Why does your organisation need an IT equipment disposal policy?
UK GDPR’s accountability principle (Article 5(2)) requires that organisations be able to demonstrate compliance with data protection law — not merely claim it. An IT equipment disposal policy is part of that demonstration. It shows that your organisation has thought through how personal data is handled at the point of disposal and has put controls in place.
The policy also protects operational consistency. Without written guidance, disposal decisions vary by individual: one member of staff donates a laptop to a charity shop without wiping it; another stores old phones in a cupboard for years. A policy removes that variability and sets a clear, lawful standard.
For context on the disposal process the policy should govern, see our IT asset disposal process guide.
What UK regulations must an IT equipment disposal policy reflect?
Any policy written for a UK organisation should reference:
- UK GDPR and the Data Protection Act 2018 — personal data must be handled securely throughout its lifecycle, including at disposal. Inadequate erasure before disposal is a personal data breach.
- The WEEE Regulations 2013 — business electrical and electronic equipment must not enter general waste. It must be collected by a registered carrier and processed at an authorised treatment facility.
- The Environmental Protection Act 1990 — duty of care for all waste, including WEEE, from point of generation to point of lawful disposal.
- HMG Infosec Standard 5 — the UK government’s data sanitisation standard, widely adopted as the benchmark for software overwriting in UK public and private sector ITAD.
Your policy should name these obligations explicitly so that readers understand the legal context for the controls it sets.
What should an IT equipment disposal policy contain?
A well-structured policy typically includes the following sections:
Purpose and scope
State what the policy covers — which categories of equipment, which sites, which staff. Be specific. A policy that says “all IT equipment” should define what that includes (laptops, desktops, servers, mobile phones, tablets, printers, networking equipment, external storage, USBs).
Roles and responsibilities
| Role | Responsibility |
|---|---|
| IT Manager | Maintains the asset register; coordinates disposal with approved provider |
| Data Protection Officer (if applicable) | Ensures policy reflects current UK GDPR obligations; reviews annually |
| Line managers | Ensure staff return equipment promptly at end of use |
| Finance / Procurement | Confirms lease and finance status before disposal |
| Approved ITAD provider | Carries out certified data destruction and WEEE-compliant recycling |
Approved disposal methods
The policy must state which data destruction methods are acceptable. At minimum:
- Software overwriting to NIST 800-88 or HMG Infosec Standard 5 for bootable devices
- Physical shredding or degaussing for drives that cannot be wiped, damaged devices and high-sensitivity data environments
- No device may be donated, sold or otherwise transferred without prior certified data destruction
Approved providers
Name or describe the criteria for approved ITAD providers. Require that any provider holds:
- A valid Environment Agency waste carrier licence
- ADISA certification or equivalent independently audited data destruction standard
- ICO registration as a data processor
- Relevant ISO certifications (27001, 14001)
Chain of custody and documentation
The policy should require that every disposal generates:
- A collection manifest signed at the point of transfer
- A data destruction certificate per device
- A waste transfer note for WEEE recycling
- A final asset report reconcilable against the IT asset register
Prohibited actions
Be explicit about what staff must not do:
- Delete files or format drives as a substitute for certified disposal
- Transfer devices to personal use without certified data destruction
- Place IT equipment in general or mixed recycling waste
- Donate equipment to external parties — including charities — without prior certified data destruction
Record retention
Specify how long disposal records must be kept. The ICO’s accountability principle suggests retaining compliance evidence for as long as the related processing obligation exists. In practice, many organisations retain disposal records for a minimum of three to six years, aligned with their broader data retention schedule.
Policy review
State a review frequency. Annual review is appropriate for most organisations, or review triggered by a significant regulatory change (such as future updates to UK GDPR post-EU retained law).
Free template structure
Below is a condensed template you can adapt. Replace bracketed fields with your organisation’s details.
IT Equipment Disposal Policy
Organisation: [Name]
Policy owner: [Role]
Version: [1.0]
Last reviewed: [Date]
Next review due: [Date]
1. Purpose
This policy sets out [Organisation]’s approach to retiring end-of-life IT equipment in a manner that protects personal data, meets environmental obligations and generates an auditable record of compliance.
2. Scope
This policy applies to all IT equipment owned or leased by [Organisation], including laptops, desktops, servers, mobile devices, tablets, printers, networking equipment and removable storage media.
3. Legal basis
This policy supports compliance with UK GDPR, the Data Protection Act 2018, the WEEE Regulations 2013 and the Environmental Protection Act 1990.
4. Approved disposal method
All equipment must be disposed of via [Approved Provider Name], who holds [relevant certifications]. No equipment may be disposed of by any other means without prior written approval from the IT Manager and Data Protection Officer.
5. Data destruction standard
Functional storage media: software overwriting to HMG Infosec Standard 5 minimum. Non-functional or high-sensitivity media: physical destruction.
6. Documentation
A data destruction certificate and waste transfer note must be obtained for every disposal and filed in [location] for a minimum of [X] years.
7. Prohibited actions
[See prohibited actions list above.]
8. Breaches
Any breach of this policy must be reported to the Data Protection Officer within 24 hours.
For a practical pre-disposal task list, see our IT asset disposal checklist. When you are ready to choose a certified ITAD provider, our business services page describes how Recycle4Charity operates and what documentation we supply.