How to Create an IT Asset Disposal Policy for Your Business
Most businesses don't have a written IT asset disposal policy until something goes wrong — a compliance audit, a data breach investigation, or a question from a client about how their data was handled. A disposal policy doesn't have to be complicated, but it does have to exist, and it has to be followed consistently. This guide walks through what belongs in one, why each element matters, and how to make it something your team will actually use.
Why a written policy matters
Without a written policy, IT asset disposal defaults to whatever feels right in the moment — which means different people handle it differently, documentation is inconsistent, and there's no clear answer when someone asks what happened to a specific device. That's a problem in an audit and a bigger problem in a breach investigation.
Under Massachusetts 201 CMR 17.00, businesses are required to have a written information security program that includes provisions for the disposal of records containing personal information. A disposal policy is part of that program. For businesses subject to HIPAA, GLBA, or SOC 2, the documentation requirements are more explicit still — and regulators want to see not just that you have a policy, but that you can demonstrate it was followed for specific devices.
Beyond compliance, a written policy is simply good operational practice. It makes disposal predictable, auditable, and repeatable — and it gives your ITAD vendor a clear brief to work from.
The most common gap isn't the absence of a policy — it's having a policy that doesn't match actual practice. If your written policy says drives are shredded but your team has been doing software wipes, the policy doesn't protect you. Whatever you write has to reflect what you actually do, and what you actually do has to meet the standard.
What your policy needs to cover
A complete IT asset disposal policy addresses six core areas. Here's what goes in each:
Scope — what the policy covers
Define exactly which assets and which people are covered. Scope creep in the other direction — assuming everyone knows what's included — is how devices fall through the cracks.
- All company-owned devices (laptops, desktops, servers, mobile phones, tablets)
- Peripheral and networking equipment (printers, copiers, switches, routers, firewalls)
- Removable storage media (USB drives, external hard drives, backup tapes)
- Any device that has connected to company networks or stored company data
- Employee-owned devices used for work (BYOD) where applicable
- Applies to all employees, contractors, and vendors who handle company equipment
Data classification and destruction requirements
Not all data carries the same risk, but in practice, treating all business devices as potentially containing sensitive data is the cleanest approach. Your policy should define:
- Default destruction method — What happens to every device unless otherwise specified. Physical shredding for all storage media is the most defensible default, particularly for SSDs.
- Elevated requirements — Devices that handled PHI, financial records, legal files, or other regulated data may require on-site witnessed destruction and additional documentation.
- Prohibited methods — Explicitly list what is not acceptable: factory reset, standard formatting, deletion, donation without verified destruction.
- Standard reference — State that destruction must meet NIST 800-88 Purge or Destroy standards, as applicable.
Chain of custody requirements
Chain of custody documents where a device has been and who has had control of it from decommission through destruction. Your policy should require:
- Devices flagged for disposal must be logged in your asset tracking system before physical removal
- Decommissioned devices must be staged in a designated, secure location — not left at employee desks or in unsecured storage
- Transfer to a disposal vendor must be documented with a signed pickup receipt listing every device
- No device may be removed from the premises for disposal without a documented handoff
Vendor requirements
If you're using a third-party vendor for electronics recycling or data destruction — which most businesses should be — your policy should specify what that vendor is required to provide:
- R2 certification for downstream recycling accountability
- NIST 800-88 compliant destruction methods, documented by media type
- Serialized tracking — every drive logged by serial number, not batch counts
- Certificate of Destruction issued after all media is destroyed
- On-site shredding capability for situations requiring witnessed destruction
Documentation and recordkeeping
Define what documentation must be collected and how long it must be retained. At minimum:
- Pickup receipt from vendor — retained for the life of the compliance record
- Serialized drive log — device-level tracking from your asset system to destruction
- Certificate of Destruction — filed with information security compliance records
- Asset inventory reconciliation — decommissioned assets closed out in CMDB or asset tracker
- Retention period — match to your industry's requirements (HIPAA: 6 years; GLBA: varies; MA 201 CMR 17.00: as part of your WISP)
Roles and responsibilities
A policy without named owners doesn't get followed. Assign clearly:
- IT Manager / IT Director — Owns the disposal process, vendor relationship, and documentation
- Department managers — Responsible for flagging and staging devices when employees leave or equipment is replaced
- Employees — Required to return company devices to IT within a defined timeframe upon departure or device replacement
- Compliance / Legal — Reviews policy annually and confirms alignment with current regulatory requirements
Devices your policy needs to account for that are often missed
Standard disposal policies cover computers and servers. These devices are frequently overlooked:
Networked copiers and multifunction printers store images of every document that passes through them on internal hard drives. Most businesses never think to include printers in their disposal policy. When the lease ends and the printer goes back, that drive goes with it — full of whatever was copied, scanned, or faxed over the life of the machine. Make sure your policy explicitly covers printers and requires drive removal or destruction before any printer leaves the building.
The disposal workflow your policy should define
- Device flagged for decommission — IT receives notice (employee departure, end of refresh cycle, device failure). Asset is updated in tracking system with decommission status.
- Device retrieved and staged — Equipment collected from employee or location and moved to a designated, locked staging area. Intake log updated.
- Data classification reviewed — Does the device require elevated destruction requirements? Confirm destruction method per policy.
- Vendor pickup scheduled — Contact your electronics recycling and ITAD vendor to schedule collection. Confirm access logistics.
- Pickup and receipt — Vendor collects equipment, issues signed pickup receipt. Receipt filed immediately.
- Destruction completed — NIST 800-88 compliant destruction performed. Certificate of Destruction issued.
- Documentation filed and assets closed — Certificate filed with compliance records. Assets closed out in CMDB. Reconciliation complete.
Documentation your policy should require vendors to provide
- Signed pickup receipt — Issued on-site at collection, listing every device removed. This is your chain-of-custody anchor.
- Serialized drive log — Every storage device tracked by serial number from pickup through destruction. Batch-level documentation is not sufficient for most compliance frameworks.
- Certificate of Destruction — Formal documentation of NIST 800-88 compliant destruction, issued after all media is destroyed. Should name the destruction method and include serial numbers.
- Asset inventory report — For large-volume projects, a full itemized equipment list to reconcile against your asset tracking system.
Keeping the policy current
An IT asset disposal policy isn't a one-time document. It should be reviewed at least annually and updated when:
- Your regulatory environment changes (new frameworks, updated guidance)
- You change ITAD or recycling vendors
- Your device mix changes significantly (e.g., shift to SSDs, new mobile device program)
- Your organization grows into new industries or data types
- An audit or incident reveals a gap in the current process
Run a tabletop exercise: a device is reported missing during a refresh. Can you produce documentation showing where every device from that batch went? If the answer involves searching through emails and asking around, your policy isn't operational yet. The documentation trail should be findable in minutes.
EverTech as your disposal vendor in Greater Boston
EverTech provides secure electronics recycling, NIST 800-88 compliant data destruction, and ITAD with value recovery for businesses across Greater Boston. Every pickup comes with a signed receipt and serialized drive log. Every destruction project includes a Certificate of Destruction. On-site shredding is available for organizations that require witnessed destruction. Assets with residual market value are assessed for buy-back to offset disposal costs.
If you're building a disposal policy and want to make sure your vendor relationship supports it properly, that's a conversation worth having before you finalize the document.
Need a disposal vendor that supports your policy?
EverTech provides the documentation, chain of custody, and destruction standards your policy requires. Call or email to talk through your situation and get a quote.

