Choose an ITAD company in the UK by checking four things: certified information security (ISO 27001 as a minimum), a recognised data destruction standard (NIST 800-88 or HMG IS5), serial-matched certificates of destruction, and legal waste credentials such as waste carrier registration. Then test rebate models, insurance and premises before you sign anything.
Key facts at a glance
- ISO 27001 certifies a company's security management system, not each individual wipe. Always check the certificate scope.
- ADISA ICT Asset Recovery Standard 8.0 is an ICO-approved UK GDPR certification scheme specific to ITAD.
- AATF status relates to WEEE evidence notes for producers. It is not a legal requirement for disposing of your own equipment.
- NIST 800-88 and HMG IS5 are the two sanitisation standards worth asking about. Both require verification.
- A certificate of destruction without serial numbers will not survive an audit.
- A 12-question scorecard for supplier meetings is included below.
Why does your choice of ITAD company matter?
Under UK GDPR, your business stays responsible for personal data even after a contractor drives the equipment away. If a supplier resells an unwiped laptop, the breach is yours. The ICO can fine up to £17.5 million or 4% of annual global turnover, and it expects controllers to have checked their processors properly. Environmental law works the same way. The duty of care in the Environmental Protection Act 1990 means you must take reasonable steps to ensure your waste reaches an authorised operator. If your old servers turn up fly-tipped, the paper trail leads back to you. Good IT asset disposal closes both risks at once: certified data destruction, lawful waste handling and documentation that proves each step. The checklist below shows how to separate suppliers who can evidence that from suppliers who simply say it.
Which certifications should an ITAD company hold?
ISO 27001 is the baseline certification to look for, but you need to know what it actually covers. ISO 27001 certifies an information security management system, or ISMS. It confirms the company identifies security risks, applies controls and passes independent audits. It does not, by itself, guarantee any single hard drive was wiped. So check three details: the certificate number, the certification body that issued it, and the scope statement. The scope must cover data destruction and asset recovery, not just an office IT system. Alongside ISO 27001, confirm the legal basics. The company should be a registered waste carrier, which you can verify free on the Environment Agency public register. Its site should hold an environmental permit or a registered exemption that matches the work. A T11 exemption, for example, allows the repair and refurbishment of waste electronics for reuse. No carrier registration and no permit means no contract.
What do ADISA and AATF mean, and do you need them?
ADISA and AATF appear in most ITAD comparisons, so it pays to know exactly what each one covers. ADISA ICT Asset Recovery Standard 8.0 is an industry-specific certification for asset disposal firms. It is approved by the ICO as a UK GDPR certification scheme, and it audits the full recovery process from collection through to sanitisation. It is a strong signal, and common among suppliers serving government and finance. An AATF is an Approved Authorised Treatment Facility under the WEEE Regulations 2013. AATFs can issue evidence notes that prove treatment tonnage, which matters to equipment producers and their compliance schemes. A business disposing of its own kit does not need its contractor to be an AATF. You need a registered carrier, an authorised site and proper transfer paperwork. Some excellent ITAD companies hold both badges. Others provide equal assurance through ISO 27001, open audits and serial-level reporting. Judge the evidence, not the logo count.
NIST 800-88 or HMG IS5: which data destruction standard do you need?
NIST 800-88 and HMG IS5 are the two sanitisation standards UK ITAD companies quote most often. NIST 800-88 is the US government's media sanitisation guideline, now the commercial default worldwide. It defines three levels, Clear, Purge and Destroy, and requires verification that the process worked. It also deals properly with SSDs, where simple overwriting can miss data. HMG IS5 is the UK government's standard, with Baseline and Enhanced levels. IS5 Enhanced is the higher-assurance option used for sensitive and government data, combining overwriting with verification. For most businesses, either standard is defensible if the process is verified and documented per device. The sharper questions are these: which standard applies to which media type, how is each wipe verified, and what happens to drives that fail wiping? The correct answer to the last one is physical destruction. A good secure data destruction service will answer all three without hesitation.
How do you test the quality of a certificate of destruction?
A certificate of destruction is only as strong as the detail printed on it. Ask every shortlisted supplier for a sample certificate before you sign, then apply a simple test. Does it list each device by serial number, make and model? Does it state the destruction method and the standard applied? Does it record the date, the facility and an authorised signatory? Can each line be matched back to your own asset register? A one-page letter saying "40 computers destroyed" fails every part of that test, and it will fail an ICO audit for the same reason. Certificates should also arrive after destruction, never at the point of collection. Our guide to certificates of destruction covers the required contents in full. In short: if the sample certificate is vague, the process behind it usually is too.
What insurance and liability questions should you ask?
Liability does not transfer just because the equipment left your building. Before contracting, get written answers to five questions. First, at what exact point does custody pass to the supplier, and how is it recorded? Second, what professional indemnity and public liability cover does the company hold, and will it share the insurance certificates? Third, is there specific cover for data breach events, not just physical damage? Fourth, are subcontractors used at any stage, and if so, do the same standards and insurance apply to them? Fifth, what liability cap sits in the contract, and is it realistic against the cost of a breach? A supplier that hesitates on any of these is telling you something. A supplier that answers in writing, with documents attached, is giving you the audit trail your data protection officer will one day ask for.
How do ITAD rebate models work?
UK ITAD companies pay rebates in three main ways: revenue split, fixed price per unit, or price per weight. A revenue split means the supplier resells your equipment and returns an agreed percentage of the sale price. It usually pays the most for recent kit, but only if you receive serial-level resale reporting, so you can see what each asset sold for. A fixed price per unit gives certainty up front. It suits standard fleets, though unusual or high-spec items can be undervalued. Price per weight pays scrap rates per tonne. That model is fine for genuine end-of-life scrap and completely wrong for three-year-old laptops, which are worth far more as working devices. Whatever the model, ask two questions: is the figure quoted gross or net of service fees, and how will the final statement be broken down? A transparent IT equipment buyback report shows every line, every grade and every deduction.
What are the red flags when choosing an ITAD company?
The riskiest ITAD suppliers look cheap and helpful right up to the moment something goes wrong. Watch for these warning signs:
- Cash-today buyers. Websites offering instant cash with no process, no premises and no paperwork.
- No named facility. If a supplier will not say where your data-bearing devices are processed, or refuses a site visit, walk away.
- Cherry-picking. Suppliers who take only the working, resellable kit and leave you to deal with the rest. Full-service ITAD takes the whole estate.
- Certificates at collection. A certificate of destruction issued before destruction has happened is a fiction.
- No waste carrier number. Registration takes minutes to verify. Its absence is never an oversight.
- Unexplained free services. Free is a legitimate model when resale value funds it. If a supplier cannot explain where its revenue comes from, assume the worst.
None of these flags is rare. Every one of them has put a UK business in the headlines at some point.
What should be on your ITAD scorecard?
Print this scorecard and put the same twelve questions to every ITAD company on your shortlist. Score each answer, and insist on evidence rather than assurances.
| # | Question | What a strong answer looks like |
|---|---|---|
| 1 | Are you ISO 27001 certified, and does the scope cover ITAD? | Certificate number, certification body and a scope statement naming data destruction. |
| 2 | Do you hold industry-specific certification such as ADISA? | Either yes with a current certificate, or an honest account of the assurance offered instead. |
| 3 | Are you a registered waste carrier? | A registration number you can check on the Environment Agency register. |
| 4 | What permit or exemption covers your treatment site? | A named permit or registered exemption (such as T11) matching the activity. |
| 5 | Which sanitisation standard do you apply, and to which media? | NIST 800-88 or HMG IS5, mapped to media types, with verification described. |
| 6 | What appears on your certificate of destruction? | A sample showing serials, method, standard, date, site and signatory. |
| 7 | When does liability transfer, and what insurance backs it? | A defined custody point plus insurance certificates on request. |
| 8 | Can we visit the facility that processes our devices? | Yes, with a named address and an open invitation. |
| 9 | How is equipment tracked from our door to destruction? | Asset-level chain of custody, reconciled against your inventory. |
| 10 | How are rebates calculated and reported? | A clear model (split, fixed or weight) with line-by-line statements. |
| 11 | Do you take whole estates or working equipment only? | Everything collected, including items with no resale value. |
| 12 | What happens to equipment that cannot be resold? | Recycling with zero landfill, and evidence of where materials go. |
How does Innovent answer these twelve questions?
We built our service to pass this scorecard, so here are our answers, including the honest ones. Innovent is ISO 27001 certified, with information security management covering our disposal and destruction operations. We do not hold ADISA certification and we are not an AATF; we say so plainly, because question two deserves a straight answer. Our assurance rests instead on ISO 27001, our registered waste carrier status, a T11 exemption covering repair and refurbishment for reuse, serial-matched asset reports on every job, and an open invitation to visit our solar-powered facility in Ellesmere Port. We wipe drives to NIST 800-88-compliant processes and destroy media to HMG IS5 (Enhanced) where required, with failed drives physically destroyed. Every data-bearing device is tracked by serial from your door to final disposition, and every certificate is issued after destruction, never before. Rebates are paid through our buyback programme with itemised statements, we collect whole estates free of charge nationwide, from computer recycling in Manchester to single-site clearances anywhere in the UK, and nothing we process goes to landfill. To put us on your shortlist, book a collection online or call 0151 355 5482 and ask us all twelve questions.
Frequently asked questions
What is an ITAD company?
An ITAD (IT asset disposition) company manages the retirement of business IT equipment. It collects redundant devices, destroys the data they hold to a recognised standard, resells what has value, recycles the rest and documents every step, so the business can prove compliance with UK GDPR and waste law.
Does my ITAD provider need to be an AATF?
No. AATF approval lets a facility issue WEEE evidence notes, which producers and compliance schemes need to prove recycling tonnage. A business disposing of its own equipment needs a registered waste carrier, an authorised or exempt treatment site, correct transfer paperwork and certified data destruction, not an AATF.
Is NIST 800-88 or HMG IS5 better for data destruction?
Neither is universally better. NIST 800-88 is the commercial default and handles SSDs well through its Clear, Purge and Destroy levels. HMG IS5 (Enhanced) is the UK government standard for sensitive data. Both are defensible when each device is verified and documented; unverified wiping under any name is not.
Can a genuinely free ITAD service be trusted?
Yes, if the supplier can explain how it is funded. Resale value from refurbished equipment typically covers collection and processing, which is why reputable firms collect free and still pay rebates. Be cautious only when a supplier cannot explain its revenue model or produces no compliance paperwork.
How many quotes should I get before choosing an ITAD company?
Three is a sensible minimum. Put the same twelve scorecard questions to each supplier, request a sample certificate of destruction and a sample rebate statement from every one, and compare the evidence side by side. Differences in documentation quality usually show up faster than differences in price.
