Most organisations know they need to do something with retired IT equipment. They arrange a collection, hand over a pallet of laptops and servers, and call the job done. But the question most IT managers should be asking is what happens next.

A collection is not disposal. It is the beginning of a process. What occurs between the moment your equipment leaves the building and the point where you receive a data destruction certificate determines whether your organisation is protected or exposed.

The gap between collection and certainty

A surprising number of organisations hand over retired devices and receive nothing in return. No itemised manifest. No record of how data was handled. No confirmation that specific drives were processed. If your auditor or insurer asks what happened to the 200 laptops refreshed in Q2, “we gave them to someone” is not an answer that closes the loop.

Chain of custody is the documented record of where your equipment went, who handled it, what was done to it, and when. Without it, you have a transfer. Not a disposal.

What a proper chain of custody looks like

When equipment leaves your premises with EWV, the process starts with an itemised asset register: serial numbers, device types, and condition notes captured at collection. That register does not disappear. It follows the equipment through every subsequent step.

At the processing facility, storage media earmarked for destruction undergoes data sanitisation aligned with NIST 800-88 Rev. 2, which specifies clearing, purging, and destruction methods by media type. A solid-state drive and a spinning hard drive have different data residency characteristics. They are not treated the same way.

Once destruction is complete, a certificate is generated that ties back to the original asset register. Your IT manager and compliance team receive documentation naming specific devices, serial numbers, and the destruction method applied. That certificate is your audit evidence.

Why this matters for ISO 27001 compliance

If your organisation holds ISO 27001 certification or is working toward it, IT asset disposal is an explicit control area. Annex A.8.10 covers media disposal and requires documented evidence that assets containing sensitive information were handled securely. A certificate of destruction from an ITAD provider aligned with ISO 27001 satisfies that control. A verbal assurance from a collection driver does not.

For Victorian organisations, the regulatory floor is the e-waste landfill ban, in effect since 1 July 2019. But compliance with the ban is the minimum. The data security obligations that sit on top of it are where organisations typically face their real exposure.

The risk you do not see

Data breaches from physical media do not generate headlines the way software breaches do, but they happen. A laptop with a wiped-but-not-sanitised drive. A server with recoverable RAID configuration data. A phone not fully reset before trade-in. These are real vectors. The cost is not just remediation. It is notification obligations, regulatory scrutiny, and reputational damage.

The control you have over that risk ends the moment the device leaves your custody. A documented chain of custody is how you extend that control forward in time.

Three questions to ask before you book a collection

Before you hand equipment to any ITAD provider, ask:

  1. Will I receive an itemised manifest at collection?
  2. What standard governs your data destruction process?
  3. Will I receive a certificate of destruction listing individual devices by serial number?

Vague answers mean gaps in your chain of custody.

EWV’s process aligns with AS/NZS 5377, and our data destruction practice follows NIST 800-88 Rev. 2. Every collection results in a traceable record from pickup through to certificate, with full asset-level visibility via CircularTrack.

If you are planning a hardware refresh and want to understand the documentation your organisation should be receiving, contact EWV to walk through what a compliant ITAD process looks like for your environment.