Why use a checklist for IT disposal?
IT disposal projects fail — or create legal exposure — when steps are skipped. A hard drive that is not wiped, a device that goes missing between office and recycler, or a missing waste transfer note can each cause a compliance problem. A checklist imposes a consistent order on the process and creates a record that each step was completed.
This checklist is designed for IT managers, facilities teams and operations staff preparing for an office IT clear-out, whether that is a routine device refresh, an office move or a full decommission. For the detailed reasoning behind each stage, see our IT asset disposal process guide.
Before collection: planning and inventory
- [ ] Produce a full inventory of all devices to be disposed of, including make, model, serial number and location
- [ ] Identify devices containing sensitive data — HR systems, finance servers, devices used by senior staff
- [ ] Flag any devices requiring physical destruction (damaged drives, classified data environments)
- [ ] Check whether any devices are still under lease or finance agreement — these cannot be disposed of without the lessor’s consent
- [ ] Review your IT asset disposal policy to confirm the approved destruction standards and authorised provider
- [ ] Confirm the approved ITAD provider holds a valid Environment Agency waste carrier licence — check the public register at gov.uk
- [ ] Verify the provider’s ADISA certification or equivalent data destruction accreditation
- [ ] Agree a collection date and confirm site access requirements (car park, lift access, floor-by-floor logistics)
- [ ] Notify building management if a large collection vehicle needs access
On collection day
- [ ] Have an authorised member of staff present to sign the collection manifest
- [ ] Check that every device on your inventory is listed on the provider’s collection manifest before signing
- [ ] Note the collection vehicle registration and operative names
- [ ] Retain a copy of the signed collection manifest
- [ ] Confirm the waste transfer note will be issued — this is a legal requirement under the Environmental Protection Act 1990
After collection: certification and records
- [ ] Receive and file the data destruction certificate for every device processed
- [ ] Receive and file the waste transfer note confirming WEEE-compliant recycling
- [ ] Receive the final asset report listing each device’s serial number and disposal outcome
- [ ] Reconcile the final asset report against your original inventory — flag any discrepancies to the provider immediately
- [ ] Update your IT asset register to remove disposed items
- [ ] Store all disposal documentation in line with your data retention policy
Comparing disposal methods
Not all devices follow the same route. This table summarises the correct approach by device type:
| Device type | Recommended destruction method | Notes |
|---|---|---|
| Laptops and desktops (functional) | Software wipe (NIST 800-88 or HMG IS5) | Certificate issued per device |
| Laptops and desktops (non-functional) | Physical drive shredding | Drive removed and destroyed separately |
| Servers | Physical shredding or certified wipe | Confirm with provider based on drive type |
| Mobile phones and tablets | Software wipe + factory reset to certified standard | IMEI recorded on asset manifest |
| USB drives and external storage | Physical shredding | Do not attempt software wipe — shred |
| Printers with internal storage | Wipe or remove and shred storage module | Printer memory is often overlooked |
| Networking equipment (switches, routers) | Configuration reset to certified standard | Confirm with provider |
What to do with devices you are not sure about
If you have devices that are damaged, very old or of uncertain data content, do not guess. Pass them to your ITAD provider with a note that they require physical destruction of storage media. The cost of physical shredding is small compared with the cost of a data breach.
For devices that may still have commercial value — recent laptops, servers, workstations — ask your provider about asset recovery. Depending on condition, you may receive a credit against your disposal costs. Our guide to IT asset recovery explains how this works.
Policy and governance checks
Alongside the operational checklist, confirm the following at the governance level:
- [ ] Your IT equipment disposal policy has been reviewed in the last 12 months and reflects current UK GDPR obligations
- [ ] Staff who handle IT disposal have received appropriate data protection training
- [ ] Your data processing agreement with your ITAD provider is current and signed
- [ ] Your Records of Processing Activities (RoPA) reflects IT disposal as a processing activity, as required by UK GDPR Article 30
If your organisation does not yet have a formal IT disposal policy, our IT equipment disposal policy template gives you a starting point.
Ready to book your collection?
Recycle4Charity provides certified ITAD services across London and the South East. We issue data destruction certificates for every device, supply waste transfer notes for all WEEE recycling, and refurbish reusable equipment for donation to digitally-excluded Londoners. Visit our business services page to arrange a collection or request a quote.