
Guide
GDPR and old computers: what businesses must do before disposal
What UK data protection law expects when you retire IT equipment: the security duty, the evidence you need to keep, and where responsibility sits when somebody else does the wiping.
9 minute read
A cupboard of retired laptops is not just clutter. If those machines still hold personal data — staff records, customer details, an old payroll export somebody saved to the desktop — then under UK data protection law they are still your responsibility, and they stay your responsibility until that data is properly destroyed.
This is a plain-English summary of what the law expects, written for somebody who has been asked to deal with the machines rather than for a lawyer. It is general information and not legal advice; if the stakes are high, take proper advice on your specific situation.
The obligation does not end when the machine stops being used
UK GDPR requires personal data to be processed securely, using appropriate technical and organisational measures. “Processing” includes erasure and destruction, so how you dispose of a device is itself a processing activity that has to be done properly.
The practical consequence: a laptop sitting in a drawer with a working drive in it is a live risk, not a dormant one. If it walks out of the building, that is a personal data breach in exactly the way a misdirected email is.
Storage limitation cuts both ways
Personal data should not be kept longer than necessary. Old equipment tends to hold data long past any retention period the organisation actually set, because nobody thinks of a decommissioned machine as a place where records live. If your retention schedule says customer records go after six years, a drive in the store cupboard holding a 2016 export is not complying with it.
Deleting is not erasing
Dragging files to the bin, emptying it, or reformatting a disk generally removes the reference to the data rather than the data itself. Until that space is overwritten the underlying information can often still be recovered with freely available tools.
A factory reset is better and, on modern encrypted devices, can be genuinely effective — because destroying the encryption key makes the contents unreadable. But it varies by device and by how it was configured, which is why “we reset them” is a weaker answer to a regulator than “here is the record of what was erased and how”.
Accountability: you have to be able to show it
This is the part organisations most often miss. UK GDPR does not only require you to handle data properly; it requires you to be able to demonstrate that you did. Good intentions and a verbal assurance from whoever took the machines away are not evidence.
What that means in practice for a disposal:
- An asset list. Which devices left, identified well enough to be individually recognisable — serial numbers or asset tags, not “about forty laptops”.
- A record of what happened to each one. Erased, destroyed, or returned. Devices that could not be wiped need accounting for separately, because they are the ones most likely to have been handled differently.
- Evidence of the erasure. A certificate recording the work, kept with your own records rather than left with the supplier.
- Who did it and under what terms. See the next section.
Using a third party does not transfer the responsibility
If somebody else erases the data on your behalf, they are generally acting as a processor and you remain the controller. UK GDPR requires that relationship to be governed by a written contract setting out what they may do with the data, the security measures in place, and what happens at the end.
Two things follow. First, ask the question before the van arrives: “what are the data terms?” is a reasonable thing to ask any disposal supplier, and an evasive answer is informative. Second, remember that if a supplier loses your data, it is still your breach to report — you chose them.
Breaches have to be reported quickly
Where a personal data breach is likely to result in a risk to people, it must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. That clock is uncomfortably short if your first task is working out which machines went missing and what was on them — which is the practical argument for keeping the asset list before anything leaves, not after.
WEEE sits alongside this, not instead of it
Data protection is not the only duty. Business IT equipment is also covered by the WEEE regulations governing how electrical waste is handled. The two are separate: a supplier can be perfectly sound on recycling and still leave you exposed on data, and vice versa. Satisfy yourself on both.
A practical checklist
- Find everything. Store cupboards, desk drawers, the box under the stairs, machines lent to people who left.
- List it before it moves, with serial numbers or asset tags.
- Identify which devices hold data. Assume anything with a drive does until you have checked — including servers, network hardware and old phones and tablets.
- Decide erase or destroy for each, and agree who does it and where.
- Get the terms in writing before anything leaves the building.
- Keep the certificate and the list together, with your retention records.
- Check the equipment is actually yours to dispose of — leased and financed hardware may belong to a funder.
Where we fit
We buy retired business IT equipment and deal with the data on it as part of the job. Tell us at enquiry stage which items hold data and it is agreed before anything moves: eligible storage is erased and a data erasure certificate is issued recording the work, and anything that cannot be wiped is destroyed rather than passed on. What was collected is recorded at the point of collection, so your list and ours match.
If your procurement or compliance process needs something specific in writing, ask for it by name and we will tell you plainly where we stand rather than guess. How data wiping works, and what IT asset disposal covers.
Talk to us about IT asset disposal
Tell us what you have and we will come back with a free quote for anything we are able to buy. There is no obligation to accept it.
Talk to us about IT asset disposalReady to sell your IT equipment?
Tell us what you have and we will take a look. No obligation, and no equipment is too old for us to assess.

