SalesCollab

Guide

IT asset disposal (ITAD) without the spreadsheet panic.

Decommissioning a laptop or server is the easy part. Proving you wiped it, recorded the serial, captured the wipe certificate and disposed of it through a licensed handler — that is what auditors, insurers and regulators actually want to see. Here is the practical end-to-end.

What IT asset disposal actually covers

IT asset disposal (ITAD) is the controlled process of retiring an asset from active service: removing data, recovering residual value, and either reusing, reselling, recycling or destroying the device through a licensed handler. It applies to laptops, desktops, servers, phones, tablets, network gear, printers and any storage media that ever held company data.

Done badly, ITAD leaks personal data, breaches POPIA/GDPR, blows holes in the fixed-asset register and creates an awkward gap on the insurance schedule. Done well, it produces a clean paper trail your auditor can sign off in an afternoon.

The lifecycle from decommission to disposal

  • Flag the asset for retirement in the register — record the trigger (end-of-life, damaged, replaced, lost, stolen).
  • Capture the final assignment: who had the device last, where it was returned, who signed for it.
  • Wipe the storage to NIST 800-88 (or equivalent) and attach the wipe certificate to the asset record.
  • Decide the disposal route: reuse internally, donate, resell, recycle, or destroy. Each route has different documentation.
  • Hand over to a licensed ITAD partner and attach the certificate of destruction or recycling manifest.
  • Close the asset in the register with disposal date, method, gain/loss vs book value, and the final document set.

POPIA, GDPR and the regulatory backdrop

POPIA (South Africa) and GDPR (EU/UK) both require that personal data be destroyed, deleted or de-identified when no longer needed. A laptop on a shelf with a working drive is still processing personal data in the eyes of the regulator. The Information Regulator and ICO have both issued fines for residual data on disposed equipment.

In practice this means three documents per disposed device: a wipe certificate (proving the data is gone), a chain-of-custody record (proving who handled the device at every step) and a certificate of destruction or recycling manifest from the ITAD partner.

Why wipe certificates matter

A wipe certificate is the evidence that storage media were sanitised to a recognised standard (NIST 800-88 Clear or Purge, or HMG IS5 Enhanced). It names the device, the serial number, the technician, the date, the method and the verification result.

Without one, you cannot prove the data was destroyed — and "we always wipe before disposal" is not a defence in a POPIA breach hearing or an insurance claim. Modern ITAD partners issue these as PDFs per device; attach each one to the corresponding asset record so it is one click away during an audit.

How a clean register makes ITAD painless

  • Every disposed asset already has a serial, photo, purchase cost, depreciation history and last-known assignment — no scramble for the paperwork.
  • Wipe certificates, certificates of destruction and recycling manifests attach to the asset, not a shared drive — they survive staff turnover.
  • Disposal posts a gain/loss against the net book value automatically, so finance sees the impact in the same view IT sees the certificate.
  • Bulk-archive a batch (end-of-lease return, server refresh) in one action with a shared disposal date and certificate.
  • The fixed-asset register and insurance schedule update on retirement — no orphaned line items.

A working ITAD checklist

  • Decommission ticket raised in the register with reason code.
  • Final assignee signs off return on a phone (chain-of-custody log).
  • Drive wiped to NIST 800-88; wipe certificate attached to asset.
  • Asset photographed at handover to the ITAD partner.
  • Certificate of destruction or recycling manifest attached on receipt.
  • Asset archived with disposal date, method, residual value and gain/loss.
  • Quarterly export to finance and the auditor — one CSV, one folder of PDFs.

Frequently asked questions

Is reformatting a drive enough?

No. A quick format leaves the data recoverable with off-the-shelf tools. Use a NIST 800-88 Clear or Purge wipe, or physical destruction for SSDs that cannot be reliably purged.

What about SSDs and phones?

SSDs and embedded flash do not respond to traditional overwrites. Use the manufacturer secure-erase command or, for the highest assurance, physical shredding. Phones should be factory-reset with encryption enabled, then verified by the ITAD partner.

Do we need a licensed ITAD partner?

For anything beyond internal reuse, yes. Resale, recycling and destruction all need a paper trail that ends with a licensed handler — both for POPIA/GDPR and for landfill/e-waste regulations.

How does disposal affect the fixed-asset register?

Retiring an asset removes it from active depreciation and posts the difference between residual value and net book value as a disposal gain or loss. AssetTrack does this automatically when you archive the asset with a disposal date and value.

Make your next ITAD round a non-event.

Import your register, attach wipe certificates, and close disposals with a full paper trail — without a spreadsheet in sight.