IT Recycling: A Practical Guide to Secure Disposal for UK Businesses
Most offices have a cupboard. Inside it are eleven laptops nobody has switched on since 2021, a stack of desktop towers, a few phones and at least one server that was decommissioned so long ago that nobody remembers what was on it.
That cupboard is a liability sitting on your floor. Every device in it still holds data, and every device in it is classed as waste electrical equipment the moment you decide to get rid of it. IT recycling is how you deal with both problems at once, legally and with a paper trail that stands up if anyone asks.
Here is what the process actually involves, what the law expects of you, and what a competent IT recycling company should be handing back at the end of it.
![]() |
| Secure IT Recycling |
What IT recycling actually means
The term covers more than putting old computers in a skip marked electrical.
Done properly, IT recycling is a chain of separate steps. Equipment is collected under a documented transfer of responsibility. Data-bearing media is identified and either wiped to a recognised standard or physically destroyed. Working equipment is assessed for reuse. Whatever cannot be reused is broken down so that the metals, plastics and circuit boards go back into the material stream rather than into landfill.
The industry term for the whole cycle is IT asset disposition, often shortened to ITAD. Whether you call it IT recycling, IT disposal or ITAD, the obligations are the same.
Disposal of IT equipment is a data problem before it is a waste problem
This is the part organisations get wrong most often.
A laptop leaving your building is not an IT problem. It is a potential personal data breach with wheels on. Under UK GDPR, you remain the data controller for personal data held on that device right up until it is verifiably destroyed or sanitised. Handing it to a third party does not transfer that responsibility, it just adds a processor to the chain.
Article 5(1)(f) requires appropriate security of personal data, including protection against unauthorised processing and accidental loss. A hard drive that turns up on an auction site with your customer records still readable is a fairly direct failure of that. Penalties under UK GDPR reach £17.5 million or four per cent of global annual turnover, whichever is higher, though the more common outcome is reputational rather than financial.
The exposure is broader than most people assume. Photocopiers and multifunction printers store scanned documents on internal drives. Networking kit holds configuration and credentials. Phones and tablets hold everything. Even a device that appears dead can have a perfectly readable drive inside it.
The legal position: WEEE and duty of care
Two separate frameworks apply to UK businesses.
The Waste Electrical and Electronic Equipment Regulations 2013 cover the environmental side. Electrical equipment must not go to landfill, and it has to be treated at an approved facility. If you are disposing of equipment used in a business, you fall under the business-to-business provisions rather than the household route, which is why you cannot simply take a pallet of office laptops to the local tip.
Separately, section 34 of the Environmental Protection Act 1990 places a duty of care on anyone who produces, holds or disposes of controlled waste. In practice that means you must check that whoever collects your equipment is a registered waste carrier, and you must keep the waste transfer documentation. Transfer notes need to be retained for two years.
The duty of care point matters because it is not delegable. If your equipment is fly-tipped three counties away, the trail leads back to you, and the defence is your paperwork.
Secure IT disposal: what to check before you appoint anyone
The market ranges from serious certified operators to a man with a van who will take your servers away for free. The free offer is the one to be careful about, because the value is in the components and there is no incentive to document anything.
A few checks worth making.
Confirm the company holds a waste carrier registration with the Environment Agency, or SEPA in Scotland and NRW in Wales. The registration number is public and takes a minute to verify.
Ask which data destruction standard they work to. NIST SP 800-88 is the reference most credible providers cite for media sanitisation. For physical destruction of confidential material, BS EN 15713 sets out the requirements. ADISA certification is the UK-specific accreditation for IT asset disposal specifically, and it involves unannounced audits.
Ask how equipment is handled between your building and their facility. Sealed vehicles, vetted staff and a documented chain of custody are the difference between secure IT disposal and a van.
And ask what happens to devices they cannot wipe. Some drives fail mid-process. A good provider will tell you their default is physical destruction in that case rather than quietly putting the unit aside.
Reuse or destruction: how the decision gets made
Not everything needs shredding, and there is a genuine environmental argument for reuse where the data risk can be properly closed off.
Equipment that is under about five years old, functional and wipeable can usually be sanitised and resold or donated. That has value, and some providers will offset your disposal cost against the resale value of the fleet.
Equipment that is dead, obsolete, or carrying data you are not prepared to see leave the building in any form goes to destruction. Regulated sectors often take this route by policy regardless of device age. Legal, financial services, healthcare and public sector clients frequently specify physical destruction of all storage media as standard.
The honest position is that reuse is better environmentally and destruction is better for certainty. A sensible policy usually splits the fleet: destroy the storage media, refurbish the hardware around it.
The process of laptop recycling, step by step
Laptops are the most common item in a business disposal, so it is worth walking through what happens to one.
First comes the audit. Each unit is logged by make, model and serial number before it leaves your site, and that list becomes the basis of everything that follows. Without it there is nothing to reconcile the final certificate against.
Second, collection under a documented transfer. You sign, the carrier signs, and a waste transfer note is raised. Keep your copy.
Third, the drive is separated from the chassis. In most modern laptops that means opening the base and removing an M.2 or SATA drive. Soldered storage, which is now common in slim models and all Apple silicon machines, cannot be removed, so the whole mainboard becomes the data-bearing item.
Fourth, data destruction. The drive is either overwritten and verified using software that produces a per-device report, or it is physically destroyed. Mechanical drives can be degaussed or shredded. Solid state drives should be shredded rather than degaussed, because degaussing works on magnetic media and does nothing to flash memory. This distinction catches people out and is worth asking your provider about directly.
Fifth, the remaining hardware is either refurbished for resale or broken down. Batteries are removed and handled separately as hazardous waste. Screens, aluminium, plastics and circuit boards are separated into material streams.
Sixth, reporting. You receive an asset list reconciled against what you sent, with the outcome recorded for each serial number.
Hard drives: why deleting files is not enough
Deleting a file removes the pointer to it, not the data. Formatting a drive does slightly more and still leaves the contents recoverable with tools that cost nothing to download.
A single-pass overwrite of the full drive is genuinely effective on conventional hard drives, and the old advice about needing dozens of passes is out of date. Solid state drives are more complicated, because wear levelling means the controller decides where data physically sits and an overwrite command may not reach every cell. This is why the built-in secure erase or crypto-erase commands, or physical destruction, are the recommended routes for SSDs.
Where certainty matters more than recovery value, hard drive destruction is the straightforward answer. The drive is shredded or crushed to the point where the platters or memory chips cannot be reassembled, and the destruction is documented.
What you should receive at the end
The paperwork is the point of using a professional provider, so check what you are getting.
You should have a waste transfer note covering the collection, an asset report listing every serial number and its outcome, a certificate of destruction or data sanitisation referencing those serials, and confirmation of the treatment facility and recycling rate achieved.
A certificate that says only "IT equipment destroyed" with a date on it proves very little. One that ties specific serial numbers to specific outcomes is what an auditor, an insurer or the ICO would actually want to see.
Keep these with your information asset register. If you ever need to demonstrate that a device was disposed of properly, you will need to find the record quickly rather than knowing it exists somewhere.
Coverage, volume and cost
Cost depends on volume, the mix of equipment and whether any of it holds resale value. A single pallet of old desktops from one office is priced differently from a rolling contract across multiple sites.
If you operate from several locations, ask about national IT disposal coverage before you commit, because a provider who is genuinely set up for multi-site collection will handle consolidated reporting across all of them. That matters more than it sounds. Chasing four separate certificates from four regional suppliers for one audit is a poor use of anyone's week.
Volume also affects the destruction option. On-site destruction, where the equipment is processed in a mobile unit outside your building and never leaves in readable form, costs more and is worth it for high-sensitivity material. Off-site destruction at a secure facility is the standard route for most business disposals.
Talk to Total Shred
Total Shred handles secure IT disposal alongside document destruction for businesses across the UK, from single collections to scheduled contracts. That includes hard drive destruction, laptop and desktop disposal, server decommissioning and full asset reporting with certificates tied to serial numbers.
If you have a cupboard full of equipment and no clear record of what is in it, that is the normal starting point rather than an unusual one. Get in touch with a rough count of devices and we can tell you what the process looks like, what documentation you will receive and what it will cost.
FAQ
What is IT recycling?
IT recycling is the controlled disposal of redundant computers, laptops, servers, phones and related equipment. It covers data destruction on any storage media, reuse or refurbishment where the equipment still has life in it, and material recovery for whatever cannot be reused. In the UK it sits under the WEEE Regulations 2013 for the environmental side and UK GDPR for anything holding personal data.
Can I just throw old computers in the skip?
No. Electrical equipment is banned from landfill under the WEEE Regulations, and business waste carries a duty of care under the Environmental Protection Act 1990. You also remain responsible for any personal data on those devices. Equipment must go to an approved treatment facility via a registered waste carrier, with a transfer note kept for two years.
Does deleting files or formatting the drive remove the data?
No. Deleting removes the reference to a file rather than the file itself, and formatting leaves most content recoverable with freely available tools. Proper sanitisation means a verified full-drive overwrite, a manufacturer secure erase command, or physical destruction of the media. Anything less is recoverable.
Is degaussing enough for solid state drives?
No. Degaussing disrupts magnetic fields, which works on traditional spinning hard drives but has no effect on the flash memory in an SSD. Solid state media should be handled with a crypto-erase or secure erase command, or physically shredded. Ask any provider how they distinguish between the two media types.
What documents should I get after an IT disposal?
A waste transfer note for the collection, an asset report listing each device by serial number, and a certificate of destruction or sanitisation that references those serial numbers. You should also be able to confirm which treatment facility processed the equipment. A generic certificate with no serial numbers on it has limited evidential value.
What is the difference between IT recycling and IT asset disposal?
They largely describe the same activity. IT asset disposal, or ITAD, tends to be used where recovering value through resale and refurbishment is part of the objective. IT recycling emphasises the material recovery and environmental compliance side. Both should include secure data destruction as a matter of course.
Do you offer national IT disposal for multi-site businesses?
Yes. Collections can be arranged across multiple UK sites with consolidated asset reporting, so you receive one reconciled set of documentation rather than chasing separate certificates from each location. Contact Total Shred with your site list and approximate device counts for a quote.
How much does secure IT disposal cost?
It depends on volume, equipment mix and whether any of the fleet retains resale value, which can offset the cost. On-site destruction costs more than off-site processing at a secure facility. For an accurate figure you will need a rough count of devices by type and the number of collection points.

Comments
Post a Comment