top of page

IT Disposal Regulations & Standards

A practical UK business guide to distinguishing IT disposal law, official guidance, technical standards and internal requirements.

UK data protection framework

UK GDPR and the Data Protection Act 2018 remain the core UK data-protection framework. The Data (Use and Access) Act 2025 amends that framework and its data-protection provisions are now in force. For IT disposal, the practical question is whether personal data remains appropriately protected throughout decommissioning, transfer, sanitisation and final disposal.

Waste duty of care

Section 34 of the Environmental Protection Act 1990 creates a waste duty of care in England and Wales. Organisations controlling waste should keep it secure, transfer it responsibly and use appropriately authorised organisations.

WEEE Regulations

The Waste Electrical and Electronic Equipment Regulations 2013, as amended, underpin the UK WEEE regime. Their effect varies according to the equipment, the parties involved and the activity being carried out, so IT disposal projects should distinguish reuse from waste treatment and recycling.

ICO disposal and secure deletion guidance

ICO guidance reinforces that simply deleting files or performing a quick reformat may not be enough. Organisations should consider the storage medium, the sensitivity of the information and whether secure deletion, destruction or a specialist provider is appropriate.

NCSC secure sanitisation guidance

NCSC guidance explains how organisations can sanitise storage media before reuse, sale, repair or disposal. It emphasises understanding the data, the media type, the intended outcome and the assurance required before equipment leaves organisational control.

NIST SP 800-88 Rev. 2

NIST SP 800-88 Revision 2, published in 2025, is a widely used technical reference for media sanitisation programmes. It is not UK law. It is useful when an organisation wants a structured framework for selecting, validating and governing sanitisation methods.

Batteries, damaged equipment and transport

Some IT assets can introduce additional transport or hazardous-material considerations, particularly damaged batteries or mixed electrical waste. Those issues should be identified before collection so packaging, transport and downstream handling can be planned correctly.

Policies, contracts and sector requirements

An organisation may choose controls that go beyond the legal minimum because of internal policy, customer contracts, cyber-security requirements, insurance, sector expectations or audit needs. These requirements are real for the project even when they are not statutory law.

Frequently asked questions

Is NIST SP 800-88 legally required in the UK?

No. NIST SP 800-88 is a US technical publication and is not UK legislation. An organisation may still choose to use it as a recognised technical reference or contractual requirement.

Does UK GDPR prescribe one exact data-destruction method?

No single disposal method suits every device and risk. The organisation should select controls that are appropriate to the information, media, threat and intended outcome, then be able to demonstrate that decision.

Is a Certificate of Data Destruction itself a legal requirement?

Not in every project. A certificate can form useful evidence, but the required documentation depends on the organisation, contract, sector, risk and disposal process.

Does WEEE mean every old device must be recycled immediately?

No. Equipment that can be securely and lawfully reused may follow a reuse route. Where equipment becomes waste, the relevant waste and WEEE controls become important.

What should we ask a supplier who says they are “compliant”?

Ask which specific law, standard, certification or scheme they mean; what scope it covers; who issued it; whether it is current; and what evidence you receive for your own project.

What is the difference between a standard and a certification?

A standard describes requirements or guidance. Certification is a separate assessment or recognition process against a defined scope. Saying a process follows a standard is not the same as holding an independent certification.

bottom of page