← Blog ·

GDPR for Financial Services: IT Disposal Obligations and FCA Overlap

GDPR for financial services organisations creates a dual compliance landscape: UK GDPR governs the protection of personal data, while FCA rules on operational resilience and data security sit alongside it. Banks, insurance companies, wealth managers and financial advisers must navigate both when disposing of old IT equipment, and must ensure that every retired device containing customer or transaction data is securely wiped or destroyed.

The Regulatory Context for Financial Services Data

Financial services firms in the UK operate under a more complex regulatory environment than most other sectors. UK GDPR and the Data Protection Act 2018 apply to all personal data processing, but the Financial Conduct Authority (FCA) also sets operational and conduct standards that overlap with data security obligations. Getting IT disposal wrong in financial services carries the risk of regulatory action from two directions.

The ICO enforces data protection law. The FCA enforces conduct and prudential standards. While they operate under different legislation, both expect firms to implement appropriate controls to prevent unauthorised access to customer data — and the disposal of hardware containing that data is a point at which both sets of expectations apply.

What Personal Data Do Financial Services Firms Hold?

Financial services organisations typically process large volumes of personal data, including some of the most sensitive categories:

  • Customer identification data (names, addresses, dates of birth, National Insurance numbers)
  • Financial data (account numbers, transaction histories, credit information, salary details)
  • Identity verification documents (passport scans, utility bills)
  • Biometric data where used for identity verification
  • Employment and income data collected during onboarding or lending decisions
  • Communications data (recorded calls, email correspondence under record-keeping obligations)

Much of this data sits on trading workstations, customer service terminals, servers running core banking or CRM systems, and the laptops of advisers and analysts. Each of these devices is a potential vector for data exposure if not properly disposed of at end of life.

UK GDPR Obligations for Financial Services IT Disposal

UK GDPR imposes the same core obligations on financial services firms as on any other organisation, but the volume and sensitivity of data held makes the practical stakes higher.

The key principles for disposal are:

  • Storage limitation (Article 5(1)(e)): personal data must not be retained beyond its defined retention period. Financial services firms typically have long retention requirements — seven years or more for many transaction and advice records — but these are not indefinite. When the retention period expires, data must be erased.
  • Integrity and confidentiality (Article 5(1)(f)): data must be processed securely, including at the point of erasure. This means certified data wiping or physical destruction — not standard deletion.
  • Accountability (Article 5(2)): firms must be able to demonstrate compliance. For IT disposal, that means a formal ITAD procedure and certificates of data destruction retained as audit records.

FCA Expectations on Data Security

The FCA’s Senior Managers and Certification Regime (SMCR) places individual accountability on senior managers for the firm’s compliance with regulatory requirements. Under the SMCR, a senior manager may be personally accountable for failures in data security — including failures at the point of IT disposal — where those failures result from inadequate governance.

The FCA also requires firms to maintain operational resilience, including appropriate controls over data security. FCA Principle 11 requires firms to deal with their regulators in an open and cooperative way. Where a data breach occurs as a result of improper IT disposal, firms should consider their reporting obligations to both the FCA and the ICO.

The FCA and ICO have a memorandum of understanding setting out how they cooperate and share information, particularly in cases involving data incidents at regulated firms. A breach affecting customer financial data may therefore trigger parallel investigations by both regulators.

Common IT Disposal Risks in Financial Services

Risk Example Consequence
Unwiped workstations Desktops sold or recycled with customer account data on drives Personal data breach; ICO and FCA investigation
Server decommissioning without certified destruction Core banking or CRM server retired without drive destruction Mass data breach; potential criminal liability
Trading floor equipment Workstations with recorded voice and transaction data not properly cleared Breach of FCA record-keeping obligations as well as UK GDPR
Leased equipment returned without data clearing Photocopiers or terminals returned to lessors with internal drives intact Exposure of correspondence; data breach
Mobile devices (advisers’ phones and tablets) Client contact data and email correspondence not wiped before retirement Personal data breach

Record-Keeping and Audit Trail

Financial services firms are already well accustomed to extensive record-keeping obligations — MiFID II, the Consumer Duty, and FCA conduct rules all impose documentation requirements. Extending that culture to IT asset disposal is a natural fit.

For each retired device, firms should retain:

  • an asset record identifying the device, its data classification and the date of retirement
  • a certificate of data destruction confirming the method and date of destruction
  • confirmation that the destruction was carried out by a provider with appropriate security controls
  • evidence of the data processing agreement with the ITAD provider

These records should be retained for at least as long as the firm’s standard retention period for regulatory documents — and available for production to both the FCA and the ICO if requested.

Choosing an ITAD Provider for Financial Services

Financial services firms should apply the same due diligence to their ITAD provider as to any other critical supplier. Key questions include:

  • Can they provide certificates of data destruction for each asset?
  • Do they maintain a documented chain of custody?
  • Are they willing to sign a data processing agreement?
  • What security standards govern their destruction processes?
  • How do they handle devices containing particularly sensitive data?

Firms with data centre infrastructure should read our data centre IT recycling and disposal guidance for considerations specific to server and network equipment. For the core legal framework governing your disposal obligations, our data destruction service page explains what certified destruction involves.

To discuss secure disposal of financial services IT equipment, contact Recycle4Charity.

Blog

Frequently asked questions

Yes. UK GDPR applies to all organisations that process personal data, including banks, insurance companies, investment firms, credit brokers and financial advisers. Financial services firms typically process large volumes of sensitive personal data, which increases both their obligations and their exposure.

The FCA's requirements on operational resilience, data security and senior manager accountability under SMCR are all relevant to IT disposal. Where a breach results from improperly disposed hardware, a senior manager with responsibility for data security governance may face personal regulatory scrutiny. The FCA and ICO cooperate on data incidents at regulated firms.

Retention periods vary by the type of data and the applicable regulation. FCA rules typically require firms to retain records of investment advice, transactions and client communications for at least five to seven years. These are minimum retention periods — data must be kept this long, but must also be deleted once the retention period expires.

Decommissioning should follow a formal IT asset disposal procedure: the device should be wiped to a certified standard or its drive physically destroyed, with a certificate of data destruction issued by the ITAD provider. If the workstation held recorded communications data subject to FCA retention requirements, firms should confirm those records have been transferred to compliant long-term storage before destruction.

Yes. Under UK GDPR Article 28, any organisation that processes personal data on your behalf — including an ITAD provider that handles devices containing customer data — must be engaged under a formal data processing agreement. This agreement must specify the purpose, the security obligations and the provider's duty to assist with your compliance.

Need secure IT disposal in London?

Certified data destruction and WEEE recycling — with refurbished devices going to people who need them.