Compliance

Compliance & data security

Your data liability, properly evidenced.

We do not process your hardware. We make sure whoever does is certified to, contracted to, and evidences it — per device, in writing.

The standard we work to

NIST 800-88, certified per device

NIST Special Publication 800-88 is the media sanitisation guideline used across US federal government and adopted as the de facto standard by enterprise IT. It defines three levels of sanitisation. We specify in the tender that the appropriate level is applied per media type rather than every drive being treated the same — and check the certificates say so.

How each method should be applied, and when — the standard we hold partners to.
MethodApplied to
Clear — logical overwrite of all addressable storageDevices returning to service or resale where the controller is trusted and verification passes
Purge — cryptographic erase or block erase at firmware levelSelf-encrypting drives and modern SSDs, where overwrite alone cannot reach every cell
Destroy — physical shredding to media-appropriate particle sizeFailed drives, drives that fail erasure verification, and any media you designate destroy-only

Every unit should produce its own certificate carrying the serial number, the method applied, the verification result and the date. Not one certificate per pallet. We check that before it reaches you, and go back to the processor when it does not.

Chain of custody

Tracked from your loading bay to final disposition

The gap most disposal contracts leave open is what happens between collection and processing. We make a logged handover at every transfer of possession a condition of the work, then reconcile the record you get back.

01

Collection

Assets counted and logged on site by the processor. You receive a signed manifest before the vehicle leaves.

02

Transit

Sealed, tracked transport by vetted carriers. Any deviation is recorded against the manifest.

03

Processing

Each serial reconciled against the manifest on intake. We chase any discrepancy and flag it to you.

04

Disposition

Resale, reuse or destruction recorded per unit and closed out in your final report.

Regulatory position

What you are actually obliged to do

UK GDPR

You remain the data controller throughout, and your ITAD partner is the processor under the contract you hold with them. Article 5(1)(f) requires appropriate security including against accidental loss — an untracked device in a disposal chain is difficult to defend as appropriate, whoever was holding it.

WEEE Regulations

Business users must ensure electrical waste goes to an approved authorised treatment facility, with evidence retained. We only tender to audited processors, and we collect that evidence back for you.

Duty of care

Waste transfer documentation is a legal requirement, not paperwork for its own sake. Chasing it from the processor is our job, not yours.

This page describes the standards we work to. It is not legal advice — if you need a formal position on your own obligations, take it from your DPO or legal counsel.

Coming soon

The audit portal

Everything above, in one place, live. Search any serial number and see where that device is in its lifecycle, which buyer took it, and the destruction record against it — without emailing anyone.

  • Per-device lifecycle tracking, searchable by serial or asset tag
  • Certificates downloadable on demand, individually or as a pack
  • Buyer transparency: see who bought what, and for how much
  • Export a full audit trail for any date range
Want early access?

We are opening the portal to existing clients first. Submit an asset list and you will be on the list by default.

See the data room

Close the gap in your disposal chain.

No upfront cost. Response within one business day.

Scroll to Top