The old computers in your store cupboard are still your problem
There is a cupboard. Nearly every business has one. Four laptops nobody has switched on since the Windows 10 deadline, a desktop with a label on it saying reception, do not move, and a bare hard drive somebody pulled out of a server in 2019 and fully intended to deal with.
None of that is dead kit. It is live personal data sitting in your building, and you are still the one answerable for it. This is what actually removes the data, how to tell whether a disposal firm is what it says it is, and the second set of rules, the environmental ones, that almost nobody reads.
Deleting a file does not remove it. Formatting does not either.
NCSC's guidance on secure sanitisation opens with the sentence every IT manager should have to read once a year: simply hitting the Delete key isn't enough.
Deleting removes the pointer. The contents stay where they are until something else needs that space, which on a machine that has been sitting unplugged in a cupboard since March is never. A quick format is barely different: it writes a fresh file table over the top and leaves everything underneath intact. Recovery software that costs nothing will pull most of it back, and the people who buy job lots of second-hand business machines know that perfectly well.
Overwriting the whole drive is the real version. NCSC describes it as writing over the entire user-accessible memory space with a fixed value, all zeros for instance, and that does work. But read the phrase again. User-accessible. If the drive's own metadata shows remapped sectors or bad blocks, NCSC says plainly that data may remain on the device, because those blocks were retired by the drive's firmware years ago and nothing you run from the operating system can reach them. On a ten-year-old disk out of a server that ran hot, that is not a hypothetical.
Solid-state drives changed the answer, and most advice has not caught up
Every guide written before about 2015 says the same thing: overwrite it three times and you're fine. That advice was written for spinning platters, where a logical block address mapped to a physical spot on a disk.
An SSD does not work that way. Its controller spreads writes around to stop any one cell wearing out, which is the whole point of wear levelling, so when you tell it to overwrite a block you are making a request about a logical address and the controller decides where the write physically lands. The old copy can sit in a cell that has been quietly taken out of rotation. You cannot reach it, which is precisely the problem: neither can your wiping tool, but a lab can.
The route NCSC points at for encrypted devices is the manufacturer's factory reset, because that deletes the encryption keys. Destroy the key and the ciphertext is noise, wherever the controller left it. The hardware stays usable and can be sold or handed on.
Which gives you the single most useful thing in this article, and it is a decision you make years before disposal comes up. Encrypt the machine when you build it. BitLocker on day one turns end-of-life into a key deletion that takes under a minute. Turning it on the week you retire the laptop does almost nothing, because everything written in the four years before that may still be sitting unencrypted in blocks the new encryption never went near. That is the argument for a build standard rather than a disposal policy.
When destruction is the right answer, and what destroyed means
Sometimes the drive genuinely has to be destroyed: it has failed and will not accept a reset, or what was on it justifies protecting against somebody with a laboratory rather than somebody with a screwdriver.
For that case NCSC gives a number. Particles of 6mm or less, with the resulting particle size verified. A drive bent in a vice is not destroyed. A drive with a hole drilled through it is not destroyed either, and neither is one that has been hit with a hammer, however satisfying that is. The guidance also says something people find counter-intuitive: erase the data before you destroy the media. Destruction can go wrong, the skip can be raided, and a drive that was wiped first is a wiped drive whatever happens to the fragments.
You cannot subcontract being the controller
This is where most real failures happen, and they don't look like carelessness. They look like a business that did the right thing.
In June 2012 the ICO fined Brighton and Sussex University Hospitals NHS Trust £325,000, the largest penalty it had issued at that point. Around a thousand hard drives had been sent for destruction. At least 252 of them were later sold on eBay, carrying patient and staff records. The Trust had engaged someone to do the destruction. The penalty landed on the Trust.
The case is old now and the penalty regime has changed since, but the principle it turned on has not moved an inch. You remain the controller. Handing the boxes to a van does not hand over the responsibility, and "we used a company" is not the answer to the question the regulator will ask, which is what you did to satisfy yourself that the company was any good.
The practical version of that is dull and takes about twenty minutes. Ask which standard they hold and which of their sites it covers, because certification is granted site by site and the depot collecting from you may not be the one that was audited. Ask for asset-level records, meaning a list with a serial number against every device, not a tonnage figure. Ask what happens between the van leaving your car park and the sanitisation being done, because that gap is where the Brighton drives went.
The register that makes checking easy
Certificates of destruction are printed by the same people who are supposed to have done the destroying. Fortunately there is something better to look at.
The ICO maintains a register of approved certification schemes, and for this sector the relevant one is the ADISA ICT Asset Recovery Standard 8.0, approved in July 2021 as a UK GDPR certification scheme under Article 42 and accredited by UKAS. That accreditation is the bit that matters: it means an independent body audits the certification body, so the claim is checkable rather than self-declared. A supplier either appears as certified or does not.
The standard also introduces something called a Data Impact Assurance Level, which decides how much protection a given batch of assets needs. Worth knowing before the conversation starts, because that rating is a controller decision. The supplier will ask you how sensitive the data is, and you are the one who has to have an answer. If nobody in your business can say what was on the machines, that is the problem to fix first, and it is what an asset register kept up to date is for.
The environmental half, which nobody reads
Data protection is only one of the two rulebooks here, and the other one has its own duties.
Start with who pays, because the usual assumption is wrong. Under regulation 12 of the WEEE Regulations 2013, the producer finances the collection, treatment, recovery and disposal of business equipment they placed on the UK market on or after 13 August 2005, and also for older equipment where they are the one supplying like-for-like replacement kit. Regulation 12(2) allows the producer and the business to agree something different between themselves, and supply contracts frequently do. So the honest answer to "who pays" is: check your purchase agreement, because it may well have moved the cost onto you and you may well be paying twice.
Where the duty does fall on you as the final user, regulation 47(3) says the equipment must be treated at an approved treatment facility, or exported by an approved exporter for treatment abroad. There is no version of that sentence that includes a skip.
Then the waste duty of care, which applies to every load leaving your premises. Gov.uk's own guidance is short about it: complete a waste transfer note for each load, and check your waste carrier is registered using the public register at environment.data.gov.uk. That lookup takes a minute and it is the cheapest piece of due diligence available to you. Fly-tipped equipment with your company's asset tags still on it is a bad afternoon.
What we would actually do
In order, and none of it is complicated once somebody owns it.
Write down what you have, with serial numbers, before anything moves. Decide per machine whether it is being reused, sold on or destroyed, because those are three different processes and mixing them up is how drives end up in the wrong pile. For anything encrypted, do the manufacturer's reset and record that you did, with the date and who did it. For anything not encrypted, that is a lesson for the build standard and an overwrite or a shredder for this batch. Pull and separately account for any drive that has failed, because a dead drive cannot be sanitised and it is exactly the one people forget. Keep the paperwork: sanitisation records, the waste transfer note, and the supplier's asset-level report, and keep them somewhere that is not the cupboard the laptops were in.
One thing worth saying plainly, given the whole article is about not taking a supplier's word for it. Alpha IT is not a registered waste carrier and does not hold the ADISA certification described above. We do not collect or destroy equipment. What we do is keep the asset register so you know what exists, encrypt machines when they are built so retirement is simple later, verify and record sanitisation, and tell you which certified firms to ring. If your old hardware is piling up because Windows 10 support ended and the replacements arrived without a plan for what they replaced, a free IT health check is a sensible place to start, and our managed plans include the asset register the rest of this depends on.
And if a drive has already gone missing, that is potentially a reportable incident rather than a housekeeping problem. The clock and the thresholds are in our guide to the ICO's 72-hour rule.
Frequently asked questions
Is deleting the files and emptying the recycle bin enough?+
No. NCSC's guidance on secure sanitisation puts it bluntly: simply hitting the Delete key isn't enough. Deleting a file removes the pointer to it, not the contents, and the space is only reused when something else happens to need it. Free recovery tools get a lot of it back. On a machine that's leaving your building, deletion is not a control.
Does formatting the drive wipe it?+
A quick format writes a new file table and leaves the data where it was. Even a full overwrite has a caveat NCSC spells out: you can only overwrite the user-accessible memory space, and if the drive's own metadata shows remapped or bad sectors, data may still be sitting in the parts the drive retired years ago. Those blocks aren't reachable from outside, so nothing you run reaches them either.
Can I just overwrite an SSD?+
Not reliably. A solid-state drive's controller decides where each write physically lands, which is what wear levelling is for, so telling it to overwrite a block is a request rather than an instruction. The route NCSC points at for encrypted devices is the manufacturer's factory reset, because that deletes the encryption keys. No key, no readable data, and the drive is still usable afterwards.
So should we encrypt machines we're planning to throw away?+
Encrypt them the day they're built, not the week they're retired. Turning BitLocker on at the end doesn't help much, because everything written before that point may still be sitting in blocks the encryption never touched. Encrypted from day one, disposal is a key deletion that takes seconds. Never encrypted, and you're looking at a shredding invoice or an overwrite you can't fully verify.
We used a disposal company and they gave us a certificate. Are we covered?+
A certificate is a piece of paper produced by whoever wanted to produce it. Brighton and Sussex University Hospitals NHS Trust had a contractor, and in 2012 the ICO fined the Trust £325,000 after around 1,000 drives went for destruction and 252 turned up for sale on eBay. The penalty went to the Trust, not the contractor. Under UK GDPR you stay the controller. What's worth having instead is a supplier whose certification you can check independently, and a record listing the serial number of every asset rather than a weight in kilos.
How do we check a disposal company is genuine?+
There's a public register for this. The ICO approved the ADISA ICT Asset Recovery Standard 8.0 in July 2021 as a UK GDPR certification scheme under Article 42, and it's UKAS-accredited, so it's a claim you can verify rather than a logo. Ask which of their sites the certification covers, because certification is site-specific. Separately, check they're a registered waste carrier on the Environment Agency's public register at environment.data.gov.uk.
Can old business computers go in the skip or the general waste?+
No. Electrical waste has its own regime, and where the financing duty falls on you as the final user, regulation 47(3) of the WEEE Regulations 2013 says the equipment must be treated at an approved treatment facility or exported by an approved exporter. On top of that, waste duty of care means a waste transfer note for every load that leaves your premises, and checking the carrier taking it away is actually registered.
Who pays to recycle old business IT?+
Often not you, which surprises people. Under regulation 12 of the WEEE Regulations 2013, the producer finances collection, treatment, recovery and disposal of business equipment placed on the UK market on or after 13 August 2005, and also for older kit where they're supplying the like-for-like replacement. Regulation 12(2) lets the producer and the business agree something different between themselves, and purchase contracts often do exactly that, so read yours before assuming either way.