What Is ITAD (IT Asset Disposition)?

Related problems: Closets full of old laptops and servers we don't know what to do with; Worried data on retired drives could leak; Need proof for auditors that old devices were wiped or destroyed; Want to recover some value from retired equipment

IT asset disposition (ITAD) is the process of retiring IT equipment, such as laptops, desktops, servers, storage, phones and network gear, in a way that protects the data on it and handles the hardware responsibly. It typically covers collecting the equipment, tracking each item, sanitizing or physically destroying storage, and then reusing, reselling or recycling what remains, with records to prove it was done. Many organizations use specialist ITAD providers rather than doing it in-house.

At a glance

  • ITAD is the final stage of the device lifecycle: retiring hardware securely and responsibly.
  • The core risk is data: drives, phones and even printers and network gear can hold sensitive information.
  • Data sanitization should match the media type and be verified, often following standards such as NIST SP 800-88.
  • Buyers should expect serial-level tracking, chain of custody and certificates of sanitization or destruction.
  • Remarketing working equipment can offset costs; environmental handling rules vary by jurisdiction.

What problem it solves

Refresh cycles, office closures and layoffs leave equipment behind. Unmanaged, it piles up in closets, gets handed to whoever will take it, or goes into general waste. Each of those devices may still hold customer records, credentials, email or intellectual property. A single drive recovered from a discarded laptop can become a data breach, with notification costs and regulatory exposure that dwarf the device’s value.

ITAD gives that last step a defined, auditable process. It makes sure each asset is accounted for, that data is removed in a way appropriate to the media, that the hardware is reused or recycled under suitable environmental controls, and that you have records showing all of this happened. It also recovers value from equipment that still has a resale market.

How it works

Inventory and scheduling. The organization identifies equipment to retire, ideally from its IT asset management (ITAM) records, and schedules collection. Devices still under lease or hardware as a service contracts usually follow the lessor’s return process instead.

Collection and chain of custody. The provider collects equipment from offices, data centers or remote employees, and records each item, typically by serial number, from pickup onward. Secure transport, sealed containers and logged handovers make up the chain of custody. Some organizations require on-site drive shredding or wiping so data never leaves the building.

Data sanitization. Storage is wiped using methods suited to the media, such as overwriting, cryptographic erase on drives that were encrypted, or manufacturer secure-erase commands, and the result is verified. Media that can’t be reliably wiped, or that policy says must be destroyed, is shredded, crushed or degaussed. Standards such as NIST SP 800-88 are widely used as the reference for these methods. Good encryption during a device’s working life makes sanitization at the end easier and lowers the risk if a step is missed.

Remarketing and recycling. Working equipment may be refurbished and resold, with proceeds often shared. The rest is broken down and recycled. Electronics recycling rules vary by country and state, and responsible providers manage which downstream processors handle the materials.

Reporting. The provider issues reports listing each asset, what was done to it and when, along with certificates of sanitization or destruction and, where relevant, recycling and resale records.

When it matters for buyers

  • At refresh time. A planned laptop or server refresh is the most common ITAD trigger.
  • When downsizing or closing offices. Equipment from departing staff and closed sites needs collecting, often from homes.
  • During divestitures and mergers. Assets moving out of the business, or being consolidated, need clear records.
  • When auditors, customers or regulators ask. Certificates and chain-of-custody records answer “what happened to the data?”
  • When planning the full device lifecycle. ITAD terms belong in the plan from the start, alongside procurement and deployment.

Questions to ask vendors

  • How do you sanitize each media type, which standards do you follow, and how is the result verified?
  • Do we get serial-level reports and certificates of sanitization or destruction for every asset?
  • How is chain of custody maintained from pickup to final processing? Can you destroy drives on site?
  • Which certifications do you hold, such as R2, e-Stewards or NAID AAA, and when were you last audited?
  • Which downstream recyclers and processors do you use, and where?
  • How are resale proceeds calculated and shared, and what insurance and liability do you carry?

Our field support overview covers providers that collect, track and retire equipment across many sites.

How it differs from IT asset management (ITAM)

IT asset management (ITAM) tracks hardware and software throughout their life: what you own, where it is, who has it, what it costs and when it is due for replacement. ITAD is the end of that life: physically retiring the hardware and its data. Good ITAM records make ITAD safer, because you can reconcile what the provider reports against what you know you owned, and spot devices that never came back. Day-to-day asset tracking and a clear data retention policy help decide what to retire and what must be preserved first. ITAD is also distinct from simple e-waste recycling, which may handle materials responsibly but doesn’t necessarily include data sanitization, tracking or certificates.

Frequently Asked Questions

Is deleting files or reformatting a drive enough before disposal?
Generally not. Deleting or quick-formatting usually leaves data recoverable with common tools. Proper sanitization uses methods suited to the media type, such as overwriting, cryptographic erase or vendor secure-erase commands, or physical destruction, and is verified afterward. Standards such as NIST SP 800-88 describe these approaches.
What is a certificate of destruction?
It is a document from the ITAD provider stating that specific devices or drives were sanitized or destroyed, ideally listed by serial number with the method and date. It is your evidence for auditors and regulators, so check it matches what you sent.
What certifications should an ITAD provider have?
Common ones include R2 and e-Stewards for responsible electronics recycling, NAID AAA for data destruction, and ISO management-system certifications. Certifications show a provider has been audited against a standard; they don't replace checking the provider's processes, insurance and downstream partners yourself.
Can ITAD actually generate money?
Sometimes. Newer laptops, phones and servers can have resale value that offsets or exceeds disposal costs, usually shared with the provider. Older or damaged equipment often has little value, and the service may cost money. Value depends heavily on age, condition and market prices.
Who is liable if data leaks from a disposed device?
In many cases the organization that owned the data stays responsible even after handing devices to a provider, though contracts can shift some risk. Rules vary by jurisdiction and industry, so check with counsel and make sure the contract covers liability and insurance.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.