| Document owner | [Job title, e.g. IT Manager] |
|---|---|
| Approved by | [Name, job title] |
| Version | 1.0 |
| Date approved | [Date] |
| Next review date | [Date, 12 months from approval] |
This policy sets out how [Company] disposes of IT equipment at the end of its useful life. Its purpose is to protect the data held on that equipment, meet our legal duties for waste, and recover value where possible. It applies to every disposal, whether a single laptop or a full office clearance, and supports [Company]'s wider information security and data protection controls.
This policy applies to all employees, contractors and third parties who use or manage [Company] IT equipment. It covers all devices capable of storing data, and all electrical equipment owned or leased by [Company], including:
Leased equipment must be sanitised to the standards in section 5 before it is returned to the lessor.
| Role | Responsibility |
|---|---|
| [Job title, e.g. IT Manager] | Owns this policy, maintains the asset register, approves disposal vendors and authorises each disposal. |
| [Data Protection Officer / equivalent] | Confirms that data destruction methods meet UK GDPR and Data Protection Act 2018 obligations. Reviews certificates of destruction. |
| [Finance / Asset Manager] | Removes disposed assets from the fixed asset register and records any buyback rebates or resale income. |
| Department heads | Identify equipment for disposal and release it only through the process in this policy. |
| All staff | Must not sell, donate, bin or take home [Company] IT equipment. All disposals go through the IT department. |
[Company] maintains a register of all IT assets. Each entry records the make, model, serial number, assigned user, location and data classification of the device. No asset may be disposed of unless it appears on the register.
On disposal, the register must be updated with the disposal date, the method used, the vendor's certificate reference and the matching serial number. The register entry is retained after disposal in line with section 8.
No device or media may leave [Company] premises with recoverable data on it, except under a documented chain of custody with an approved vendor.
A certificate of data destruction, matched to each device serial number, is required for every disposal. Certificates are reviewed by the [Data Protection Officer / equivalent] and filed with the asset register.
[Company] only uses IT asset disposal vendors that meet all of the following criteria:
Vendor credentials are checked before first engagement and re-checked every [12] months. Evidence is kept on file.
[Company] has a duty of care under section 34 of the Environmental Protection Act 1990 for all waste it produces, including waste electrical and electronic equipment under the WEEE Regulations 2013. To meet this duty:
The following records must be kept for every disposal. They form [Company]'s evidence of compliance and must be produced on request during audits, client due diligence or regulator enquiries.
| Record | Minimum retention period |
|---|---|
| Certificates of data destruction and asset reports | 5 years |
| Asset register disposal entries | 5 years from disposal |
| Waste transfer notes | 2 years (legal minimum); [Company] retains for [5] years |
| Hazardous waste consignment notes | 3 years |
| Vendor due diligence records | Duration of the relationship plus [2] years |
Disposing of [Company] IT equipment outside this policy may lead to disciplinary action. It may also expose [Company] to enforcement action under the UK GDPR, the Data Protection Act 2018 or environmental law. Suspected breaches must be reported to the [Job title] without delay.
This policy is reviewed every 12 months, or sooner if regulations, standards or [Company] operations change.