← Blog ·

How to Dispose of IT Equipment: A Comprehensive Business Guide

Disposing of IT equipment as a business requires addressing three obligations in parallel: data security under UK GDPR, environmental compliance under the WEEE Regulations 2013, and documented chain of custody from collection to confirmed destruction. Treating these as separate tasks rather than an integrated process is where most compliance failures occur.

The three obligations every business must meet

Before covering practical steps, it is worth stating clearly what the law requires of UK businesses disposing of IT equipment.

1. Data security — UK GDPR and the Data Protection Act 2018

If any device you are disposing of has processed personal data — and virtually every computer, phone, or tablet used for work has — you remain responsible for that data until it is provably destroyed. The Information Commissioner’s Office (ICO) has issued significant fines for organisations that allowed equipment containing personal data to enter second-hand markets or recycling streams without confirmed erasure.

This obligation applies regardless of whether the data was stored deliberately. Email caches, browser history, temporary files, and application data routinely accumulate personal information. A standard factory reset or disk format does not destroy this data; it removes the file directory but leaves the underlying data recoverable.

2. Environmental compliance — WEEE Regulations 2013

All IT equipment — computers, laptops, monitors, printers, servers, phones, tablets, networking equipment, cables, chargers, and peripherals — is classified as Waste Electrical and Electronic Equipment (WEEE). It cannot go in commercial or household general waste. Businesses must transfer WEEE to an authorised treatment facility and obtain a Waste Transfer Note for each transfer. Waste Transfer Notes must be retained for two years.

3. Chain of custody documentation

A chain of custody record traces each device from the moment it leaves your premises to confirmed destruction or reuse. For regulated industries — finance, healthcare, legal, public sector — auditors and regulators may ask to see this documentation. For all businesses, it provides demonstrable due diligence in the event of an ICO investigation.

For a deeper look at your WEEE obligations, see our guide on what WEEE recycling means for businesses.

What IT equipment does this cover?

This guide covers the full range of business IT:

  • Desktop computers and workstations
  • Laptops, Chromebooks, and ultrabooks
  • Monitors and display screens
  • Printers, copiers, and multifunction devices
  • Mobile phones and smartphones
  • Tablets and e-readers
  • Servers, NAS devices, and storage arrays
  • Networking equipment: switches, routers, firewalls, access points
  • Cables, chargers, and power adapters
  • Keyboards, mice, and other peripherals
  • Cameras and AV equipment (where part of IT infrastructure)

Step-by-step: how to dispose of IT equipment correctly

Step 1: Audit and inventory

Before any equipment leaves the building, create a complete inventory. Record:
– Make and model
– Serial number
– Asset tag (if applicable)
– IMEI number (for mobile devices)
– Drive serial numbers (for computers and servers)
– Condition assessment

This inventory forms the basis of your chain of custody documentation and is required to match data destruction certificates to specific devices.

Step 2: Back up data you need to retain

Transfer files, licence keys, and application data to new devices or secure storage before wiping. Confirm backups are complete and accessible before proceeding to erasure.

Step 3: Arrange certified data destruction

Choose the appropriate method for each device type:

Device type Recommended data destruction method
Computer / laptop (functioning HDD or SSD) Certified software overwrite (NIST 800-88 / HMG IS5)
Computer / laptop (failed or non-functional drive) Physical shredding
Server (multiple drives, RAID configuration) Break RAID, individually wipe or shred each drive
Mobile phone / tablet (modern, encrypted) Factory reset + encryption key destruction (confirm with provider)
Printer / copier with internal hard drive Manufacturer secure delete routine + certified overwrite or shredding
External hard drives and USB drives Software overwrite or physical shredding

In every case, a data destruction certificate should be issued for each device, naming the serial number and confirming the method and standard applied.

Step 4: Deregister and decommission

Update your internal systems:
– Remove devices from your CMDB or asset register
– Deregister software licences
– Remove devices from your MDM (mobile device management) system
– Notify finance for asset write-off
– Remove from cyber insurance schedules if listed

Step 5: Choose a certified ITAD provider

For businesses, a certified IT asset disposal provider handles the WEEE compliance, data destruction, and documentation in an integrated way. Look for:

  • Registration as an authorised WEEE treatment facility with the Environment Agency
  • ISO 14001 (environmental management) certification
  • ISO 27001 (information security management) certification
  • Ability to issue Waste Transfer Notes and data destruction certificates for every device

Recycle4Charity provides ITAD services for London businesses, with free collection for qualifying volumes. Working devices are refurbished and donated to digitally-excluded Londoners; equipment beyond reuse is processed through certified WEEE streams. Visit our IT asset disposal for businesses page to request a collection.

Step 6: Collect your documentation

At the end of the process, you should hold:

  • Asset inventory — your internal record
  • Collection manifest — signed at point of collection
  • Waste Transfer Note — legally required, retain for two years minimum
  • Data destruction certificate — for each device, listing serial number, method, and standard
  • Certificate of recycling or reuse — confirming WEEE-compliant processing

Step 7: File and retain

File all documentation against your internal IT asset disposal policy. Your data protection records should note the disposal date and reference the destruction certificate for any devices that processed personal data.

Common mistakes businesses make

Disposing of devices in dribs and drabs without documentation
Every disposal requires a Waste Transfer Note. Accumulating devices and arranging a single certified collection is both more efficient and more compliant.

Assuming factory resets are sufficient
They are not, for most devices and most purposes. Always arrange certified erasure or destruction.

Overlooking printers and copiers
These often contain hard drives storing document images. Many businesses wipe computers carefully but overlook the MFD in the corner of the office. See our guide on how to dispose of old printers for the specific steps.

Leaving cables and peripherals behind
All WEEE — including cables, chargers, keyboards, and mice — needs a Waste Transfer Note. Bundle everything into one collection where possible.

Using a general waste contractor for WEEE
General waste contractors are not authorised WEEE treatment facilities. Using one exposes your business to both WEEE Regulations penalties and potential ICO liability.

IT equipment disposal for regulated sectors

Businesses in finance, healthcare, legal services, and the public sector face additional obligations:

  • Financial services: FCA rules require demonstrable data governance throughout the data lifecycle, including disposal.
  • Healthcare: NHS organisations follow NHS Data Security and Protection Toolkit guidance, which specifies certified erasure standards.
  • Legal: Law firms handling client data must satisfy SRA requirements on data protection.
  • Public sector: Central government and local authorities follow the Secure by Design framework and HMG Infosec Standards.

A certified ITAD provider experienced in regulated sectors can provide documentation aligned to these requirements. Ask for sample certificates and confirm the erasure standard applied before instructing.

Ready to dispose of your IT equipment?

Recycle4Charity provides certified ITAD services for London businesses — data destruction, WEEE recycling, full documentation, and free collection for qualifying volumes. Contact us through our business IT disposal page to arrange a collection or request a quote.

Blog

Frequently asked questions

IT asset disposal (ITAD) is the certified process of decommissioning end-of-life IT equipment with documented data destruction and WEEE-compliant recycling or reuse. Businesses need it to meet their obligations under UK GDPR, the Data Protection Act 2018, and the WEEE Regulations 2013.

Yes. All IT equipment is classified as WEEE and cannot be disposed of in commercial general waste. Businesses that do so risk enforcement action under the WEEE Regulations 2013, as well as potential ICO action if devices contain unwiped personal data.

You should receive a Waste Transfer Note (legally required for any transfer of controlled waste), a data destruction certificate for each device that held data, and a certificate of recycling or reuse confirming WEEE-compliant processing. Retain all documents for at least two years.

For a standard mixed-load collection, the physical collection typically takes a few hours. Data destruction certificates and final documentation are usually issued within a few days of processing. Recycle4Charity can typically arrange collection within a week for London businesses.

Not necessarily. Many certified ITAD providers — including Recycle4Charity — offer free collection for qualifying volumes, particularly where devices have refurbishment value. The cost of non-compliance (ICO fines, Environment Agency penalties, reputational damage) typically far exceeds the cost of proper disposal.

Need secure IT disposal in London?

Certified data destruction and WEEE recycling — with refurbished devices going to people who need them.