When Victorian businesses think about IT asset disposal, the mental image is usually servers, laptops, and desktop PCs. Those are the obvious targets. But there is a category of device that holds just as much sensitive business data, gets upgraded more frequently, and gets retired with far less rigour: the mobile phone and the tablet.
This is the ITAD blind spot that keeps data security consultants busy.
What is actually on that old work phone?
A three-year-old company smartphone can hold corporate email archives, authentication tokens, CRM contact lists, HR records, client communications, and in some industries, health information. Tablets used for field service or sales visits carry contract documents, pricing data, and sometimes biometric authentication profiles.
When those devices come in for upgrade, and Australians upgrade smartphones roughly every two and a half years on average, they often go through a process that feels secure but is not: a factory reset via MDM (Mobile Device Management) software, or a manual wipe by IT staff.
Factory resets and MDM wipes are not the same as cryptographic erasure or physical destruction. NIST 800-88 Rev. 2, the standard that defines data sanitisation adequacy, sets three levels: Clear (software overwrite for lower-sensitivity data), Purge (cryptographic erase or firmware-level overwrite for more sensitive data), and Destroy (physical destruction). An MDM remote wipe typically falls at or below the Clear threshold, depending on how the vendor implements it. For devices that have handled personal information covered by the Privacy Act, that may not be enough.
The Privacy Act applies to every device
Australia’s Privacy Act 1988, specifically Australian Privacy Principle 11, requires organisations to take reasonable steps to protect personal information and to destroy or de-identify it when it is no longer needed. “Reasonable steps” does not mean clicking reset in your MDM console.
If a former employee’s phone containing customer records ends up in a second-hand market, it is a potential notifiable data breach. If it ends up in a skip bin, it also violates the Victorian e-waste landfill ban, which applies to all electronic devices regardless of size. The Office of the Australian Information Commissioner has been clear: APP 11 applies to personal information on all devices, not just servers.
The scale of the problem
Australia has approximately 28 million active mobile subscriptions. Most organisations cycle through corporate mobile fleets every two to three years. A 100-person business might retire 30 to 50 devices per cycle. Without a formal process, those devices sit in drawers, get donated to departing employees, get traded in to carriers, or get handed to charities. Each path carries residual data risk.
Carrier trade-in programs are not data destruction providers. They refurbish and resell.
What a compliant mobile device disposal process looks like
For devices that have handled personal or business-sensitive information, the process should include:
- Documented removal from MDM and network access before physical collection
- Independent cryptographic erasure verified against NIST 800-88 Rev. 2 Clear or Purge specifications, depending on data sensitivity
- A per-device serial number certificate confirming sanitisation
- R2-aligned downstream processing for any device that cannot be repaired or resold
EWV handles mobile devices as part of its standard ITAD intake. Every device that enters the EWV stream receives the same chain of custody documentation as a laptop or server: a collection record, asset manifest, and a sanitisation certificate traceable to a serial number. EWV’s programs align with AS/NZS 5377 for materials processing and NIST 800-88 Rev. 2 for data sanitisation, with alignment to ISO 14001 and ISO 27001 embedded in our operations and full certification on the roadmap.
Book a mobile device collection
If your business is managing a mobile device refresh, or if phones and tablets have been sitting in a storage drawer since your last IT cycle, now is the right time to bring them into a formal ITAD process.
Contact EWV to arrange a scheduled collection for your mobile device fleet. We provide a confirmed collection date, a complete chain of custody record, and per-device certificates to satisfy your compliance and audit requirements.
