Skip to content

United Kingdom · original

IT asset disposal GDPR checklist for UK organisations

UK GDPR survived Brexit as UK GDPR plus the Data Protection Act 2018. Every drive that held personal data stays a controller problem until you can show it was sanitised or destroyed. RecyclicTech is the documented exit for organisations — not a skip, not a household courier.

Retired London enterprise IT prepared for WEEE-compliant ITAD collection

What to take from this page

  • You remain the controller after the van leaves.
  • Factory reset and “IT will handle it” are the usual failures.
  • Inventory serials first. Then NIST SP 800-88. Then the file.
  • Processing is in Rădăuți, Romania — declared, not a hidden plant.
  • No published ICO number, DSPT badge or CCS lot on this page.

What still applies after Brexit

The UK kept the substance of GDPR. Article 5(1)(f) — security, including against unauthorised processing and accidental loss. Article 32 — appropriate technical and organisational measures. Article 5(2) — you must demonstrate it. IT disposal is inside that scope. An unwiped laptop on a marketplace is unauthorised processing with a postage stamp.

You remain the controller

Handing cages to a collector does not move controllership. If the contractor mishandles media, the ICO still looks at the organisation that collected the data. That is why RecyclicTech returns a serial-level pack instead of a verbal “it’s gone”. Public bodies: we do not claim an NHS DSPT badge, an RM6098 lot or ADISA membership we have not published. The same file is the evidence.

Where the kit actually goes

Collection is nationwide in the United Kingdom. Processing after collection is in Rădăuți, Romania — Strada Putnei 213. That is an international movement of equipment, declared on the file. Commodity UK pages imply a local plant they may not have. We would rather lose a tender than invent a Slough destruction hall.

A DPO checklist that matches our job

1. Inventory data-bearing serials before the first rack moves.

2. Choose NIST SP 800-88 erase or physical destruction in the assessment — not “format and donate”.

3. Keep chain of custody from floor to process.

4. File the per-serial certificate with WEEE duty-of-care papers.

5. Do not put household laptops on this booking — they use /donate/.

6. Digital Waste Tracking ID: empty until RecyclicTech holds a real consignment ID.

Wipe or physical destruction?

Neither is universally better. Erase (NIST SP 800-88 Clear or Purge) keeps residual value and is the default when the drive can be sanitised. Destroy is for failed media, policy that forbids reuse, or when you instruct it in the assessment. RecyclicTech will not certify a factory reset.

Public sector — what we will not claim

The controller still owns the risk after the van leaves — NHS trust or listed company, same file. We do not publish an NHS DSPT badge, a Crown Commercial Service lot, ADISA membership or NCSC partnership we have not been issued. If your framework requires those numbers, we lose that tender honestly.

Official sources

Written 2026-08-28. Not a paraphrase of the pages currently ranking for this query.

Questions

Straight answers.

Does UK GDPR still apply to IT disposal after Brexit?+

Yes. UK GDPR and the Data Protection Act 2018 cover personal data on retired media until it is no longer usable. RecyclicTech’s job is the demonstration, not a legal opinion.

If RecyclicTech processes in Romania, is that our problem?+

It is declared on the file so it is not a surprise in an audit. You remain the controller. We remain the documented processor of the kit. We do not hide the depot behind a UK trading style.

Can we just delete files and recycle the chassis?+

The ICO expects documented secure methods for devices — wiping or destruction — not emptying a recycle bin. RecyclicTech will not certify a format.

Are you ICO-registered?+

No ICO registration number is published on this site. No T11, no Environment Agency permit number, no invented ISO seal. What is live is the serial-level file.