← Blog ·

IT equipment disposal policy: what to include and a free template

An IT equipment disposal policy is a formal document that defines how your organisation retires end-of-life technology, who is responsible for each step, which data destruction standards apply and how compliance is evidenced. Without one, disposal decisions are ad hoc, inconsistent and difficult to defend to the ICO or to clients who ask about your data handling.

IT equipment disposal policy: what to include and a free template

Why does your organisation need an IT equipment disposal policy?

UK GDPR’s accountability principle (Article 5(2)) requires that organisations be able to demonstrate compliance with data protection law — not merely claim it. An IT equipment disposal policy is part of that demonstration. It shows that your organisation has thought through how personal data is handled at the point of disposal and has put controls in place.

The policy also protects operational consistency. Without written guidance, disposal decisions vary by individual: one member of staff donates a laptop to a charity shop without wiping it; another stores old phones in a cupboard for years. A policy removes that variability and sets a clear, lawful standard.

For context on the disposal process the policy should govern, see our IT asset disposal process guide.

What UK regulations must an IT equipment disposal policy reflect?

Any policy written for a UK organisation should reference:

  • UK GDPR and the Data Protection Act 2018 — personal data must be handled securely throughout its lifecycle, including at disposal. Inadequate erasure before disposal is a personal data breach.
  • The WEEE Regulations 2013 — business electrical and electronic equipment must not enter general waste. It must be collected by a registered carrier and processed at an authorised treatment facility.
  • The Environmental Protection Act 1990 — duty of care for all waste, including WEEE, from point of generation to point of lawful disposal.
  • HMG Infosec Standard 5 — the UK government’s data sanitisation standard, widely adopted as the benchmark for software overwriting in UK public and private sector ITAD.

Your policy should name these obligations explicitly so that readers understand the legal context for the controls it sets.

What should an IT equipment disposal policy contain?

A well-structured policy typically includes the following sections:

Purpose and scope

State what the policy covers — which categories of equipment, which sites, which staff. Be specific. A policy that says “all IT equipment” should define what that includes (laptops, desktops, servers, mobile phones, tablets, printers, networking equipment, external storage, USBs).

Roles and responsibilities

Role Responsibility
IT Manager Maintains the asset register; coordinates disposal with approved provider
Data Protection Officer (if applicable) Ensures policy reflects current UK GDPR obligations; reviews annually
Line managers Ensure staff return equipment promptly at end of use
Finance / Procurement Confirms lease and finance status before disposal
Approved ITAD provider Carries out certified data destruction and WEEE-compliant recycling

Approved disposal methods

The policy must state which data destruction methods are acceptable. At minimum:

  • Software overwriting to NIST 800-88 or HMG Infosec Standard 5 for bootable devices
  • Physical shredding or degaussing for drives that cannot be wiped, damaged devices and high-sensitivity data environments
  • No device may be donated, sold or otherwise transferred without prior certified data destruction

Approved providers

Name or describe the criteria for approved ITAD providers. Require that any provider holds:

  • A valid Environment Agency waste carrier licence
  • ADISA certification or equivalent independently audited data destruction standard
  • ICO registration as a data processor
  • Relevant ISO certifications (27001, 14001)

Chain of custody and documentation

The policy should require that every disposal generates:

  • A collection manifest signed at the point of transfer
  • A data destruction certificate per device
  • A waste transfer note for WEEE recycling
  • A final asset report reconcilable against the IT asset register

Prohibited actions

Be explicit about what staff must not do:

  • Delete files or format drives as a substitute for certified disposal
  • Transfer devices to personal use without certified data destruction
  • Place IT equipment in general or mixed recycling waste
  • Donate equipment to external parties — including charities — without prior certified data destruction

Record retention

Specify how long disposal records must be kept. The ICO’s accountability principle suggests retaining compliance evidence for as long as the related processing obligation exists. In practice, many organisations retain disposal records for a minimum of three to six years, aligned with their broader data retention schedule.

Policy review

State a review frequency. Annual review is appropriate for most organisations, or review triggered by a significant regulatory change (such as future updates to UK GDPR post-EU retained law).

Free template structure

Below is a condensed template you can adapt. Replace bracketed fields with your organisation’s details.


IT Equipment Disposal Policy
Organisation: [Name]
Policy owner: [Role]
Version: [1.0]
Last reviewed: [Date]
Next review due: [Date]

1. Purpose
This policy sets out [Organisation]’s approach to retiring end-of-life IT equipment in a manner that protects personal data, meets environmental obligations and generates an auditable record of compliance.

2. Scope
This policy applies to all IT equipment owned or leased by [Organisation], including laptops, desktops, servers, mobile devices, tablets, printers, networking equipment and removable storage media.

3. Legal basis
This policy supports compliance with UK GDPR, the Data Protection Act 2018, the WEEE Regulations 2013 and the Environmental Protection Act 1990.

4. Approved disposal method
All equipment must be disposed of via [Approved Provider Name], who holds [relevant certifications]. No equipment may be disposed of by any other means without prior written approval from the IT Manager and Data Protection Officer.

5. Data destruction standard
Functional storage media: software overwriting to HMG Infosec Standard 5 minimum. Non-functional or high-sensitivity media: physical destruction.

6. Documentation
A data destruction certificate and waste transfer note must be obtained for every disposal and filed in [location] for a minimum of [X] years.

7. Prohibited actions
[See prohibited actions list above.]

8. Breaches
Any breach of this policy must be reported to the Data Protection Officer within 24 hours.


For a practical pre-disposal task list, see our IT asset disposal checklist. When you are ready to choose a certified ITAD provider, our business services page describes how Recycle4Charity operates and what documentation we supply.

Blog

Frequently asked questions

There is no single law requiring a document called an IT equipment disposal policy, but UK GDPR's accountability principle (Article 5(2)) requires organisations to demonstrate that they handle personal data lawfully at all stages — including disposal. A written policy is the most effective way to do so.

Ownership typically sits with the IT Manager or Head of IT, with the Data Protection Officer reviewing the data protection elements. In smaller organisations, a single person may hold both functions.

At least annually, and whenever there is a significant change to relevant legislation, your IT infrastructure or your approved provider.

For UK organisations, HMG Infosec Standard 5 is the benchmark for software overwriting. NIST 800-88 is also widely accepted. Physical shredding should be required for drives that cannot be wiped or that held particularly sensitive data.

Only if certified data destruction has been completed first and documented. The device must be wiped to the policy's required standard before transfer — not after. Your policy should state this explicitly.

Need secure IT disposal in London?

Certified data destruction and WEEE recycling — with refurbished devices going to people who need them.