The three obligations every business must meet
Before covering practical steps, it is worth stating clearly what the law requires of UK businesses disposing of IT equipment.
1. Data security — UK GDPR and the Data Protection Act 2018
If any device you are disposing of has processed personal data — and virtually every computer, phone, or tablet used for work has — you remain responsible for that data until it is provably destroyed. The Information Commissioner’s Office (ICO) has issued significant fines for organisations that allowed equipment containing personal data to enter second-hand markets or recycling streams without confirmed erasure.
This obligation applies regardless of whether the data was stored deliberately. Email caches, browser history, temporary files, and application data routinely accumulate personal information. A standard factory reset or disk format does not destroy this data; it removes the file directory but leaves the underlying data recoverable.
2. Environmental compliance — WEEE Regulations 2013
All IT equipment — computers, laptops, monitors, printers, servers, phones, tablets, networking equipment, cables, chargers, and peripherals — is classified as Waste Electrical and Electronic Equipment (WEEE). It cannot go in commercial or household general waste. Businesses must transfer WEEE to an authorised treatment facility and obtain a Waste Transfer Note for each transfer. Waste Transfer Notes must be retained for two years.
3. Chain of custody documentation
A chain of custody record traces each device from the moment it leaves your premises to confirmed destruction or reuse. For regulated industries — finance, healthcare, legal, public sector — auditors and regulators may ask to see this documentation. For all businesses, it provides demonstrable due diligence in the event of an ICO investigation.
For a deeper look at your WEEE obligations, see our guide on what WEEE recycling means for businesses.
What IT equipment does this cover?
This guide covers the full range of business IT:
- Desktop computers and workstations
- Laptops, Chromebooks, and ultrabooks
- Monitors and display screens
- Printers, copiers, and multifunction devices
- Mobile phones and smartphones
- Tablets and e-readers
- Servers, NAS devices, and storage arrays
- Networking equipment: switches, routers, firewalls, access points
- Cables, chargers, and power adapters
- Keyboards, mice, and other peripherals
- Cameras and AV equipment (where part of IT infrastructure)
Step-by-step: how to dispose of IT equipment correctly
Step 1: Audit and inventory
Before any equipment leaves the building, create a complete inventory. Record:
– Make and model
– Serial number
– Asset tag (if applicable)
– IMEI number (for mobile devices)
– Drive serial numbers (for computers and servers)
– Condition assessment
This inventory forms the basis of your chain of custody documentation and is required to match data destruction certificates to specific devices.
Step 2: Back up data you need to retain
Transfer files, licence keys, and application data to new devices or secure storage before wiping. Confirm backups are complete and accessible before proceeding to erasure.
Step 3: Arrange certified data destruction
Choose the appropriate method for each device type:
| Device type | Recommended data destruction method |
|---|---|
| Computer / laptop (functioning HDD or SSD) | Certified software overwrite (NIST 800-88 / HMG IS5) |
| Computer / laptop (failed or non-functional drive) | Physical shredding |
| Server (multiple drives, RAID configuration) | Break RAID, individually wipe or shred each drive |
| Mobile phone / tablet (modern, encrypted) | Factory reset + encryption key destruction (confirm with provider) |
| Printer / copier with internal hard drive | Manufacturer secure delete routine + certified overwrite or shredding |
| External hard drives and USB drives | Software overwrite or physical shredding |
In every case, a data destruction certificate should be issued for each device, naming the serial number and confirming the method and standard applied.
Step 4: Deregister and decommission
Update your internal systems:
– Remove devices from your CMDB or asset register
– Deregister software licences
– Remove devices from your MDM (mobile device management) system
– Notify finance for asset write-off
– Remove from cyber insurance schedules if listed
Step 5: Choose a certified ITAD provider
For businesses, a certified IT asset disposal provider handles the WEEE compliance, data destruction, and documentation in an integrated way. Look for:
- Registration as an authorised WEEE treatment facility with the Environment Agency
- ISO 14001 (environmental management) certification
- ISO 27001 (information security management) certification
- Ability to issue Waste Transfer Notes and data destruction certificates for every device
Recycle4Charity provides ITAD services for London businesses, with free collection for qualifying volumes. Working devices are refurbished and donated to digitally-excluded Londoners; equipment beyond reuse is processed through certified WEEE streams. Visit our IT asset disposal for businesses page to request a collection.
Step 6: Collect your documentation
At the end of the process, you should hold:
- Asset inventory — your internal record
- Collection manifest — signed at point of collection
- Waste Transfer Note — legally required, retain for two years minimum
- Data destruction certificate — for each device, listing serial number, method, and standard
- Certificate of recycling or reuse — confirming WEEE-compliant processing
Step 7: File and retain
File all documentation against your internal IT asset disposal policy. Your data protection records should note the disposal date and reference the destruction certificate for any devices that processed personal data.
Common mistakes businesses make
Disposing of devices in dribs and drabs without documentation
Every disposal requires a Waste Transfer Note. Accumulating devices and arranging a single certified collection is both more efficient and more compliant.
Assuming factory resets are sufficient
They are not, for most devices and most purposes. Always arrange certified erasure or destruction.
Overlooking printers and copiers
These often contain hard drives storing document images. Many businesses wipe computers carefully but overlook the MFD in the corner of the office. See our guide on how to dispose of old printers for the specific steps.
Leaving cables and peripherals behind
All WEEE — including cables, chargers, keyboards, and mice — needs a Waste Transfer Note. Bundle everything into one collection where possible.
Using a general waste contractor for WEEE
General waste contractors are not authorised WEEE treatment facilities. Using one exposes your business to both WEEE Regulations penalties and potential ICO liability.
IT equipment disposal for regulated sectors
Businesses in finance, healthcare, legal services, and the public sector face additional obligations:
- Financial services: FCA rules require demonstrable data governance throughout the data lifecycle, including disposal.
- Healthcare: NHS organisations follow NHS Data Security and Protection Toolkit guidance, which specifies certified erasure standards.
- Legal: Law firms handling client data must satisfy SRA requirements on data protection.
- Public sector: Central government and local authorities follow the Secure by Design framework and HMG Infosec Standards.
A certified ITAD provider experienced in regulated sectors can provide documentation aligned to these requirements. Ask for sample certificates and confirm the erasure standard applied before instructing.
Ready to dispose of your IT equipment?
Recycle4Charity provides certified ITAD services for London businesses — data destruction, WEEE recycling, full documentation, and free collection for qualifying volumes. Contact us through our business IT disposal page to arrange a collection or request a quote.