INNOVENT RECYCLING

The ITAD Glossary: 40 Terms UK Businesses Should Know

IT asset disposition (ITAD) has a language of its own. This glossary defines the 40 terms UK businesses meet most often when retiring IT equipment, from WEEE and duty of care to NIST 800-88 and revenue splits. Each definition is self-contained, so you can cite it in a policy, tender or audit without further reading.

Key facts at a glance

  • 40 terms, listed A to Z, each with its own link you can bookmark or cite
  • Covers data security standards (NIST SP 800-88, HMG IS5), UK waste law (WEEE Regulations 2013, duty of care) and resale terms (rebates, grades, revenue splits)
  • Written for UK businesses: Environment Agency registrations, ICO enforcement and HMRC points included
  • Definitions are neutral and factual, so they can go straight into tender documents
  • Questions about a term? Call Innovent Recycling on 0151 355 5482

Why does ITAD terminology matter for UK businesses?

ITAD terminology matters because disposal contracts, waste law and data protection rules all turn on precise definitions. A quote that promises a "wipe" tells you little on its own. Does it mean a NIST 800-88 clear, a purge or physical destruction? A carrier without the right registration puts your duty of care at risk, and that duty cannot be passed on. The difference between a rebate and a revenue split changes how much money comes back from a refresh.

Shared vocabulary also speeds up procurement. When your tender asks for serial-matched certificates, an unbroken chain of custody and purge-level sanitisation, suppliers know exactly what to price. You can then compare bids like for like. The 40 definitions below give IT managers, finance teams and data protection officers that common language.

How do I use this glossary?

The terms run A to Z. Each entry stands on its own, so you can read one definition, link to it from an internal policy, or share it with a colleague. Use the index below to jump straight to a term.

Terms A to C

This section covers the accreditation bodies, tax points and certification terms that appear early in the alphabet. Several of these — AATF and ADISA in particular — describe voluntary schemes, so it pays to know what each one does and does not prove.

AATF (Approved Authorised Treatment Facility)

An Approved Authorised Treatment Facility (AATF) is a site approved by a UK environmental regulator to treat waste electrical and electronic equipment and issue evidence notes. Producer compliance schemes use those notes to prove their members have financed WEEE treatment. Approval comes from the Environment Agency in England, with equivalent bodies elsewhere in the UK. Not every legitimate IT recycler is an AATF; many operate lawfully under permits or registered exemptions instead.

ADISA

ADISA is an independent certification scheme that audits IT asset disposal companies against its ICT Asset Recovery Standard. The audits focus on how data-bearing assets are collected, transported, processed and sanitised. ADISA's Standard 8.0 has been approved by the Information Commissioner's Office as a UK GDPR certification scheme. Certification is voluntary, and it is one of several ways a disposal provider can evidence sound practice.

Asset tag

An asset tag is a physical label carrying a unique identifier that ties a device to an organisation's asset register. Tags support tracking through the asset's working life and during disposal. A good ITAD process records each asset tag and serial number at collection, then matches both to the final wipe or destruction record. Tags should be removed before resale so refurbished devices cannot be traced back to the original owner.

Benefit in kind (BIK)

Benefit in kind (BIK) is a taxable perk an employee receives on top of salary, and it can arise when retired IT equipment is sold or given to staff. If a company passes a laptop to an employee for less than its market value, the difference may count as a taxable benefit. That benefit may need reporting to HMRC. Many businesses route staff sales through their ITAD provider to set a defensible market price.

Certificate of destruction (CoD)

A certificate of destruction (CoD) is a formal document confirming that the data on a specific device has been destroyed or put beyond recovery. A credible CoD records the serial number, the method used, the standard applied and the date. Serial-matched certificates are the evidence auditors and regulators expect. Our guide to certificates of destruction explains what a valid UK certificate must contain.

Chain of custody

Chain of custody is the documented record of who held an IT asset at every point between collection and final disposition. It often covers named staff, vehicle details, transfer times, secure storage and each processing step. An unbroken chain of custody lets a business prove that no device went missing between its office and the wiping or shredding line. Gaps in this record are a common audit finding.

Circular economy

The circular economy is an economic model that keeps products and materials in use for as long as possible through reuse, repair, refurbishment and recycling. In IT terms, it means a retired laptop is refurbished and resold rather than scrapped, and only true end-of-life equipment is broken down for material recovery. Choosing reuse-led disposal is one of the most direct ways a business can take part.

Clear (NIST 800-88)

Clear is the first of three sanitisation levels defined in NIST SP 800-88, using standard read-and-write commands to overwrite the data on a device. Clearing protects against simple recovery attempts, such as consumer file-recovery software. It is seen as suitable where media stays within the organisation or holds lower-risk data. For confidential business data, the stronger purge or destroy levels are normally specified instead.

Cryptographic erasure

Cryptographic erasure destroys the encryption key protecting a self-encrypting drive, leaving the stored data as unreadable ciphertext. Because only the key is erased, the process takes seconds even on very large drives. NIST SP 800-88 recognises it as a purge technique, provided the drive was fully encrypted and the key cannot be recovered. It is widely used on modern SSDs and smartphones.

Terms D to F

The letter D carries most of the data protection vocabulary. These are the terms your data protection officer will care about most, because they define who stays responsible for information after equipment leaves the building.

Data-bearing device

A data-bearing device is any piece of equipment that stores information, not just obvious items such as laptops and servers. Printers, photocopiers, routers, switches, phones and CCTV recorders all hold data that can identify people or expose company information. A disposal process that only sanitises computers leaves these devices as an unmanaged risk. ITAD scopes should list every data-bearing asset type on site.

Data controller

A data controller is the organisation that decides why and how personal data is processed. It stays legally responsible for that data until the data is destroyed. Under UK GDPR, disposing of old equipment does not transfer this responsibility. If a discarded drive causes a breach, the ICO holds the controller — your business — to account, even where a contractor caused the failure.

Data processor

A data processor is an organisation that handles personal data on behalf of a data controller. An ITAD provider acts as one when it wipes or destroys your drives. UK GDPR Article 28 requires a written contract setting out the processor's security duties. Businesses should check a provider's measures, such as ISO 27001 certification, before handing over data-bearing equipment.

Data sanitisation

Data sanitisation is the process of making data on a storage device impossible to recover, whether by overwriting, degaussing, cryptographic erasure or physical destruction. It differs from deletion, which only removes pointers to files while leaving the data itself intact. Professional secure data destruction combines a recognised sanitisation method with verification and a serial-matched certificate for every data-bearing device processed.

Degaussing

Degaussing destroys data by exposing magnetic media to a powerful magnetic field that scrambles the recorded patterns. It is effective on traditional hard drives and backup tapes, and it leaves the media permanently unusable. Degaussing does nothing to solid-state drives or USB sticks, because flash memory stores data electrically rather than magnetically. SSDs need overwriting, cryptographic erasure or shredding instead.

Destroy (NIST 800-88)

Destroy is the highest sanitisation level in NIST SP 800-88 and means physically destroying the storage media so it can never be used again. Techniques include shredding, disintegration and incineration. Destruction is specified for the most sensitive data, or for failed drives that cannot be wiped and verified. Even destroyed media should be tracked by serial number so each device can be certified.

Data Protection Act 2018 (DPA 2018)

The Data Protection Act 2018 is the UK law that sits alongside UK GDPR and tailors data protection rules for the UK. It sets out the Information Commissioner's enforcement powers and creates criminal offences, including unlawfully obtaining personal data. For IT disposal, its practical effect mirrors UK GDPR: personal data must be kept secure until it has been properly destroyed.

Duty of care

Duty of care is a legal obligation under section 34 of the Environmental Protection Act 1990 that makes every business responsible for its waste from creation to final disposal. You must store waste safely, describe it accurately and pass it only to authorised carriers and sites. The duty cannot be contracted away, and breaches can bring unlimited fines. Checking registrations before collection is how you discharge it.

DWT (pennyweight)

DWT stands for pennyweight, a traditional unit used to weigh and price precious metals, including those recovered from electronics. One pennyweight equals about 1.555 grams, and there are 20 pennyweights in a troy ounce. You may see dwt pricing when refiners quote for gold, silver, palladium or platinum reclaimed from circuit boards. Most UK ITAD paperwork uses kilograms; dwt appears mainly in refining quotes. Note that in waste compliance contexts, DWT can instead mean digital waste tracking, DEFRA's digital record service for UK waste movements.

E-waste

E-waste is any discarded product with a plug or a battery, from servers and laptops to cables and phones. It is the world's fastest-growing waste stream: the UN's Global E-waste Monitor recorded around 62 million tonnes generated worldwide in 2022. E-waste contains valuable metals alongside hazardous substances, which is why UK law requires proper treatment through IT recycling rather than landfill.

End of life (EOL)

End of life (EOL) is the point at which an IT asset no longer meets business needs. It may have failed, fallen out of support or been replaced in a refresh. Manufacturers also use EOL to mark the date a product stops being sold or supported. An asset at end of life for one organisation may still hold resale value for another, which is what makes buyback possible.

Factory reset

A factory reset restores a device's software to its original settings, but it is not certified data sanitisation. On many devices, reset data can still be recovered with forensic tools, and a reset produces no verification report or certificate. Resets are acceptable as a first step before handover, not as final destruction. Auditors expect a documented wipe or physical destruction for business devices.

Terms G to N

This short section holds the three heavyweight standards and process terms that anchor most ITAD contracts. If you learn only three entries from this glossary, make it these.

HMG IS5

HMG Infosec Standard No. 5 (HMG IS5) is a UK government standard for the secure sanitisation of storage media. It defines two levels: Baseline, for routine data, and Enhanced, for sensitive or protectively marked information. Enhanced-level destruction is often specified in public sector contracts. Commercial providers apply IS5 methods so that private-sector customers can get government-grade destruction of their drives.

ITAD (IT asset disposition)

IT asset disposition (ITAD) is the managed process of retiring business IT equipment securely, legally and with as much value recovered as possible. It covers collection, data destruction, refurbishment, resale and recycling, all backed by an audit trail. ITAD differs from simple waste removal because every asset is tracked by serial number. Our IT asset disposal page explains the process step by step.

NIST SP 800-88

NIST Special Publication 800-88 is the most widely referenced standard for media sanitisation, published by the US National Institute of Standards and Technology. It defines three levels — clear, purge and destroy — and matches each to media types and data sensitivity. Although it is an American publication with no legal force in the UK, British contracts, auditors and disposal providers treat it as best practice.

Terms P to R

The P-to-R terms are mostly commercial. They decide how much money comes back from a refresh and how disposal costs are structured, so procurement and finance teams should know them as well as IT does.

Producer compliance scheme (PCS)

A producer compliance scheme is a body that companies join to meet their WEEE Regulations duties when they place electrical equipment on the UK market. The scheme finances the collection and treatment of an agreed share of the UK's WEEE on behalf of its members. Compliance schemes matter mostly to manufacturers and importers; a business disposing of its own IT deals with carriers and treatment sites instead.

Purge (NIST 800-88)

Purge is the middle sanitisation level in NIST SP 800-88, applying techniques that defeat laboratory-grade recovery attempts. Methods include firmware secure-erase commands, overwriting with verification, degaussing of magnetic media and cryptographic erasure. Purged drives can be safely reused or resold, which makes purge the workhorse level for ITAD: it protects the data while preserving the asset's resale value.

Rebate

A rebate is a payment made to a business for the resale value of its retired IT equipment. Working laptops, servers and network kit hold second-hand value, and a rebate returns part of that value to the original owner, offsetting or even exceeding disposal costs. Rebate levels depend on age, condition and market demand. Our IT equipment buyback page shows how valuations are built.

Redeployment

Redeployment means reusing an IT asset elsewhere inside the same organisation instead of disposing of it. A laptop from a leaver can be wiped, re-imaged and issued to a new starter, extending its life at minimal cost. Redeployment is usually the highest-value option in an asset's lifecycle, so good ITAD policies check for it before any equipment is released for resale or recycling.

Refurbishment grades A/B/C

Refurbishment grades A, B and C describe the cosmetic condition of used IT equipment and directly affect resale value. Grade A is near-new with minimal signs of use. Grade B shows light marks or wear that do not affect function. Grade C works fully but carries visible scratches, dents or worn keys. Grading is a market convention rather than a formal standard, so definitions vary slightly between sellers.

Remarketing

Remarketing is the resale of refurbished IT equipment on the second-hand market after data sanitisation, testing and grading. It is how ITAD providers turn retired assets into rebates for their clients while keeping working equipment in circulation. A provider's resale reach matters: the stronger the remarketing channels, the higher the value returned and the fewer devices broken down for parts.

Revenue split

A revenue split is a buyback pricing model in which the resale proceeds of refurbished equipment are shared between the ITAD provider and the client at an agreed percentage. It contrasts with a fixed rebate, where a price per unit is agreed up front. Splits can return more on desirable stock but carry market risk. Contracts should state the percentage, allowable deductions and reporting frequency.

Right to repair

Right to repair is the principle that owners should be able to fix the products they buy, backed by laws requiring spare parts and repair information. UK rules introduced in 2021 cover certain appliances and televisions but do not yet extend to laptops or phones. The movement still shapes IT buying, because repairable equipment lasts longer, holds value better and supports reuse targets.

Terms S to Z

The final group mixes destruction methods with the waste paperwork every UK business should recognise. These are the terms to check before you sign a collection booking.

Shredding

Shredding is the mechanical destruction of storage media into small particles so that data can never be recovered and the device can never be reused. Hard drives, SSDs, tapes and phones can all be shredded. The required particle size depends on the media: flash storage needs finer shredding than magnetic drives because data sits in tiny chips. Shredded material then enters metal and plastic recycling streams.

T11 exemption

A T11 exemption is an Environment Agency waste exemption that allows an operator to repair or refurbish waste electrical and electronic equipment so it can be reused. Registration must be renewed every three years, and limits apply to the quantities treated. The T11 is the exemption under which many reuse-focused IT recyclers in England lawfully operate, sitting alongside carrier registration and duty of care rules.

UK GDPR

The UK General Data Protection Regulation (UK GDPR) is the UK's core data protection law, retained and amended after Brexit. It requires personal data to be kept secure throughout its life, including at disposal. Serious breaches can bring fines of up to £17.5 million or 4% of global annual turnover. Wiping or destroying drives before equipment leaves your control is part of compliance.

Urban mining

Urban mining is the recovery of metals and other materials from discarded products rather than from the ground. Circuit boards are a rich seam: gram for gram, they can contain far more gold than typical mined ore. Recovering copper, aluminium, gold, silver and palladium from old IT equipment cuts demand for primary extraction and gives e-waste a genuine economic value.

Waste carrier licence

A waste carrier licence is a registration a business needs before it can legally transport waste, including old IT equipment. In England the register is held by the Environment Agency, with equivalent bodies in the devolved nations. Anyone carrying other people's waste as part of their business must hold an upper tier registration. Before you book computer recycling in Manchester or anywhere else, check the carrier's number on the public register.

Waste transfer note

A waste transfer note is the document that records each handover of non-hazardous waste, naming both parties, describing the waste and stating how it is contained. Businesses must keep transfer notes for at least two years and produce them if the regulator asks. For IT disposal, the note works alongside asset-level records to show that duty of care obligations were met.

WEEE

WEEE stands for waste electrical and electronic equipment: anything with a plug, cable or battery that has been discarded. The WEEE Regulations 2013 govern how this waste is collected, treated and reported in the UK, placing duties on producers, distributors and treatment sites. Business IT — servers, PCs, monitors, printers and network kit — makes up a significant slice of the UK's WEEE stream.

Zero landfill

Zero landfill is a commitment that no collected material is sent to landfill; everything is reused, recycled or recovered instead. In ITAD, it means working equipment is refurbished and resold, while end-of-life devices are separated into material streams for recycling. Businesses citing disposal in ESG reports should ask providers to evidence the claim, since credible operators can show where each stream goes.

Frequently asked questions about ITAD terms

What is the difference between ITAD and IT recycling?

ITAD manages the whole retirement process: data destruction, audit trails, refurbishment and resale, with value returned where possible. IT recycling is the material-recovery stage, breaking end-of-life equipment into metals and plastics. Most businesses need both, but any device that has stored data should always enter an ITAD process first.

Is a certificate of destruction a legal requirement in the UK?

No law names certificates of destruction, but UK GDPR's accountability principle requires you to prove that personal data was securely destroyed. A serial-matched certificate is the accepted evidence in audits and ICO investigations. Treat certificates as effectively mandatory for any device that has held business or personal data.

Does NIST 800-88 apply to UK businesses?

NIST SP 800-88 is an American publication with no legal force in the UK. It applies in practice because contracts, insurers and auditors reference it as the benchmark for sanitisation. UK firms often specify NIST 800-88 methods alongside UK rules such as UK GDPR and, in government work, HMG IS5.

Do I need to use an AATF to dispose of business IT equipment?

Not necessarily. Your legal duties are to use a registered waste carrier and to ensure equipment reaches an authorised site, which can be a permitted facility or one operating under a registered exemption such as the T11. AATF status mainly matters for producer compliance evidence, not routine business disposal.

Why is deleting files or resetting a device not enough?

Deletion removes the index entry for a file, not the data itself, and factory resets often leave recoverable data behind. Neither produces verification or a certificate. Recognised sanitisation — overwriting, purging or destruction under NIST 800-88 — plus a serial-matched certificate is the standard businesses are expected to meet.

How do you put these terms into practice?

Knowing the vocabulary is step one; the next step is a disposal process that meets it. Innovent Recycling is an ISO 27001 certified ITAD provider based in Ellesmere Port. We offer free nationwide collection, NIST 800-88-compliant wiping, HMG IS5 (Enhanced) destruction, and serial-matched certificates with full asset reports. Working equipment earns buyback rebates, and nothing we process goes to landfill. To get started, book a collection online or call 0151 355 5482 — and keep this glossary to hand when you compare quotes.