirms that the command completed successfully and is the evidence needed for a certificate of data destruction.

  3. Verify completion: The tool should confirm that the Secure Erase or Sanitise command was accepted by the drive and completed without errors. A failed or unsupported command must be treated as incomplete — the drive should then be physically shredded.

  4. Document the result: The verification report should record the drive make, model, serial number, firmware version, the command issued, and the outcome. This feeds into the certificate of data destruction.

Note that NIST Special Publication 800-88 (“Guidelines for Media Sanitisation”) addresses flash-based media and recommends Secure Erase or Sanitise commands for the “purge” level of sanitisation.

Method 2: Encryption then wipe

Some SSD manufacturers implement hardware-based encryption that encrypts all data on the drive at rest. Cryptographic erase — destroying the encryption key — renders all data permanently unreadable because the ciphertext cannot be decrypted without the key.

Where a drive supports this (known as a Self-Encrypting Drive, or SED), the process is to enable encryption from the outset and then issue a cryptographic erase command at disposal. NIST SP 800-88 accepts cryptographic erase as a “purge”-level method for supported drives.

This method requires planning ahead: the drive must have been operating in encrypted mode from the start. An SSD that was not encrypted during use cannot be retrospectively made secure by enabling encryption — the existing data was written in plaintext.

Method 3: Physical shredding

Where certified software sanitisation cannot be confirmed — because the drive does not support the required commands, the firmware is unresponsive, or the drive is faulty — physical shredding is the reliable alternative.

Industrial shredders reduce the SSD to fragments that destroy the NAND flash chips. Once shredded, data recovery is not possible regardless of what data was present or how it was stored. Shredding is also the right choice when:

  • The SSD is at end of life and has no residual value
  • The data held was of the highest sensitivity
  • The device type is a smartphone, tablet, or other device where the storage is integral and firmware-level commands are not accessible
  • You need absolute certainty without reliance on firmware behaviour

For more on shredding as a method, see our guide to hard drive shredding explained.

What does not work on SSDs

The following methods are commonly misunderstood or misapplied to SSDs and should not be relied upon:

  • Degaussing: Has no effect on NAND flash memory. Zero protection.
  • Standard disk overwrite (e.g. DoD 5220.22-M applied to SSDs via host-level writes): May not reach all storage cells due to wear levelling and over-provisioned areas.
  • Factory reset: A factory reset on a laptop or phone does not constitute a secure wipe of the SSD. It removes the operating system’s access to the data but does not overwrite or sanitise the flash cells.
  • Drilling or hammering: Damaging one area of an SSD does not destroy the flash chips elsewhere. Data recovery laboratories can retrieve data from physically damaged SSDs.

UK GDPR obligations

Under UK GDPR and the Data Protection Act 2018, personal data held on an SSD must be destroyed securely when it is no longer needed. The method must be appropriate to the device type and the sensitivity of the data, and destruction must be evidenced by a certificate of data destruction.

The ICO does not prescribe specific technical methods, but it expects organisations to follow recognised standards. For SSDs, that means either certified firmware-level sanitisation or physical shredding.

Recycle4Charity provides certified SSD data destruction for London businesses — using certified software tools where supported or physical shredding where not — and issues a certificate of data destruction with every collection. Visit our hard drive and media destruction page, or contact us to arrange a collection.

Why the choice of ITAD company matters

Selecting the wrong ITAD company is not merely an inconvenience — it can expose your organisation to regulatory enforcement. Under UK GDPR and the Data Protection Act 2018, you remain legally responsible for personal data on retired devices until you can prove it has been destroyed. If an unqualified provider fails to wipe a hard drive and that data later resurfaces, the ICO may hold your organisation accountable, not the provider.

Similarly, under the WEEE Regulations 2013, your duty of care for waste electrical and electronic equipment does not end when a carrier collects it. If that carrier is not properly licensed, your organisation may face enforcement from the Environment Agency.

Choosing a properly certified ITAD company is the only way to transfer these risks effectively. For background on what the service covers, see our guide on what ITAD is and how it works.

What certifications should an ITAD company hold?

These are the credentials to verify before signing a contract with any UK ITAD provider:

Certification / Registration Issuing body What it confirms
Environment Agency waste carrier licence Environment Agency Legal authority to transport WEEE on public roads
Authorised Treatment Facility (AATF) status Environment Agency Permission to process WEEE at their facility
ADISA certification Asset Disposal and Information Security Alliance Independently audited data destruction processes
ISO 27001 BSI / accredited certification body Information security management system
ISO 14001 BSI / accredited certification body Environmental management system
ICO registration (data processor) Information Commissioner’s Office Registered to process personal data on your behalf

You can verify Environment Agency permits through the public register on gov.uk. ADISA certification can be confirmed on the ADISA website. ICO registration is searchable at ico.org.uk/ESDWebPages/Search.

Do not accept a provider’s assurances at face value. Ask to see their licence numbers and check them.

What questions should you ask a prospective ITAD company?

Before committing, put these questions to any provider:

On data destruction:
– What standards do you use for data wiping (NIST 800-88, HMG Infosec Standard 5)?
– Do you issue individual data destruction certificates per device?
– What happens to drives that cannot be wiped — are they physically shredded on-site or off-site?

On chain of custody:
– How do you log assets from collection to final destination?
– Will I receive a manifest of every device collected, including serial numbers?

On recycling:
– Which authorised treatment facilities do you use?
– Do you supply a waste transfer note as required under the Environmental Protection Act 1990?

On resale:
– If devices are remarketed, how do you ensure data has been wiped before resale?
– Do I receive any financial return from devices that are sold?

On social impact:
– Do you offer donation pathways for functional devices?

What red flags should you watch for?

Be cautious of ITAD companies that:

  • Cannot provide a valid Environment Agency waste carrier licence number
  • Offer data destruction without issuing certificates
  • Are unwilling to disclose which recycling facilities they use
  • Promise collection “for free” with no explanation of where revenue comes from — devices may be resold without proper data wiping
  • Lack any ISO or ADISA certification for data security

A provider that cannot answer questions about their certifications transparently is not a provider you should trust with your data.

Should you choose a local or national ITAD company?

Both can be appropriate, depending on your needs.

A national provider may be preferable for multi-site or high-volume projects, where scale and logistics infrastructure matter. A London-based provider such as Recycle4Charity will typically offer faster response times for London offices and a more personal account relationship. Local providers also often have stronger community ties — our refurbishment programme gives devices to digitally-excluded Londoners, which is something a large national operation rarely does.

For smaller businesses with a single office, a local certified provider is often the most cost-effective and responsive option. Read our guide on secure IT disposal for small businesses for considerations specific to smaller organisations.

How to compare quotes from ITAD companies

When comparing proposals, look beyond the headline price. Ask each provider to break down:

  • Collection and logistics costs
  • Data destruction costs (per device or per project)
  • Resale credit or revenue share on remarketed devices
  • Recycling fees for non-resaleable equipment
  • Certification and reporting costs

A provider offering a very low price may be cutting corners on data destruction, using unlicensed recycling routes, or reselling devices without adequate wiping. Our guide to IT asset disposal costs in the UK explains what drives pricing and what a reasonable fee structure looks like.

Ready to choose?

Recycle4Charity operates across London and the South East, holds the relevant certifications and publishes its processes transparently. We give every reusable device a second life in the community before anything is recycled. Visit our business services page to request a quote or arrange a collection.

Why manufacturing is the biggest carbon event in a device’s life

To understand why IT reuse cuts carbon, it helps to understand where carbon comes from in a device’s lifecycle.

A laptop, for instance, accumulates greenhouse gas emissions at three stages: manufacturing, use, and end of life. Of these, manufacturing is consistently the most carbon-intensive phase.

Manufacturing a laptop requires extracting and refining metals including aluminium, copper, cobalt, and rare earth elements. It requires fabricating semiconductors — a process that demands vast amounts of ultra-pure water, specialty chemicals, and energy. It requires assembling hundreds of components, sourced from supply chains spanning multiple continents, into a finished product. Each of those steps has a carbon cost.

Research from manufacturers and independent lifecycle analysis studies suggests that, for a typical laptop, up to 80% of total lifetime carbon emissions occur before the device reaches the customer. (Source: Apple Environmental Progress Reports and independent lifecycle assessments; figures vary by device type and manufacturer.)

This has a crucial implication: every time a working device is discarded and replaced with a new one, a fresh carbon debt is created — regardless of how “green” the replacement device is marketed to be.

What carbon savings does reuse deliver?

If manufacturing represents the majority of a device’s lifetime carbon, then avoiding a new manufacture is the most effective carbon intervention available.

When a device is refurbished and reused, it displaces the need for a new device. The carbon saving is equivalent to the embodied carbon of the device that was not manufactured. This saving is direct, measurable, and immediate.

Compare this with recycling. Certified WEEE recycling is valuable — it recovers metals and reduces demand for virgin material extraction. But it does not preserve the device as a device. The embodied carbon already invested in assembling it is effectively lost. Recycling recovers some of the material value but none of the manufacturing value.

This is why the waste hierarchy places reuse above recycling. It is not an arbitrary ordering — it reflects the relative carbon benefit of each intervention. Reuse first; recycle only when reuse is no longer possible.

The carbon saving from reusing a single laptop is estimated at 300–400 kg CO₂ equivalent for a typical business laptop, compared with manufacturing a new device. (Source: lifecycle assessment studies; Recycle4Charity uses verified data where available.) Across a fleet of 50, 100, or 500 devices, this adds up to figures that are material to a corporate carbon inventory.

How does IT reuse affect Scope 3 emissions?

For organisations reporting under the Greenhouse Gas (GHG) Protocol — as required for many listed companies and recommended for all serious net zero commitments — IT equipment disposal falls under Scope 3 emissions. Specifically, it appears under Category 5: Waste generated in operations, and potentially Category 12: End-of-life treatment of sold products (for manufacturers).

Scope 3 is typically the largest component of a corporate carbon footprint — often 70% or more of total emissions — and historically the hardest to address. IT asset management is one of the areas where organisations can make a documented, third-party-verified difference.

When a business sends its retired devices to a certified ITAD provider who prioritises refurbishment, those devices — and the carbon embedded in them — remain in circulation. The Scope 3 emissions associated with disposal are replaced by documented impact: devices donated, CO₂ avoided, waste diverted.

This documentation matters. As Scope 3 disclosure becomes more common — driven by the Task Force on Climate-related Financial Disclosures (TCFD) framework and incoming ISSB standards — companies need to be able to demonstrate the outcomes of their waste and disposal decisions, not just describe their intentions.

How Recycle4Charity’s model maximises carbon savings

At Recycle4Charity, every device collected from a London business follows a consistent process designed to maximise its useful life and the carbon benefit of its disposal.

Collection and assessment: devices are collected from business premises, with collection logistics arranged end to end.

Secure data destruction: all data is destroyed to recognised standards before any device is assessed for reuse. Certificates of data destruction are issued for every asset.

Refurbishment: devices that are functional — or can be made functional — are cleaned, tested, and prepared for reuse. This is the stage that delivers the greatest carbon saving: the device remains a device.

Donation: refurbished devices are donated free of charge to digitally excluded Londoners through our network of partner schools, charities, and community organisations. The device gets a second life. The recipient gets technology they could not otherwise afford.

Certified recycling: devices that cannot be refurbished are sent to certified WEEE recycling partners. No device goes to landfill.

The impact of this process — in devices donated, kg diverted, and CO₂ avoided — is documented and reported. Businesses receive an impact summary that can be used directly in ESG reporting.

To see the full picture of what IT reuse achieves environmentally and socially, visit our impact page. And to understand the broader carbon story of e-waste, read our article on the carbon footprint of e-waste.


Every device you hand to us is a carbon saving in the making. Book a collection and we’ll do the rest.

How hard drive shredding works

An industrial hard drive shredder is not a paper shredder scaled up. It uses hardened cutting blades or rotary hammers to tear apart the drive casing, platters, circuit boards, and any flash memory chips into small, irregular fragments. The fragments are typically collected in a secure container, audited by weight or count, and then separated by material type for recycling as raw metals and plastics.

The security assurance of shredding is determined by the particle size: the smaller the fragments, the harder data recovery becomes. Industrial ITAD shredders typically produce fragments of between 6 mm and 20 mm, depending on the machine and the settings used. Security-critical applications may require smaller particle sizes — HMG IA Policy No.5, which governs the destruction of UK government-classified information, specifies maximum particle dimensions by classification level.

Once shredded, no data recovery technique — including laboratory-level forensic analysis — can reconstruct the original data.

Which devices can be shredded?

Physical shredding works on all types of storage media, including:

  • Traditional magnetic hard drives (HDDs)
  • Solid-state drives (SSDs)
  • USB flash drives
  • Backup tapes
  • Optical media (CDs, DVDs, Blu-ray discs)
  • Smartphones and tablets (where the storage chip is integral to the device)
  • Memory cards and microSD cards

This universality is one of shredding’s key advantages. Where software wiping may not be suitable — for example, on certain SSDs with non-standard firmware, or drives with bad sectors — shredding provides reliable destruction regardless of the device’s internal architecture.

For SSDs in particular, degaussing is not effective because SSDs store data using flash memory, not magnetic fields. Shredding is the recommended alternative when certified software wiping cannot be confirmed. See our guide to how to destroy an SSD for more detail.

When is shredding the right choice?

Shredding is the appropriate method in several situations:

  • Highest sensitivity data: Where drives have held personally sensitive data (health records, legal files, financial data classified under sector regulation), the absolute certainty of physical destruction may be required or preferred.
  • Drives with faults: A drive with bad sectors or firmware issues may not respond correctly to software wiping tools. Verification failures mean the wipe cannot be confirmed — shredding removes the uncertainty.
  • No residual value: Drives that are too old, too small, or too damaged to be refurbished have no economic reason to be preserved. Shredding is appropriate when there is nothing to gain from wiping.
  • Government and regulated sectors: Public sector organisations and businesses handling data classified under HMG IA Policy No.5, or subject to sector-specific regulation, may be required to use physical destruction for certain asset types.
  • SSD disposal without certified wiping tools: If you cannot confirm that your wiping software fully supports the specific SSD model and firmware, shredding is the safer option.

When is shredding not the right choice?

Shredding destroys the device entirely, so it is not appropriate if the drive is to be reused, refurbished, or donated. A drive in good working condition that holds personal data can be certified-wiped and returned to service. Shredding a working drive removes that option.

For devices that will be reused, certified software wiping to NIST SP 800-88 standard is the preferred route. See our guide to how to wipe a hard drive for step-by-step guidance.

On-site vs off-site shredding

Hard drive shredding can be carried out on your premises (on-site) or at a secure facility operated by an ITAD provider (off-site).

On-site shredding uses a mobile shredder brought to your location. You witness the destruction directly, which provides immediate assurance and eliminates the chain-of-custody risk of transporting unshredded drives. It is the preferred option for organisations with very high sensitivity requirements or large volumes.

Off-site shredding involves drives being collected in locked, tamper-evident containers and transported to a secure facility for shredding. A documented chain of custody records the transfer. Off-site shredding is more practical for smaller volumes and lower-sensitivity situations, and it allows the ITAD provider to use high-capacity industrial equipment rather than a mobile unit.

Both options should result in a certificate of data destruction and a WEEE-compliant recycling route for the shredded material.

What happens to shredded material?

Shredded hard drives are not simply discarded. The fragments — a mixture of aluminium, steel, copper, circuit board material, and glass platters — are sorted by material type and sent to specialist recycling facilities. Metals are smelted and reused as raw materials. This process complies with the WEEE Regulations 2013, which require electronic waste to be processed through an authorised treatment facility rather than sent to landfill.

Documentation and compliance

Shredding must be evidenced. For every collection, your ITAD provider should issue a certificate of data destruction that records:

  • The serial numbers and asset identifiers of every drive shredded
  • The destruction method (physical shredding) and the particle size achieved
  • The date of destruction
  • The name and contact details of the provider
  • A statement confirming WEEE-compliant disposal of residual material

This certificate is your evidence of compliance with UK GDPR’s accountability principle. Keep it alongside your IT asset register.

Recycle4Charity provides certified hard drive shredding for London businesses, with a certificate of data destruction issued for every collection. Visit our hard drive and media destruction page to learn more, or contact us to arrange a collection.

Why Healthcare Data Requires Special Attention

Health data is classified as special category data under UK GDPR Article 9. Processing it requires not only a lawful basis under Article 6 but also a separate condition under Article 9 — and healthcare organisations must identify and document both. The elevated status of health data reflects the serious and lasting harm that its unauthorised disclosure can cause: discrimination, distress, damaged relationships and loss of employment.

For IT disposal, the practical consequence is that any device that has ever stored or processed health records must be treated with the highest level of care. This includes clinical workstations, servers running patient management systems, tablets used for ward rounds, diagnostic equipment with digital outputs, and printers or photocopiers used to handle patient correspondence.

NHS DSP Toolkit Requirements

For NHS organisations and their suppliers, the Data Security and Protection (DSP) Toolkit sets out the minimum information governance standards expected. Published by NHS England and accessible via dsptoolkit.nhs.uk, the DSP Toolkit covers ten data security standards, several of which bear directly on IT asset disposal:

  • Standard 1 (Personal confidential data) requires that personal data is only accessible to staff who need it, and that it is not retained longer than necessary
  • Standard 9 (Unsupported systems) requires that systems no longer receiving security support are removed from use
  • Standard 10 (IT protection) requires that devices are securely decommissioned

NHS organisations must attest annually to compliance with all ten standards. Failure to meet the DSP Toolkit standards can affect CQC ratings, NHS contract compliance and access to NHS systems. For IT disposal specifically, the Toolkit expects that end-of-life devices are disposed of through a process that ensures data cannot be recovered.

Special Category Data and the Disposal Obligation

Under UK GDPR, health data is special category data. The storage limitation principle (Article 5(1)(e)) requires that it be erased when no longer needed. The security principle (Article 5(1)(f)) requires that when it is erased, erasure is done securely. The accountability principle (Article 5(2)) requires that the organisation can demonstrate both.

For healthcare IT disposal, this means:

Device type Disposal requirement
Clinical workstations Certified data wiping or physical drive destruction
Servers (patient management, EHR systems) Physical destruction of drives or certified wiping to NIST 800-88 or equivalent
Tablets and mobile devices Certified factory reset to manufacturer standard or physical destruction
Diagnostic equipment with digital storage Manufacturer-advised secure wipe; physical destruction where not possible
Printers and photocopiers Internal drive removed and destroyed; or certified third-party disposal
Backup tapes and removable media Degaussing or physical shredding

Healthcare organisations that return leased equipment — particularly photocopiers and print management devices — without clearing internal storage have a well-documented history of inadvertently exposing patient correspondence. This risk must be addressed contractually with the leasing company and operationally at the point of return.

Data Protection Officers and Governance in Healthcare

Most healthcare organisations are required to appoint a Data Protection Officer (DPO) under UK GDPR Article 37, because they process special category health data on a large scale. The DPO is responsible for advising on data protection obligations, monitoring compliance and acting as the first point of contact with the ICO.

In the context of IT disposal, the DPO should:

  • approve or specify the disposal procedure for end-of-life clinical and administrative devices
  • ensure that certificates of data destruction are obtained and retained
  • review the organisation’s data retention schedule to ensure disposal triggers are set correctly
  • liaise with IT and procurement to ensure that supplier contracts include data security obligations

The Role of the ICO in Healthcare Data Protection

The ICO enforces UK GDPR in healthcare as in every other sector. The NHS and healthcare providers are not exempt from investigation or fines. The ICO has previously taken action against healthcare organisations following incidents involving improperly disposed equipment, misdirected correspondence and data left on returned devices.

Healthcare organisations should treat an ICO investigation as a realistic possibility following any significant IT disposal incident, and ensure that their disposal records are comprehensive enough to demonstrate what steps were taken.

Supplier Obligations and Data Processing Agreements

Where a healthcare organisation engages a third-party ITAD (IT asset disposal) provider, a data processing agreement (DPA) must be in place under UK GDPR Article 28. This agreement must specify the nature of the processing, the purpose, the type of personal data involved, and the obligations of the processor — including the requirement to destroy data securely and to assist the controller in demonstrating compliance.

Healthcare organisations should not engage ITAD providers that cannot demonstrate the necessary security controls or that are unwilling to sign a data processing agreement and provide certificates of data destruction.

Recycle4Charity works with healthcare organisations in London to provide certified data destruction and WEEE-compliant recycling for end-of-life IT equipment. Where devices can be securely wiped and refurbished, they are donated free of charge to digitally-excluded Londoners.

Find out more about our process on our data centre IT recycling and disposal page and read our guide to GDPR data disposal duties for a step-by-step approach to compliant disposal.

To discuss secure disposal of healthcare IT equipment, contact Recycle4Charity.

The Regulatory Context for Financial Services Data

Financial services firms in the UK operate under a more complex regulatory environment than most other sectors. UK GDPR and the Data Protection Act 2018 apply to all personal data processing, but the Financial Conduct Authority (FCA) also sets operational and conduct standards that overlap with data security obligations. Getting IT disposal wrong in financial services carries the risk of regulatory action from two directions.

The ICO enforces data protection law. The FCA enforces conduct and prudential standards. While they operate under different legislation, both expect firms to implement appropriate controls to prevent unauthorised access to customer data — and the disposal of hardware containing that data is a point at which both sets of expectations apply.

What Personal Data Do Financial Services Firms Hold?

Financial services organisations typically process large volumes of personal data, including some of the most sensitive categories:

  • Customer identification data (names, addresses, dates of birth, National Insurance numbers)
  • Financial data (account numbers, transaction histories, credit information, salary details)
  • Identity verification documents (passport scans, utility bills)
  • Biometric data where used for identity verification
  • Employment and income data collected during onboarding or lending decisions
  • Communications data (recorded calls, email correspondence under record-keeping obligations)

Much of this data sits on trading workstations, customer service terminals, servers running core banking or CRM systems, and the laptops of advisers and analysts. Each of these devices is a potential vector for data exposure if not properly disposed of at end of life.

UK GDPR Obligations for Financial Services IT Disposal

UK GDPR imposes the same core obligations on financial services firms as on any other organisation, but the volume and sensitivity of data held makes the practical stakes higher.

The key principles for disposal are:

  • Storage limitation (Article 5(1)(e)): personal data must not be retained beyond its defined retention period. Financial services firms typically have long retention requirements — seven years or more for many transaction and advice records — but these are not indefinite. When the retention period expires, data must be erased.
  • Integrity and confidentiality (Article 5(1)(f)): data must be processed securely, including at the point of erasure. This means certified data wiping or physical destruction — not standard deletion.
  • Accountability (Article 5(2)): firms must be able to demonstrate compliance. For IT disposal, that means a formal ITAD procedure and certificates of data destruction retained as audit records.

FCA Expectations on Data Security

The FCA’s Senior Managers and Certification Regime (SMCR) places individual accountability on senior managers for the firm’s compliance with regulatory requirements. Under the SMCR, a senior manager may be personally accountable for failures in data security — including failures at the point of IT disposal — where those failures result from inadequate governance.

The FCA also requires firms to maintain operational resilience, including appropriate controls over data security. FCA Principle 11 requires firms to deal with their regulators in an open and cooperative way. Where a data breach occurs as a result of improper IT disposal, firms should consider their reporting obligations to both the FCA and the ICO.

The FCA and ICO have a memorandum of understanding setting out how they cooperate and share information, particularly in cases involving data incidents at regulated firms. A breach affecting customer financial data may therefore trigger parallel investigations by both regulators.

Common IT Disposal Risks in Financial Services

Risk Example Consequence
Unwiped workstations Desktops sold or recycled with customer account data on drives Personal data breach; ICO and FCA investigation
Server decommissioning without certified destruction Core banking or CRM server retired without drive destruction Mass data breach; potential criminal liability
Trading floor equipment Workstations with recorded voice and transaction data not properly cleared Breach of FCA record-keeping obligations as well as UK GDPR
Leased equipment returned without data clearing Photocopiers or terminals returned to lessors with internal drives intact Exposure of correspondence; data breach
Mobile devices (advisers’ phones and tablets) Client contact data and email correspondence not wiped before retirement Personal data breach

Record-Keeping and Audit Trail

Financial services firms are already well accustomed to extensive record-keeping obligations — MiFID II, the Consumer Duty, and FCA conduct rules all impose documentation requirements. Extending that culture to IT asset disposal is a natural fit.

For each retired device, firms should retain:

  • an asset record identifying the device, its data classification and the date of retirement
  • a certificate of data destruction confirming the method and date of destruction
  • confirmation that the destruction was carried out by a provider with appropriate security controls
  • evidence of the data processing agreement with the ITAD provider

These records should be retained for at least as long as the firm’s standard retention period for regulatory documents — and available for production to both the FCA and the ICO if requested.

Choosing an ITAD Provider for Financial Services

Financial services firms should apply the same due diligence to their ITAD provider as to any other critical supplier. Key questions include:

  • Can they provide certificates of data destruction for each asset?
  • Do they maintain a documented chain of custody?
  • Are they willing to sign a data processing agreement?
  • What security standards govern their destruction processes?
  • How do they handle devices containing particularly sensitive data?

Firms with data centre infrastructure should read our data centre IT recycling and disposal guidance for considerations specific to server and network equipment. For the core legal framework governing your disposal obligations, our data destruction service page explains what certified destruction involves.

To discuss secure disposal of financial services IT equipment, contact Recycle4Charity.

Why Data Disposal Is a GDPR Obligation

Many UK businesses treat data disposal as a practical or logistical task — clearing out old equipment or deleting records to save storage space. UK GDPR frames it very differently. The storage limitation principle (Article 5(1)(e)) and the integrity and confidentiality principle (Article 5(1)(f)) together create a positive legal duty to erase data that is no longer needed, and to do so securely.

Failure to meet this duty is not just poor practice — it is a breach of UK GDPR, and the Information Commissioner’s Office (ICO) has enforcement powers that include fines of up to £17.5 million or 4% of global annual turnover, whichever is higher.

The Storage Limitation Principle

Article 5(1)(e) of UK GDPR requires that personal data be kept “in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.”

In practice, this means every category of personal data your organisation holds must have a defined retention period. Once that period expires, the data must be erased — not archived indefinitely, not moved to a “cold storage” folder and forgotten, but genuinely deleted. For digital data on hardware, deletion must be carried out in a way that prevents recovery.

What “Securely Erased” Means in Law

UK GDPR does not define a specific technical standard for data deletion. The ICO’s guidance, however, is clear that standard deletion — emptying a recycle bin, removing files or formatting a drive — does not constitute secure erasure. Data deleted this way remains recoverable using widely available tools.

Secure erasure means one of two things:

  • Certified data wiping: software overwrites every sector of the storage medium, typically multiple times, to a recognised standard. NIST Special Publication 800-88 (Guidelines for Media Sanitisation) is widely accepted as the benchmark.
  • Physical destruction: the storage medium — the hard drive, SSD, USB stick or backup tape — is physically destroyed to the point of being unreadable. This is appropriate for media at the end of its serviceable life or where data sensitivity warrants it.

Both approaches, properly carried out and documented, satisfy the GDPR data disposal obligation. The choice between them depends on whether the device can be reused after wiping, and on the sensitivity of the data it held.

Which Data and Which Devices Need Secure Disposal?

Any storage medium that has held personal data requires secure disposal. This includes:

  • Hard drives and SSDs in desktop computers, laptops and servers
  • Mobile phones and tablets
  • USB drives, SD cards, memory sticks and backup tapes
  • Internal drives in printers, photocopiers and multi-function devices
  • Network-attached storage (NAS) and external hard drives
  • Cloud accounts and virtual machines (data must be deleted, not merely decommissioned)

Organisations often overlook printers and photocopiers. Many hold hard drives that store copies of every document scanned, copied or printed. A photocopier returned to a leasing company without its drive being cleared can expose months or years of business correspondence.

The Accountability Requirement: Documenting Disposal

UK GDPR Article 5(2) — the accountability principle — requires organisations to be able to demonstrate compliance with all other principles, including the disposal obligation. For GDPR data disposal, this means retaining documentary evidence that disposal took place.

The standard document for this purpose is a certificate of data destruction. A reputable ITAD (IT asset disposal) provider will issue a certificate for each device destroyed, specifying the asset, the destruction method, the date and the standards applied. These certificates are your audit trail.

The ICO may request this documentation during an investigation or audit. Organisations that cannot demonstrate that data was securely disposed of face greater regulatory exposure than those that have clear records.

Building a Compliant Data Disposal Process

A formal GDPR data disposal process should cover the following steps:

Step Action
1. Identify Audit end-of-life devices and data stores requiring disposal
2. Classify Determine the sensitivity of data held on each device
3. Select method Choose certified wiping (for reusable devices) or physical destruction
4. Execute Engage a certified ITAD provider; maintain chain of custody
5. Document Obtain and retain certificate of data destruction for each asset
6. Record Log the disposal in your Record of Processing Activities

Organisations should not rely on individual staff members to carry out ad hoc deletion. Disposal should be a documented, auditable process managed by a responsible person — typically the data protection officer, IT manager or equivalent.

Responding to Individuals’ Right to Erasure

UK GDPR Article 17 gives individuals the right to request erasure of their personal data in certain circumstances — for example, where it is no longer necessary for the purpose for which it was collected, or where they withdraw consent and there is no overriding legal basis to continue. This “right to be forgotten” applies to digital records, paper records and any device that holds personal data about that individual.

Where a valid erasure request is received, the organisation must act within one calendar month. The response must confirm that data has been erased — and again, the organisation must be able to demonstrate this.

Choosing a Responsible ITAD Partner

Not all IT recyclers carry out certified data destruction. Before engaging a provider, verify that they:

  • provide a written certificate of data destruction for each asset
  • use a recognised standard for data wiping or physical destruction
  • maintain a documented chain of custody from collection to destruction
  • can describe what happens to devices or components after destruction

For businesses in London, Recycle4Charity offers certified data destruction alongside WEEE-compliant recycling. Where devices can be securely wiped and still function, they are refurbished and given free to digitally-excluded Londoners — turning your compliance obligation into a direct social benefit.

Find out more about how our process works on our data destruction service page, and read our overview of what is data destruction for more on methods and standards.

To arrange GDPR-compliant data disposal for your organisation, contact Recycle4Charity.

Why GDPR Applies When You Dispose of IT

Most organisations focus on GDPR when they collect or share data. Far fewer think carefully about the end of the data lifecycle — the moment an old device leaves the building. Yet UK GDPR Article 5(1)(e) requires that personal data be kept “no longer than is necessary” and Article 5(1)(f) requires that it be processed with “appropriate technical and organisational measures” to ensure security. Both obligations apply at the point of disposal.

When a hard drive, SSD, USB stick, photocopier or mobile phone passes from your organisation to a skip, an auction house or even a charity, you remain the data controller. The data on that device is still your responsibility until it has been demonstrably and irreversibly destroyed.

What Counts as a Data Security Failure at Disposal?

The Information Commissioner’s Office (ICO) has investigated organisations that sold second-hand computers still containing customer records, patient data or employee files. In each case the organisation assumed that deleting files or reformatting a drive was sufficient. It is not. Standard deletion leaves data recoverable using freely available tools. Even a factory reset on a mobile phone may leave residual data accessible to a determined attacker.

Under the Data Protection Act 2018 and UK GDPR, a recoverable data remnant on a disposed device is a potential personal data breach. If discovered — by a journalist, a researcher or a malicious actor — it must be reported to the ICO within 72 hours of the organisation becoming aware of it.

Which Devices Need Secure Data Destruction?

Any device that has ever stored, processed or transmitted personal data requires proper attention at end of life. That includes:

  • Desktop computers and laptops
  • Servers and network-attached storage (NAS) devices
  • Mobile phones and tablets
  • Printers, photocopiers and multi-function devices (many store scanned documents internally)
  • USB drives, SD cards and backup tapes
  • Smart building controllers and IoT devices that log access or behaviour

Many organisations overlook printers and photocopiers. These commonly hold internal hard drives that retain copies of every document scanned, copied or printed. Disposing of a leased photocopier without clearing its drive is a frequent source of data exposure.

The Storage Limitation and Data Minimisation Principles

Two of the seven principles of UK GDPR are especially relevant to disposal. The storage limitation principle (Article 5(1)(e)) means you must not keep personal data longer than necessary for the purpose for which it was collected. If you are retaining old equipment simply because disposal feels complicated, you may already be in breach. The data minimisation principle (Article 5(1)(c)) reinforces that you should hold no more data than required — and by extension, no more devices containing that data than you actively need.

A documented IT asset disposal (ITAD) policy, reviewed regularly, helps demonstrate compliance with both principles.

What Does “Secure Disposal” Actually Mean?

Secure disposal means the data cannot be recovered by any reasonably foreseeable means. In practice, organisations should look for one of two approaches:

Method How it works Suitable for
Certified data wiping Software overwrites every sector of the drive multiple times to a recognised standard (e.g. NIST 800-88) Devices to be reused or resold
Physical destruction Drive is shredded or crushed so media is unreadable Drives at end of serviceable life

A certificate of data destruction issued by the disposal provider gives you documentary evidence that destruction took place. This is your audit trail for GDPR accountability purposes.

For devices that can be securely wiped and still function, refurbishment and reuse is the better environmental outcome. Recycle4Charity wipes business devices and passes working equipment free of charge to digitally-excluded Londoners, supporting both your compliance and your social impact obligations.

Building an Audit Trail

UK GDPR’s accountability principle (Article 5(2)) requires you to be able to demonstrate compliance, not merely assert it. For IT disposal, that means keeping records of:

  • Which assets were disposed of and when
  • The method of data destruction used
  • Who carried it out (and what certifications they hold)
  • The certificate of data destruction for each device

These records should be retained for at least as long as your organisation’s standard data retention period, and made available to the ICO if requested.

Choosing a Responsible ITAD Partner

Not every IT recycler offers certified data destruction. When selecting a provider, ask for evidence of the standards they work to, how they document the chain of custody, and what happens to devices after data is destroyed. A reputable partner will provide a certificate of data destruction as a matter of course.

Learn more about what certified data destruction involves on our data destruction service page, or read our guide to what a certificate of data destruction covers.

If you are ready to dispose of old IT equipment in a compliant, environmentally responsible way, contact Recycle4Charity to arrange a collection.