Compliance & data security
Your data liability, properly evidenced.
We do not process your hardware. We make sure whoever does is certified to, contracted to, and evidences it — per device, in writing.
The standard we work to
NIST 800-88, certified per device
NIST Special Publication 800-88 is the media sanitisation guideline used across US federal government and adopted as the de facto standard by enterprise IT. It defines three levels of sanitisation. We specify in the tender that the appropriate level is applied per media type rather than every drive being treated the same — and check the certificates say so.
| Method | Applied to |
|---|---|
| Clear — logical overwrite of all addressable storage | Devices returning to service or resale where the controller is trusted and verification passes |
| Purge — cryptographic erase or block erase at firmware level | Self-encrypting drives and modern SSDs, where overwrite alone cannot reach every cell |
| Destroy — physical shredding to media-appropriate particle size | Failed drives, drives that fail erasure verification, and any media you designate destroy-only |
Every unit should produce its own certificate carrying the serial number, the method applied, the verification result and the date. Not one certificate per pallet. We check that before it reaches you, and go back to the processor when it does not.
Chain of custody
Tracked from your loading bay to final disposition
The gap most disposal contracts leave open is what happens between collection and processing. We make a logged handover at every transfer of possession a condition of the work, then reconcile the record you get back.
Collection
Assets counted and logged on site by the processor. You receive a signed manifest before the vehicle leaves.
Transit
Sealed, tracked transport by vetted carriers. Any deviation is recorded against the manifest.
Processing
Each serial reconciled against the manifest on intake. We chase any discrepancy and flag it to you.
Disposition
Resale, reuse or destruction recorded per unit and closed out in your final report.
Regulatory position
What you are actually obliged to do
UK GDPR
You remain the data controller throughout, and your ITAD partner is the processor under the contract you hold with them. Article 5(1)(f) requires appropriate security including against accidental loss — an untracked device in a disposal chain is difficult to defend as appropriate, whoever was holding it.
WEEE Regulations
Business users must ensure electrical waste goes to an approved authorised treatment facility, with evidence retained. We only tender to audited processors, and we collect that evidence back for you.
Duty of care
Waste transfer documentation is a legal requirement, not paperwork for its own sake. Chasing it from the processor is our job, not yours.
This page describes the standards we work to. It is not legal advice — if you need a formal position on your own obligations, take it from your DPO or legal counsel.
The audit portal
Everything above, in one place, live. Search any serial number and see where that device is in its lifecycle, which buyer took it, and the destruction record against it — without emailing anyone.
- Per-device lifecycle tracking, searchable by serial or asset tag
- Certificates downloadable on demand, individually or as a pack
- Buyer transparency: see who bought what, and for how much
- Export a full audit trail for any date range
We are opening the portal to existing clients first. Submit an asset list and you will be on the list by default.
See the data roomClose the gap in your disposal chain.
No upfront cost. Response within one business day.
