IT asset disposition (ITAD) is the process of retiring IT equipment, such as laptops, desktops, servers, storage, phones and network gear, in a way that protects the data on it and handles the hardware responsibly. It typically covers collecting the equipment, tracking each item, sanitizing or physically destroying storage, and then reusing, reselling or recycling what remains, with records to prove it was done. Many organizations use specialist ITAD providers rather than doing it in-house.
At a glance
- ITAD is the final stage of the device lifecycle: retiring hardware securely and responsibly.
- The core risk is data: drives, phones and even printers and network gear can hold sensitive information.
- Data sanitization should match the media type and be verified, often following standards such as NIST SP 800-88.
- Buyers should expect serial-level tracking, chain of custody and certificates of sanitization or destruction.
- Remarketing working equipment can offset costs; environmental handling rules vary by jurisdiction.
What problem it solves
Refresh cycles, office closures and layoffs leave equipment behind. Unmanaged, it piles up in closets, gets handed to whoever will take it, or goes into general waste. Each of those devices may still hold customer records, credentials, email or intellectual property. A single drive recovered from a discarded laptop can become a data breach, with notification costs and regulatory exposure that dwarf the device’s value.
ITAD gives that last step a defined, auditable process. It makes sure each asset is accounted for, that data is removed in a way appropriate to the media, that the hardware is reused or recycled under suitable environmental controls, and that you have records showing all of this happened. It also recovers value from equipment that still has a resale market.
How it works
Inventory and scheduling. The organization identifies equipment to retire, ideally from its IT asset management (ITAM) records, and schedules collection. Devices still under lease or hardware as a service contracts usually follow the lessor’s return process instead.
Collection and chain of custody. The provider collects equipment from offices, data centers or remote employees, and records each item, typically by serial number, from pickup onward. Secure transport, sealed containers and logged handovers make up the chain of custody. Some organizations require on-site drive shredding or wiping so data never leaves the building.
Data sanitization. Storage is wiped using methods suited to the media, such as overwriting, cryptographic erase on drives that were encrypted, or manufacturer secure-erase commands, and the result is verified. Media that can’t be reliably wiped, or that policy says must be destroyed, is shredded, crushed or degaussed. Standards such as NIST SP 800-88 are widely used as the reference for these methods. Good encryption during a device’s working life makes sanitization at the end easier and lowers the risk if a step is missed.
Remarketing and recycling. Working equipment may be refurbished and resold, with proceeds often shared. The rest is broken down and recycled. Electronics recycling rules vary by country and state, and responsible providers manage which downstream processors handle the materials.
Reporting. The provider issues reports listing each asset, what was done to it and when, along with certificates of sanitization or destruction and, where relevant, recycling and resale records.
When it matters for buyers
- At refresh time. A planned laptop or server refresh is the most common ITAD trigger.
- When downsizing or closing offices. Equipment from departing staff and closed sites needs collecting, often from homes.
- During divestitures and mergers. Assets moving out of the business, or being consolidated, need clear records.
- When auditors, customers or regulators ask. Certificates and chain-of-custody records answer “what happened to the data?”
- When planning the full device lifecycle. ITAD terms belong in the plan from the start, alongside procurement and deployment.
Questions to ask vendors
- How do you sanitize each media type, which standards do you follow, and how is the result verified?
- Do we get serial-level reports and certificates of sanitization or destruction for every asset?
- How is chain of custody maintained from pickup to final processing? Can you destroy drives on site?
- Which certifications do you hold, such as R2, e-Stewards or NAID AAA, and when were you last audited?
- Which downstream recyclers and processors do you use, and where?
- How are resale proceeds calculated and shared, and what insurance and liability do you carry?
Our field support overview covers providers that collect, track and retire equipment across many sites.
How it differs from IT asset management (ITAM)
IT asset management (ITAM) tracks hardware and software throughout their life: what you own, where it is, who has it, what it costs and when it is due for replacement. ITAD is the end of that life: physically retiring the hardware and its data. Good ITAM records make ITAD safer, because you can reconcile what the provider reports against what you know you owned, and spot devices that never came back. Day-to-day asset tracking and a clear data retention policy help decide what to retire and what must be preserved first. ITAD is also distinct from simple e-waste recycling, which may handle materials responsibly but doesn’t necessarily include data sanitization, tracking or certificates.
