The refresh gets signed off. Two hundred laptops go into a storeroom. A firm offers to take them away at no cost, and somebody in IT says yes because the cupboard is needed for something else.
Eighteen months later a stranger emails to say they bought one of your machines online, and the previous user’s mailbox is still sitting on it. The critical GDPR mistakes in IT asset disposal rarely look like mistakes at the time. They look like tidying up.
This is not a hypothetical. The ICO fined NHS Surrey £200,000 in 2013 after patient records surfaced on a second-hand computer bought through an online auction site. The trail led back to a contractor that had offered to destroy 1,570 hard drives at no charge in return for keeping the salvageable parts. There was no written contract, and nobody checked the work had been done.
What Are the Most Common GDPR Mistakes in IT Asset Disposal?
The most common GDPR mistakes in IT asset disposal are treating a factory reset as secure erasure, appointing a provider with no written processor contract, tracking assets by pallet rather than by serial number, accepting a weight receipt in place of a certificate of data destruction, and overlooking every device that is not a laptop.
All five share one root cause. Disposal gets treated as a logistics job when it is still processing, and the duties under Article 5 and Article 32 of the UK GDPR apply right up to the moment the last byte is gone.
Each mistake below comes with the fix, the evidence you should be holding, and what an auditor will ask for when they reach that part of the file.
Why Disposal Is the Weakest Point in Most IT Estates
Because nobody owns it. Procurement owns buying, IT owns running, finance owns depreciating, and disposal falls into the space between all three.
The exposure is larger than most boards assume. A four-year-old laptop can hold cached mailboxes, saved credentials, client files, HR records and browser data from systems the user forgot they ever signed into. Under Article 5(2) you have to be able to demonstrate that the data is gone, and demonstration means records rather than assurances.
Transputec regularly assesses estates where the wiping is technically sound and the paperwork is missing entirely. That combination still sits among the GDPR mistakes in IT asset disposal most likely to fail an audit.
Can You Prove What Happened to Your Last Hardware Refresh?
Tell us how your organisation retires devices today and we will show you where the GDPR mistakes in IT asset disposal are sitting, what evidence is missing, and what a defensible process should produce.
Get a Strategic ConsultationMistake 1: Treating a Factory Reset as Secure Erasure
A factory reset only destroys data reliably when the drive was encrypted and the reset genuinely discards the encryption key. On an unencrypted drive it routinely leaves recoverable material behind.
The NCSC guidance on secure sanitisation of storage media draws the line clearly. For devices running BitLocker or FileVault, a manufacturer reset provides a satisfactory level of assurance in most cases. For devices without encryption, it sets out a longer sequence:
- Overwrite the entire user accessible memory space with a fixed value.
- Check the metadata for remapping and bad sectors, since either means data may remain.
- Power the device down completely for at least fifteen minutes, removing batteries where practical.
- Read the memory back to confirm it holds the value you wrote.
Step four is the one that gets skipped. Without verification you have a procedure rather than proof. Solid state drives make it harder again, because wear levelling moves data around the chip and remapped blocks can sit outside the range a standard overwrite reaches.
The fix: encrypt every device at build time, then erase to a named standard such as NIST SP 800-88 and retain the verification log. Encryption at deployment turns disposal from a technical problem into an administrative one, which removes one of the most expensive GDPR mistakes in IT asset disposal before it can happen.
Mistake 2: Choosing a Disposal Provider Because Collection Is Free
Free collection is paid for somewhere. Usually it comes out of the resale value of the assets, which gives the provider a commercial reason to keep drives working rather than destroy them.
That is exactly what went wrong at NHS Surrey. The contractor took 1,570 hard drives at no charge in exchange for the salvageable parts, there was no written contract, nobody oversaw the destruction, and the ICO described it as one of the most serious breaches it had seen.
Under Article 28 of the UK GDPR your disposal provider is a processor acting on your instructions. The ICO’s guide to data security is explicit that your written contract must require the processor to take the same Article 32 measures you would take yourself, and must let you audit and inspect. It also names the disposal of electronic waste as a physical security measure sitting inside the security principle. If the provider loses a pallet of drives, the controller answers for it.
What to require before anything leaves the building:
- A written processor agreement, not a collection note.
- Named subcontractors, particularly for transport.
- Audit rights you could realistically exercise.
- Independent certification such as ADISA, or CAS-S accreditation for central government work.
- A stated position on what happens to assets that fail erasure.
Ask who keeps the resale value and what the provider does with a drive it cannot wipe. The answer tells you more than the certification logos on the website do.
Mistake 3: Tracking Assets by Pallet Instead of by Serial Number
Pallet-level records prove that fifty laptops arrived somewhere. They cannot prove which fifty, and which fifty is the question an auditor asks.
Chain of custody means an unbroken, documented record of who held each individual device between the desk it left and the moment its data was destroyed, tied to a serial number. Anything less is a narrative.
A workable record covers:
- Asset capture at collection by serial number or IMEI, signed by the person handing it over.
- A signed transfer at every change of hands, including any subcontracted courier.
- Sealed, tracked transport in tamper-evident packaging.
- Access-logged storage for any period the device sits waiting.
- An erasure or destruction record against that same serial number.
The weak points are predictable: devices left in an unlocked cupboard for months before a collection is booked, and logistics handed to a third party the vendor never named. Both turn up repeatedly in the GDPR mistakes in IT asset disposal we find during reviews. Transputec records at device level from the point of collection, so each asset carries its own history rather than sharing one with the consignment it travelled in.
If you cannot answer “where was serial number X on 14 March”, the gap already exists.
Mistake 4: Accepting a Weight Receipt Instead of a Certificate of Data Destruction
A document listing a quantity and a tonnage is a waste receipt. A certificate of data destruction names individual assets and states what was done to each one.
Check the certificate carries all of the following:
- Serial numbers for every asset, listed individually.
- The method, whether software erasure, degaussing or physical destruction.
- The standard applied, such as NIST SP 800-88.
- Date and location of the work.
- A named signatory at the processing facility.
On physical destruction the NCSC expects media to be reduced to particles of 6mm or less, with the particle size verified afterwards, and it expects data to be erased before destruction rather than instead of it.
Ask for the certificate format before you sign, not after the collection van has left. Transputec issues certificates against individual serial numbers and keeps the erasure evidence alongside the waste transfer notes, because the auditor asking about WEEE treatment and the auditor asking about erasure are usually the same person on the same day.
Mistake 5: Disposing of Laptops Carefully and Everything Else Carelessly
Laptops get attention because everyone knows they hold data. The equipment that quietly stores just as much tends to leave the building unrecorded.
The NCSC treats any device that might contain electronic storage media as requiring sanitisation, and its list is broader than most disposal registers: hard drives, solid state drives, memory chips, USB and SD media, magnetic tape and optical discs. In practice that pulls in a lot of hardware nobody is tracking.
- Multifunction printers and copiers, which cache scanned documents on internal drives.
- Mobile phones and tablets, especially devices collected during offboarding.
- Servers and NAS units, where one drive can carry an entire department’s history.
- Network kit, including routers, switches and firewalls holding configurations and credentials.
- Backup tapes and external drives sitting in a drawer nobody has opened since the last migration.
Build the disposal register from your asset inventory rather than from whatever happens to be in the storeroom. Missing categories are the quietest of the GDPR mistakes in IT asset disposal, because nothing looks wrong until a device that was never on a list turns up somewhere it should not be.
Fixing the Five Critical GDPR Mistakes in IT Asset Disposal
Set what you are doing now against what a defensible process produces. The gap between the two right-hand columns is your remediation list.
| Area | What Most Organisations Do | What Holds Up Under Audit |
|---|---|---|
| Erasure | Factory reset, no verification step | Full-disk encryption at build, erasure to NIST SP 800-88, verification log retained |
| Provider | Free collection on a verbal assurance | Article 28 processor contract, named subcontractors, ADISA or equivalent certification |
| Custody | Pallet-level count on a collection note | Serial-level record, signed transfers, tamper-evident tracked transport |
| Evidence | Weight receipt or quantity confirmation | Per-device certificate naming method, standard, date and signatory |
| Scope | Laptops and desktops only | Every asset holding storage media, driven from the inventory |
Work through it in that order. Encryption at build is the highest-value change, because it reduces the consequences of every later failure. The contract comes next, since it decides who carries the liability when something does go wrong.
Our companion piece on GDPR compliant device disposal across the UK and GCC covers the regulatory detail in full, and our comparison of in-house against outsourced device lifecycle management works through who should be running this day to day. Transputec’s device lifecycle management and IT procurement teams handle collection through to certified disposal, backed by ISO 27001 and ISO 14001.
Conclusion
Disposal is the last moment your organisation controls a device, and the only moment where an error becomes permanent. A laptop that leaves the building with recoverable data on it cannot be recalled, patched or explained away.
The organisations that come through an ICO enquiry or a client audit intact are not the ones with the most expensive shredder. They are the ones who can produce a serial number, a method, a certificate and a date for every asset retired in the past four years. Getting there means treating retirement as part of the device lifecycle rather than a clear-out at the end of it.
Transputec manages device collection, secure erasure, certified destruction and WEEE treatment for organisations across the UK and internationally, backed by ISO 27001, ISO 14001 and Cyber Essentials Plus. If you cannot currently trace every retired device to a destruction record, those GDPR mistakes in IT asset disposal are worth closing before somebody asks to see the file. Talk to our team about a review of how your estate is retired today.
FAQs
What Are the Most Critical GDPR Mistakes in IT Asset Disposal?
The five critical GDPR mistakes in IT asset disposal are relying on a factory reset, using a provider without an Article 28 processor contract, recording assets at pallet level rather than by serial number, accepting a weight receipt instead of a per-device certificate, and excluding non-laptop hardware from the disposal register. Each one is a documentation failure as much as a technical one, which is why they survive internal reviews and fail external audits.
How Do You Dispose of Company Laptops Under GDPR?
Record each machine by serial number, erase it to a recognised standard such as NIST SP 800-88 or physically destroy the media, then keep the certificate and the waste transfer note together. Appoint the provider under a written processor contract and confirm who handles transport, because subcontracted logistics is where most chains of custody break. Transputec’s device lifecycle management service covers collection through to certified disposal with the evidence trail built in.
Do You Need a Certificate of Data Destruction Under GDPR?
No article names the certificate specifically, but Article 5(2) requires you to demonstrate compliance, and a per-device certificate is the practical way to do it. It should list the serial number, the method, the standard applied, the date, the facility and a named signatory. A document quoting only a quantity or a total weight will not answer a question about one specific asset, which is exactly the question that gets asked after an incident.
Who Is Liable if an ITAD Provider Loses a Hard Drive?
You do, as the controller. The disposal provider is a processor acting on your instructions under Article 28, and appointing one does not transfer your accountability for the personal data. NHS Surrey was fined £200,000 for a contractor’s failure, not its own. A written processor contract, named subcontractors and audit rights will not remove the liability, though they give you a defensible position and a route to recover.
What Data Erasure Standard Does GDPR Require?
The UK GDPR names no standard. Article 32 asks for measures appropriate to the risk, so the sector convention is NIST SP 800-88 for erasure, with NCSC guidance on sanitisation and physical destruction applied for higher-risk data. Choose a named standard, apply it consistently and record the verification, because an unnamed process is difficult to defend. Our guide to GDPR compliant device disposal covers the erasure and chain of custody requirements in more depth.
This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.



