CWR

How to Choose an IT Asset Disposal (ITAD) Company

How to Choose an IT Asset Disposal (ITAD) Company

Retiring old laptops, servers, or a full office refresh is never as simple as calling the first “free IT recycling” The company you choose is the one holding your data, your compliance record, and increasingly your organisation’s reputation if something goes wrong.

Every year, businesses across the UK fall into the same trap: they book a collection based on price alone, only to discover afterwards that the “recycler” cannot produce a certificate of destruction, has no idea what an Approved Authorised Treatment Facility (AATF) is, or has quietly sold equipment on without properly wiping it first. By the time that becomes apparent, the equipment and the data on it has already left the building, and there is very little a business can do to undo the damage.

The stakes here are higher than most procurement decisions. Get it wrong, and you’re not just dealing with a poor supplier experience you could be facing a UK GDPR breach, an Environment Agency investigation, or a very uncomfortable conversation with your board about why sensitive data ended up on a resold laptop. Get it right, and IT disposal becomes a routine, low-risk part of your asset lifecycle, backed by paperwork that stands up to scrutiny if anyone ever asks.

Before you book your next IT Asset Disposal (ITAD) collection, here are seven questions worth asking every provider on your shortlist. If a provider can’t answer all seven confidently and back up the answers with documentation that’s your answer.

1. Will I receive a certificate of data destruction for every device?

This is non-negotiable. Any provider handling data-bearing equipment laptops, desktops, servers, hard drives, mobile phones should issue a certificate confirming exactly what was destroyed, how, and when.

A proper certificate will typically include:

  • The device’s serial number or asset tag
  • The sanitisation method used (wiping, degaussing, or physical shredding)
  • The standard applied (for example, NIST 800-88)
  • The date of destruction and a unique certificate reference

If a provider offers you a vague “yes, we’ll sort the data” without mentioning documentation, treat that as a warning sign. Under UK GDPR and the Data Protection Act 2018, your organisation remains accountable for that data even after it leaves your building the certificate is your evidence that you met your obligations.

It’s also worth asking when in the process destruction happens, and whether you get one certificate per device or a single blanket document covering an entire collection. Per-device certification, tied to serial numbers, gives you a far stronger audit trail than a generic “all items processed” statement particularly if you’re ever asked by an auditor, insurer, or regulator to prove that a specific machine was accounted for. If your organisation operates in a regulated sector finance, healthcare, legal, or the public sector this level of granularity often isn’t optional; it’s expected.

2. Are they an Approved Authorised Treatment Facility (or do they use one)?

IT equipment is classified as Waste Electrical and Electronic Equipment (WEEE) under the WEEE Regulations 2013. UK law requires that WEEE only be processed by an Approved Authorised Treatment Facility (AATF). Handing your equipment to an unregistered operator even unknowingly can leave your business exposed to enforcement action from the Environment Agency.

Ask directly: “Are you an AATF, or which AATF do you use?” A legitimate provider will answer this without hesitation and should be able to show you their waste carrier licence and environmental permit.

It’s worth understanding why this matters beyond the legal technicality. The duty of care around waste doesn’t end the moment a van drives away from your premises as the waste producer, your organisation retains responsibility for ensuring it’s handled correctly all the way through the chain. If your chosen provider subcontracts to an unregistered third party and that equipment is later found dumped, improperly processed, or exported illegally, your business can still be implicated. Ask for the provider’s waste carrier registration number and check it against the Environment Agency’s public register it takes two minutes and removes any doubt.

3. What accreditations do they actually hold?

Certificates and badges on a website mean very little unless they’re independently verified. Look for accreditations that are checked by a third-party body (UKAS-accredited ISO certifications, for example), rather than self-issued “compliance” badges.

Relevant accreditations to look out for include:

  • ISO 27001 — information security management
  • ISO 14001 — environmental management
  • ISO 9001 — quality management
  • ISO 45001 — health and safety
  • Cyber Essentials — baseline cybersecurity controls

None of these guarantee good service on their own, but their absence or a provider that can’t produce the certificates on request should raise questions.

A useful trick: ask for the certificate number or the accreditation body’s name, and search for the provider directly on that body’s website (UKAS, for instance, publishes a searchable directory of accredited certification bodies). A genuine accreditation will show up. A logo copied onto a website with no verifiable record behind it is worth far less than it looks.

A quick example, close to home: at Computer Waste (CWR), we hold ISO 27001 (information security), Cyber Essentials, and are ICO-registered, alongside our Environment Agency waste carrier registration all of which we’re happy to share on request before you book. If you’re building a shortlist, view our certificates and check them the same way you’d check anyone else’s.

4. What happens to the equipment after collection?

A trustworthy provider should be able to explain, clearly, the journey your equipment takes: audit and inventory, data sanitisation, then either responsible recycling or certified refurbishment and resale.

Be specific in what you ask:

  • Is everything counted and logged by serial number?
  • Is data destroyed before or after any resale assessment?
  • Where does equipment go if it’s not fit for resale?
  • Do you provide a full asset report at the end of the process?

If a provider can only give you a vague answer along the lines of “it gets recycled,” that’s not an audit trail it’s a black box, and it’s your organisation that carries the risk if anything surfaces later.

It also helps to understand the order of operations. Reputable providers sanitise data-bearing devices before any resale valuation takes place, not after equipment should never sit in a “to be assessed” pile with intact data on it, even briefly, even in a secure facility. If a provider’s process description has data destruction happening late in the chain, or “on request,” push for clarity on exactly when and where it happens.

5. Is the collection genuinely free, and what triggers a charge?

Many ITAD providers advertise free collections, and for a large proportion of commercial clients, that’s accurate value recovered from resalable equipment offsets the cost of the service. But “free” isn’t universal, and it shouldn’t be a surprise when it doesn’t apply to you.

Ask upfront:

  • What determines whether a collection is free versus chargeable?
  • Will I get a quote before the collection, not after?
  • Are there charges for low-value or damaged equipment?

A transparent provider will explain their pricing logic before you commit, not after your equipment has already left the building.

It’s also worth asking how any resale value is calculated and shared. If your equipment has genuine resale worth, some providers offer a rebate or part-payment rather than simply offsetting it against the “free” service worth knowing if you’re disposing of a larger volume of relatively current hardware, such as a fleet refresh, where the value recovered could be meaningful rather than negligible.

6. Can they handle the full range of equipment your business needs to dispose of?

A provider that only handles standard desktops and laptops isn’t much use if your refresh also includes servers, networking hardware, or specialist equipment. Before booking, confirm they can manage everything you need cleared in one collection including higher-risk items like UPS systems, which may fall under separate hazardous waste rules.

This matters practically, too fewer providers, fewer collections, and a single, consistent audit trail are all easier to manage and easier to defend if you’re ever asked to demonstrate compliance. Splitting a disposal job across several specialist suppliers might occasionally seem cheaper on paper, but it multiplies the number of parties who’ve had access to your equipment and data, and multiplies the number of certificates and processes you need to keep track of afterwards.

If your organisation has locations across multiple cities, it’s also worth checking whether the provider genuinely collects nationwide with its own fleet, or whether collections outside their home region are subcontracted out. A subcontracted collection isn’t automatically a problem, but you should know about it and it circles back to question two: who is actually handling your equipment once it leaves your hands?

Need coverage across several sites? Computer Waste runs collections nationwide, with dedicated local coverage in London, Bristol, Peterborough, Leicester, Cambridge, and Birmingham. Book a collection and we’ll confirm exactly who’s handling your equipment, start to finish.

7. What’s their track record and can you actually verify it?

“Trusted by thousands of businesses” is a claim almost every ITAD provider makes. What’s worth checking is whether that claim holds up:

  • Independent reviews (Trustpilot, Google) read a mix of recent and older reviews, not just the highlighted ones
  • How long they’ve operated in this specific sector
  • Named public sector or enterprise clients, where they’re able to share them
  • Whether they respond to negative reviews, and how

None of this needs to be perfect. Every company accumulates the odd bad review. What matters is a consistent pattern of professionalism, responsiveness, and crucially a provider that hasn’t been flagged repeatedly for issues around data handling or hidden charges. Pay particular attention to how a company responds to a negative review, if it responds at all. A defensive, dismissive, or entirely absent reply to a serious complaint especially one involving data or pricing tells you more about how that company will treat you when something goes wrong than any five-star review ever will.

It’s also worth remembering that longevity in this specific sector counts for more than longevity in business generally. IT asset disposal sits at the intersection of data protection law, waste regulation, and hardware handling it takes time to build the processes, accreditations, and staff training to do all three properly. A provider that has pivoted into ITAD from an unrelated trade, or that’s only been operating under its current name for a short time, isn’t automatically untrustworthy, but it does warrant a closer look at the answers to the six questions above.

Frequently asked questions

Is IT asset disposal actually free for businesses?

For many commercial clients, yes a genuine proportion of collections are provided at no cost because the provider recovers value from equipment that still has resale worth, and that value offsets their operating costs. However, “free” isn’t universal. Low volumes, older or damaged equipment, and equipment with little resale value can all mean a charge applies. A trustworthy provider will tell you this upfront and confirm it with a clear quote before collection, rather than after.

What’s the difference between data wiping and data destruction?

Data wiping (or erasure) uses software to overwrite the data on a storage device so it can no longer be recovered, while leaving the device itself intact and reusable this is the approach typically used when equipment is going to be resold or refurbished. Data destruction refers to physically destroying the storage media, usually by shredding, so recovery is impossible by any means. Solid-state drives (SSDs) in particular don’t always respond reliably to overwriting because of how they manage data at a hardware level, so for some devices, physical destruction is the only method that guarantees complete removal. A good provider will explain which method applies to which type of device, and why.

Do I need a certificate of destruction if I’m not in a regulated industry?

Yes. UK GDPR and the Data Protection Act 2018 apply to any organisation processing personal data — customer records, employee data, supplier details regardless of sector. A certificate of destruction is your evidence that you met your legal obligations when that data reached end of life. Without it, you have no documented proof of compliance if a question or complaint ever arises, whatever industry you’re in.

How long should I keep waste transfer notes and destruction certificates?

As a general rule, retain both waste transfer notes and data destruction certificates for a minimum of three years, in line with standard UK duty-of-care guidance. Organisations in regulated sectors, or those with stricter internal information governance policies, may need to retain records for longer check your sector-specific requirements, and store the certificates alongside your other data protection and asset management records so they’re easy to produce if requested.

What should I do if a provider can’t answer these questions clearly?

Treat it as a decision point, not a detail to overlook. A provider that’s vague about certification, accreditation, or what happens to your equipment after collection is asking you to take a great deal on trust, with very little to back it up. There are enough properly accredited, transparent ITAD providers operating across the UK that there’s rarely a good reason to settle for one that can’t answer clearly.

Conclusion

Choosing an ITAD partner isn’t just a procurement decision it’s a data protection and compliance decision wearing a procurement hat. It’s easy to treat IT disposal as an administrative afterthought, something to tick off once the new equipment has arrived and the old kit is cluttering up a storeroom. But the cheapest or most convenient option can end up being the most expensive one if a certificate never arrives, a device turns up in the wrong hands, or an Environment Agency audit asks questions your business can’t answer.

The good news is that vetting a provider properly doesn’t need to be time-consuming. The seven questions in this guide are ones any legitimate, accredited ITAD company should be able to answer clearly, confidently, and with documentation to back it up usually within a single phone call or email. If a provider hesitates, deflects, or can only offer vague reassurances, that hesitation is itself useful information.

Ultimately, the goal isn’t to find the provider with the most impressive-looking website or the loudest claims about being “the UK’s leading” anything. It’s to find a provider whose process, paperwork, and accreditations you’d be comfortable defending to a regulator, an auditor, or your own board because at some point, you may need to.

Ask the seven questions above before you book. A provider with nothing to hide will be glad you did.

Why Computer Waste (CWR) meets this checklist

We wrote this guide from the buyer’s side of the table deliberately because it’s the same checklist we’d want a client to run through on us. Computer Waste is a certified IT recycling and computer disposal provider covering the UK, offering guaranteed data destruction, full asset audits and reporting, and nationwide collections through our own network with dedicated coverage in London, Bristol, Peterborough, Leicester, Cambridge, and Birmingham.

In practice, that means:

  • A certificate of data destruction issued for every device we process, not a blanket statement covering a batch
  • Sanitisation carried out to recognised standards, with physical shredding used where wiping isn’t appropriate (SSDs and damaged drives, for example)
  • Compliant processing as part of a properly regulated, ICO-registered chain of custody, from collection through to final reporting
  • ISO 27001 (information security) and Cyber Essentials certification, alongside our Environment Agency waste carrier registration all available to view or verify before you book
  • A transparent process on cost: most commercial collections are free, and where they’re not, we confirm this with a clear quote upfront, not after collection
  • Full audit and inventory reporting, so you have a documented record for your own compliance files

If you’re weighing up providers using the seven questions above, we’d genuinely encourage you to put us through the same test as everyone else on your list.

Request a free collection or view our certificates to see the documentation for yourself.

Get in touch

Computer Waste Recycling (CWR) IT Asset Disposal, Computer Recycling & Certified Data Destruction

📍 Address: 25 Cabot Sq, Canary Wharf Estate, London, E14 4QZ)

📞 Phone: 03303410785

📧 Email: info@computerwaste.co.uk

🌐 Website: computerwaste.co.uk

Leave a Comment

Your email address will not be published. Required fields are marked *