When a business retires technology in bulk, many moving pieces must come together to avoid legal or regulatory issues. Information technology asset disposition (ITAD) is the formal practice of retiring, sanitizing, and recycling or reselling (refurbishing) bulk hardware. This includes everything from employee laptops to data center racks.
In the United States, managing ITAD carries risks stakeholders cannot overlook. While there are no specific E-waste laws, strict data privacy laws and several state mandates determine what happens to electronics at the end of their life within an organization.
Four Core Strategies for Retiring Bulk ITAD
Most companies choose one of four disposition strategies when retiring bulk office electronics. Companies combine these strategies based on the items’ age, condition, and residual market value.
- Donation: Several non-profits help groups get the electronics they need for everyday living. Old electronics become essential devices for domestic assault victims, low-income families, and schools.
- Remarketing/Refurbishing: Companies can repair, clean up, and resell items they no longer use for profit.
- Redeployment: Large corporations often clean up electronics and transfer them to another department to ensure only the oldest electronics leave the company for good. It’s a good way to save money when updated technology is needed.
- Recycling: Items with no remaining value are recycled to recover materials for secondary manufacturing.
As many devices store private information, that information must be destroyed first. An ITAD expert specializes in data destruction processes that match a company’s legal responsibilities. Finding the right electronic waste and data destruction partner is an important first step.
Environmental and Data Privacy Regulations in the U.S.
The reality is that the U.S. lacks firm electronic waste laws. Instead, you have to consider hazardous waste and data privacy regulations. Here are some of the most common rules.
- Bans on Electronic Waste in Landfills: Half of U.S. states have laws to keep electronics out of landfills. They may involve Extended Producer Responsibility or Takeback programs.
- FACTA: Businesses must securely destroy all consumer report data from both paper copies and electronics.
- GLBA: Any financial company must burn or shred paper records and destroy data on electronics.
- HIPAA: Requires anyone in medical or healthcare fields to burn or shred paperwork and wipe data from electronics that store private health records.
- RCRA: A federal environmental rule that keeps hazardous waste out of landfills, including materials like cadmium, lead, lithium, and mercury.
- State Data Privacy Laws: Many states have rules in place like California’s CCPA/CPRA, Connecticut’s CIPA, and Virginia’s VCDPA that require organizations to delete personal data from any hardware before it’s sold, transferred, or recycled.
Data Destruction Standards: NIST SP 800-88 Rev. 1 vs. DoD 5220.22-M
For most companies, NIST SP 800-88 Rev. 1 is the standard used for data destruction. DoD 5220.22-M specification was popular throughout the 1990s and 2000s, and some business owners don’t understand the differences between these standards.
DoD 5220.22-M was designed to destroy the data on magnetic devices (HDDs). Modern solid-state drives (SSDs), Non-Volatile Memory Express (NVMe) media, and flash storage require media-specific sanitization that the former multi-pass overwriting doesn’t work on.
DoD 5220.22-M (Legacy) | NIST SP 800-88 Rev. 1 (Modern Standard) | |
Primary Focus | Overwriting magnetic storage via multi-pass cycles. | Media-specific sanitization tailored to the hardware (HDDs, SSDs, Flash, Tape). |
Core Strategy | Fixed multi-pass patterns of 3- or 7- pass overwrite cycles. | Clear, Purge, or Destroy processes based on confidentiality levels. |
SSD and NVMe Compatibility | Doesn’t work effectively. | Native. Runs internal controller firmware commands like Block Erase or Cryptographic Erase, |
Drive Lifespan Impact | High. Excessive read/write cycles degrade the drive, which impacts resale value. | Low. Firmware commands preserve drive health for remarketing and support reuse in a circular economy. |
Verification | Sample verification or basic software logs. | Serial-level verification with formal Certificates of Sanitization. |
Federal Policy Status | De-certified for federal enterprise use. | Current standard for U.S. government and commercial enterprise data destruction. |
Most ITAD specialists use NIST 800-88. Sanitization is broken down into three levels based on your intentions.
- Clear: Strings of binary numbers, such as 0s or 1s, are used to overwrite data in all storage locations. This method takes time.
- Purge: Firmware-level commands make it impossible to recover any data, even with advanced knowledge. It’s faster. A cryptographic erase goes further by overwriting the Media Encryption Key (MEK) on Self-Encrypting Drives (SEDs), making encrypted data unreadable.
- Destroy: Physical destruction of the data storage device takes place. Shredding or incineration are common forms of physical destruction.
Making Sure You Choose the Right ITAD Partner
While federal rules focus on the outcome, you need to focus on operations. One way to do this is by relying on accredited third-party certifications. You need to know your electronics recycling partner does more than recycle or refurbish your company’s electronics; you need one that prioritizes data security at every stage of the process.
Pay close attention to these certifications:
- e-Stewards: Formulated by the Basel Action Network, e-Stewards focuses on environmental control and ensuring hazardous e-waste never ends up in a developing nation.
- NAID AAA: The International Secure Information Governance & Management Association (iSIGMA) ensures that the facility is secure at all hours, sanitization is verified with both off-site and on-site destruction, and that employees pass strict background checks.
- Responsible Recycling (R2v3): Sustainable Electronics Recycling International (SERI) verifies that the facility adheres to circular economy standards and protects data and workers’ health and safety. Downstream vendors must also be tracked to ensure they follow the rules.
Ask About the ITAD Provider’s End-to-End Protocol
Even if you hire a company to recycle your bulk electronics, you need a legal audit trail for every step of the entire process. If you can’t prove even one step happened, you could be liable for any data breach.
A structured protocol needs to be followed.
- Internal Asset Reconciliation and Inventory Audit: When you purchase new electronics, record the serial number, equipment type, and location. Before sending electronics to an ITAD provider or destroying data at your place of business, you must carefully inventory the assets to ensure everything is included and you haven’t lost track of any device.
- Chain of Custody: After packaging the unused electronics, they are serialized and securely transported to the nearest processing facility. Real-time GPS tracking must be available, and signed chain-of-custody logs must be secured every time pallets or boxes change hands.
- Data Sanitization or Destruction: NIST 800-88-compliant sanitization is completed based on the media type and the item’s status.
- Assessments and Material Processing: Specialists assess the status of each device. Once charged, do they power up or not? Are any parts still in good shape and useful for repairs and rebuilds? Items that still have value can go into a remarketing program or be sent back to the company for internal redeployment. Anything that’s left is sent to be recycled into metal, glass, and plastic.
- Certified Downstream Material Recovery: For electronics that are marked for recycling, they’re processed in a specialized facility where hazardous materials like lithium-ion batteries are separated from the other metal, glass, and plastic components. Those hazardous materials are safely processed.
- Final Audit: Once the process is complete, the provider issues Certificates of Destruction or Certificates of Recycling. This provides you with proof you complied with applicable state and federal regulations.
When vetting an enterprise ITAD partner in the U.S., verify certifications. Make sure they offer real-time tracking so that you know exactly where your electronics are once they leave your place of business.
ERI is a leader in data destruction and CO2-neutral operations. We offer locations across the U.S., ensuring that your office electronics never have to travel far. Call 1-800-ERI-DIRECT to learn more.