IT Asset Disposal Policy

Document owner[Job title, e.g. IT Manager]
Approved by[Name, job title]
Version1.0
Date approved[Date]
Next review date[Date, 12 months from approval]

1. Purpose

This policy sets out how [Company] disposes of IT equipment at the end of its useful life. Its purpose is to protect the data held on that equipment, meet our legal duties for waste, and recover value where possible. It applies to every disposal, whether a single laptop or a full office clearance, and supports [Company]'s wider information security and data protection controls.

2. Scope

This policy applies to all employees, contractors and third parties who use or manage [Company] IT equipment. It covers all devices capable of storing data, and all electrical equipment owned or leased by [Company], including:

Leased equipment must be sanitised to the standards in section 5 before it is returned to the lessor.

3. Roles and responsibilities

RoleResponsibility
[Job title, e.g. IT Manager]Owns this policy, maintains the asset register, approves disposal vendors and authorises each disposal.
[Data Protection Officer / equivalent]Confirms that data destruction methods meet UK GDPR and Data Protection Act 2018 obligations. Reviews certificates of destruction.
[Finance / Asset Manager]Removes disposed assets from the fixed asset register and records any buyback rebates or resale income.
Department headsIdentify equipment for disposal and release it only through the process in this policy.
All staffMust not sell, donate, bin or take home [Company] IT equipment. All disposals go through the IT department.

4. IT asset register

[Company] maintains a register of all IT assets. Each entry records the make, model, serial number, assigned user, location and data classification of the device. No asset may be disposed of unless it appears on the register.

On disposal, the register must be updated with the disposal date, the method used, the vendor's certificate reference and the matching serial number. The register entry is retained after disposal in line with section 8.

5. Data destruction standards

No device or media may leave [Company] premises with recoverable data on it, except under a documented chain of custody with an approved vendor.

A certificate of data destruction, matched to each device serial number, is required for every disposal. Certificates are reviewed by the [Data Protection Officer / equivalent] and filed with the asset register.

6. Approved disposal vendors

[Company] only uses IT asset disposal vendors that meet all of the following criteria:

  1. Certified to ISO 27001 for information security management
  2. Registered with the Environment Agency (or SEPA, NRW or NIEA) as a waste carrier, with the registration number verified before first use
  3. Operating under an environmental permit or a registered T11 exemption for the repair and refurbishment of WEEE
  4. Able to erase or destroy data to the standards in section 5 and issue serial-matched certificates of destruction and asset reports
  5. Committed to zero landfill for collected equipment
  6. Able to provide a documented chain of custody from collection to final disposition
  7. Holding adequate insurance, including professional indemnity cover

Vendor credentials are checked before first engagement and re-checked every [12] months. Evidence is kept on file.

7. WEEE and duty of care compliance

[Company] has a duty of care under section 34 of the Environmental Protection Act 1990 for all waste it produces, including waste electrical and electronic equipment under the WEEE Regulations 2013. To meet this duty:

8. Record retention

The following records must be kept for every disposal. They form [Company]'s evidence of compliance and must be produced on request during audits, client due diligence or regulator enquiries.

RecordMinimum retention period
Certificates of data destruction and asset reports5 years
Asset register disposal entries5 years from disposal
Waste transfer notes2 years (legal minimum); [Company] retains for [5] years
Hazardous waste consignment notes3 years
Vendor due diligence recordsDuration of the relationship plus [2] years

9. Non-compliance

Disposing of [Company] IT equipment outside this policy may lead to disciplinary action. It may also expose [Company] to enforcement action under the UK GDPR, the Data Protection Act 2018 or environmental law. Suspected breaches must be reported to the [Job title] without delay.

10. Review

This policy is reviewed every 12 months, or sooner if regulations, standards or [Company] operations change.