
IT Asset Disposition Services: Secure Data Wiping, Destruction and E-Waste Recycling
Retired laptops, servers and drives still hold client files, passwords and email. NetSys wipes or destroys every drive to NIST SP 800-88, tracks each device by serial number until it reaches its final destination, and gives you a certificate of data destruction for every job.
The short answer
IT asset disposition (ITAD) is the secure, documented retirement of business equipment: laptops, desktops, servers, phones and drives that are being replaced, returned from a lease or left behind in an office move. NetSys removes the data to NIST SP 800-88, wiping each drive or destroying it when it has failed or cannot be wiped, tracks every device by serial number to its final destination, and recycles what cannot be reused. Each job ends with a certificate listing every device, the method used and the date.
Closest related page: Hardware lifecycle management. That page covers a device's whole life, from purchase and refresh planning to retirement; this one covers only the end: removing the data, the chain of custody, certificates and recycling.
Most offices have a closet of retired laptops, a server nobody has switched off and a drawer of old phones. Each one still holds whatever it held on its last day in use: client files, saved passwords, cached email. Deleting the files or running a quick format leaves that data recoverable, and computers are not the only risk: copiers, printers, network equipment and phones store data too.
IT asset disposition closes each device out properly. We work from NIST Special Publication 800-88, Guidelines for Media Sanitization, whose second revision replaced the 2014 edition in September 2025. For every device that comes down to three things: a method (Clear, Purge or Destroy) chosen by how sensitive the data is and whether the device will be used again, a check that the method worked, and a record of it. That record is what an auditor, an insurer or a lessor asks for.
One record per device, from your desk to its final destination
Before anything moves, we list every device and drive by serial number and match the list to your asset records. Each drive gets the method NIST SP 800-88 calls for, and each result is checked before it counts. Equipment changes hands only with a signed hand-off, and the job closes with a certificate listing every device, the method used and the date, filed with each device's asset record.
What IT Asset Disposition Covers
Secure Data Wiping
Drives that will be used again are purged, not just overwritten.
- Method set per drive under NIST SP 800-88 Rev. 2: Clear, Purge or Destroy
- SSDs and NVMe drives purged with their built-in sanitize or cryptographic erase commands
- Hard drives overwritten or purged with the drive's own sanitize command
- Each wipe checked for completion, errors and drive health before it counts
Destruction and Certificates
For drives that have failed, cannot be purged or will not be reused.
- Physical destruction, with the remains inspected before the record closes
- One certificate per job, listing each device by serial number, the method used and the date
- Certificates filed with the closed asset record, ready for an auditor, insurer or lessor
- Loose drives, backup disks and spare server drives included, not just whole computers
Chain of Custody
Every device accounted for from your office to its final destination.
- A serialized inventory of every device and drive before anything moves
- Drives in locked or sealed containers whenever they travel
- A signed hand-off each time equipment changes hands
- Each device tracked to its final destination: reuse, lease return or recycling
Reuse and E-Waste Recycling
Equipment worth reusing gets reused; the rest is recycled, never thrown out.
- Sanitized equipment redeployed, donated, sold or returned, as you decide
- Equipment that is not reused goes to an electronics recycler, named with its certification in your records
- No computers in the trash: New York, New Jersey and Connecticut all ban it
- Each device's final destination recorded on its asset record
Lease Returns
Leased laptops, tablets and phones go back wiped, released and documented.
- Serial numbers matched against the lease schedule before anything ships
- Removed from Intune and Windows Autopilot, or released from Apple Business with Activation Lock off
- Wiped to the standard your lease names, with the certificate the lessor asks for
- The lessor's receipt filed with the certificate and the asset record
Office Moves and Cleanouts
Retire what is not making the move before the movers arrive.
- Equipment staying behind listed and dealt with before move day
- Servers, network gear, printers, copiers and phones checked for stored data, not just laptops
- Scheduled inside the move plan, so disposal does not hold up the cutover
- Coordinated with our office relocation IT project when we run the move
Why businesses bring us their retired equipment
Send a rough count of laptops, desktops, servers, phones and loose drives, where they are and any lease return dates. We will tell you which method fits each device, what records you will get and what happens next. Call 845-203-3914 or ask for a disposal plan.
- The team that tracks and buys your hardware also retires it, so the asset record and the certificate match
- Each drive's method set under NIST SP 800-88 Rev. 2, the current version of the federal guideline
- One certificate per job, listing every device by serial number, the method and the date
- Leased devices released from Intune, Autopilot and Apple Business before they go back
- On site across New York City, Long Island, Westchester, the Hudson Valley, North Jersey and Fairfield County, CT
- In managed IT and cybersecurity since 1998, from one office in Brooklyn, on month-to-month agreements
Clear, Purge and Destroy: the three NIST sanitization methods
NIST SP 800-88 Rev. 2 defines three ways to sanitize storage. The method follows from how sensitive the data is and whether the device will be used again; the technique within it depends on the kind of drive.
| Method | What it is | When to use it | Media |
|---|---|---|---|
| Clear | Overwrites every location a user can reach through the drive's normal interface, or resets a device to factory state where it cannot be overwritten. Stops simple recovery. One pass is enough: NIST calls the old multi-pass DoD 5220.22-M patterns obsolete | Devices staying inside the company that held low-sensitivity data, and phones or office equipment that offer only a factory reset | Hard drives. Not reliable on SSDs, NVMe or other flash storage, where spare cells and wear leveling keep old data out of an overwrite's reach |
| Purge | Makes the data unrecoverable even with laboratory techniques while leaving the device usable. Done with the drive's own sanitize commands (block erase, overwrite or cryptographic erase), or a degausser for some magnetic media | Working devices leaving your control: lease returns, resale, donation and recycling for reuse. NIST prefers it to Clear wherever the device supports it | SSDs, NVMe drives and hard drives, through their built-in sanitize or cryptographic erase commands. Degaussing never works on flash, and many degaussers are too weak for modern hard drives |
| Destroy | Disintegrates, shreds, pulverizes, melts or incinerates the media, so the data cannot be recovered even in a lab and the media can never store data again | Drives that have failed or cannot be purged, media that will not be reused, and data you want physically gone | Any drive or memory chip, working or not. Drilling a hole through a drive or bending it does not count: NIST notes it can leave parts readable |
Summarized from NIST SP 800-88 Rev. 2 (September 2025), which replaced the 2014 Rev. 1 and points to the IEEE 2883 standard for the technique that fits each kind of drive. It cautions that as drives get denser, some destruction techniques stop being effective, and that cryptographic erase counts as Purge only when no data was ever written unencrypted and no copy of the key survives elsewhere.
How an IT asset disposition job runs
Seven steps, from the first list to the last certificate. The order is the same for one laptop or a whole floor of them.
- Inventory: we list every device and loose drive by make, model and serial number, and match the list against your asset records and any lease schedules.
- Decide: you choose what happens to each device (reuse, lease return or recycling), and we set the NIST SP 800-88 method its data calls for: Clear, Purge or Destroy.
- Release: devices come out of Intune, Windows Autopilot and Apple Business, with Activation Lock turned off, so nothing stays tied to your company.
- Wipe: drives that will be used again are purged, or cleared where the data allows, and each wipe is checked for completion, errors and drive health before it counts.
- Move: equipment leaves your office against the inventory, with drives awaiting destruction in locked or sealed containers and a signed hand-off each time they change hands.
- Destroy: drives that have failed or cannot be purged, and any you want destroyed, are physically destroyed and the remains are inspected.
- Certify and close out: you get one certificate for the job, listing every device by serial number with the method used and the date. Reused devices go back into service or to the lessor, the rest is recycled, and each asset record is closed.
How long a job takes depends on the number of devices and locations and on any lease return dates. We confirm the schedule when we scope the job.
Returning leased laptops, tablets and phones
Microsoft says to deregister a device from Windows Autopilot whenever it permanently leaves the organization, and Apple requires you to release from Apple Business any device you no longer own or control. The order of the steps matters.
- Match: check each serial number against the lease schedule, and flag missing or damaged units before the return date.
- Back up: copy anything the user still needs from the device.
- Windows: delete the device from Intune first, then deregister it from Windows Autopilot by serial number, the order Microsoft documents.
- Apple: turn off Activation Lock in Apple Business, which replaced Apple Business Manager in April 2026, then release the device. Apple warns that a release cannot be undone and that Activation Lock cannot be managed from Apple Business afterward.
- Wipe: sanitize to the standard the lease names. If it names none, we purge to NIST SP 800-88, which notes that Purge can suit a lease return better than destruction.
- Document: keep the serial numbers, the certificate and the lessor's return receipt with the asset record.
What the disposal rules require
The main federal and tri-state rules on disposing of personal data, each in one line with its citation. They are duties on your business: your legal adviser decides which ones apply to you, and we keep the records that show how each device was handled.
| Rule | Who it covers | What it requires |
|---|---|---|
| HIPAA Security Rule, 45 CFR 164.310(d)(2)(i) and (ii) | Healthcare providers, health plans and clearinghouses covered by HIPAA, and their business associates | Policies for the final disposal of electronic health information and the hardware or media it is stored on, and its removal before media is reused. Both are required, not addressable |
| FTC Disposal Rule, 16 CFR Part 682 | Any business under FTC jurisdiction that keeps consumer report information, such as a background or credit check, for a business purpose | Reasonable measures against unauthorized access when disposing of it. Selling, donating or transferring a computer that holds it counts as disposal |
| FTC Safeguards Rule, 16 CFR 314.4(c)(6) | Financial institutions under FTC jurisdiction, such as mortgage brokers and tax preparers | Procedures to securely dispose of customer information within two years of its last use for that customer, unless it is needed for business operations, required by law or cannot feasibly be removed on its own, plus a periodic review of the retention policy |
| New York General Business Law 399-h | Businesses disposing of records in any form that hold personal identifying information, such as a name with a Social Security, driver's license or account number | Shred the record, destroy the information, make it unreadable, or follow commonly accepted industry practices that reasonably ensure no unauthorized person can reach it |
| New Jersey, N.J.S.A. 56:8-162 | Businesses and public entities holding customer records that contain personal information | Destroy, or arrange to destroy, records no longer to be kept by shredding, erasing or otherwise making the personal information unreadable, undecipherable or non-reconstructable |
| Connecticut, Conn. Gen. Stat. 42-471 | Anyone who possesses another person's personal information | Safeguard it from misuse by third parties, and destroy, erase or make unreadable the data, computer files and documents before disposal |
Summaries of the text in force in September 2026, not legal advice. Under HHS breach notification guidance, health information on media that was cleared, purged or destroyed consistent with NIST SP 800-88, so that it cannot be retrieved, is not treated as unsecured health information.
Electronics disposal rules in New York, New Jersey and Connecticut
All three states keep computers and televisions out of the trash. Here is each rule in one line.
| State | Rule | What it means for a business |
|---|---|---|
| New York | Electronic Equipment Recycling and Reuse Act, N.Y. Environmental Conservation Law 27-2611 | Since January 1, 2012, businesses may not send electronic waste, such as computers, monitors, printers, small servers and televisions, to a landfill or waste-to-energy plant or put it out with the trash. Households followed in 2015 |
| New Jersey | Electronic Waste Management Act, N.J.S.A. 13:1E-99.109 | Since January 1, 2011, no one may knowingly dispose of a used desktop or laptop computer, monitor or television, or its parts, as solid waste |
| Connecticut | Covered electronic devices law, Conn. Gen. Stat. 22a-636 | Since January 1, 2011, no one may knowingly place a computer, monitor, laptop, printer or television, or its parts, in a solid waste facility |
Checked against the NYSDEC, New Jersey DEP and Connecticut General Assembly texts in September 2026. These rules decide where the hardware may go; the disposal rules above decide what has to happen to the data first.
R2v3, e-Stewards and NAID AAA, explained
Three certifications come up when you choose where retired equipment goes. Each is granted after an independent audit, so ask any recycler or destruction provider for its current certificate and check it with the issuer.
| Certification | Issued by | What it covers |
|---|---|---|
| R2v3 | SERI (Sustainable Electronics Recycling International), with audits by independent certification bodies | Electronics reuse and recycling facilities: environmental, health and safety, quality and data security practices, with the facility answerable for its downstream vendors. Facilities certified to Appendix B add data destruction tracked down to the serial number |
| e-Stewards | The e-Stewards program, with audits by accredited certification bodies | Electronics recyclers, refurbishers and IT asset disposition companies: Basel Convention rules on exporting hazardous electronic waste, vetting of downstream vendors, and data security, with NAID AAA certification now a prerequisite |
| NAID AAA | i-SIGMA | Information destruction providers, covering physical destruction and electronic media, on site or at their own facility: secure processes, chain of custody and employee background screening, checked by scheduled and unannounced audits |
From SERI, e-Stewards and i-SIGMA descriptions of their own programs, checked September 2026.
Retiring equipment soon?
Tell us roughly what is leaving, where it is and whether any of it is leased.
IT Asset Disposition FAQs
What is IT asset disposition?
IT asset disposition, or ITAD, is how a business retires technology without leaking its data or breaking disposal rules. It has four parts: an inventory of what is leaving; sanitization of every drive to a recognized standard such as NIST SP 800-88; a chain of custody until each device reaches its final destination; and reuse or recycling of the hardware, with records that prove each step. It is the last stage of hardware lifecycle management, and it covers phones, printers, copiers and network equipment as well as computers.
How do you securely dispose of old laptops and servers?
Start with a list of every device and drive by serial number. Then sanitize each drive by the method NIST SP 800-88 calls for: purge a working drive with its built-in sanitize or cryptographic erase command, and physically destroy one that has failed or cannot be purged. Handle servers drive by drive, including storage arrays and spares on the shelf. Move equipment in locked or sealed containers with a signed hand-off, reuse what is worth reusing, recycle the rest, and keep the certificate with each asset record.
What is a certificate of data destruction?
It is the record that proves the data on a device was removed, and how. NIST SP 800-88 calls it a certificate of sanitization and recommends one for every piece of media sanitized, recording the manufacturer, model and serial number, the method (Clear, Purge or Destroy) and technique, the tool and its version, how the result was verified, and the name, date, location and signature of the person who verified it. Ours covers the whole job, listing every device by serial number with the method used and the date. It is what an auditor, an insurer or a lessor asks to see.
Is wiping a drive enough, or does it have to be destroyed?
For a working drive, purging is usually enough. NIST SP 800-88 defines Purge as making the data unrecoverable even with laboratory techniques while leaving the drive usable, which is why it suits drives going back to a lessor, to another employee or to a buyer. Destroy is for drives that have failed, cannot be purged or will never be used again. A plain overwrite, which NIST calls Clear, only stops simple recovery and does not reach everything on an SSD. Drilling a hole through a drive is not destruction either: NIST notes parts of it can stay readable.
Can an SSD be wiped securely?
Yes, but not by overwriting it. SSDs and NVMe drives keep spare cells and spread writes around to reduce wear, so software that writes over the visible space cannot reach every block that once held data, and NIST SP 800-88 Rev. 2 says overwriting such drives gives very little protection. The drive's built-in sanitize commands reach all of it. On a self-encrypting drive, cryptographic erase wipes the encryption key, which works when no data was ever stored unencrypted and no copy of the key survives elsewhere. Degaussing does nothing to an SSD, and a drive that fails or refuses the commands is destroyed.
What should we do before returning leased laptops?
Match each serial number to the lease schedule and back up anything the user still needs. Then release the devices from your management tools in the order the vendors document: for Windows, delete the device from Intune and then deregister it from Windows Autopilot; for Macs, iPhones and iPads, turn off Activation Lock in Apple Business, then release the device, which cannot be undone. Wipe to the standard the lease names, and keep the certificate and the lessor's receipt with the asset record. NIST notes that purging, rather than destroying, suits a lease return, since the lessor needs a working device back.
Which laws require businesses to dispose of data securely?
It depends on the data you hold. The HIPAA Security Rule requires disposal policies for electronic health information and its removal before media is reused (45 CFR 164.310(d)(2)(i) and (ii)). The FTC Disposal Rule covers consumer report information, including when a computer holding it is sold or donated (16 CFR Part 682). The FTC Safeguards Rule requires the financial institutions it covers to have secure disposal procedures (16 CFR 314.4(c)(6)). New York (General Business Law 399-h), New Jersey (N.J.S.A. 56:8-162) and Connecticut (Conn. Gen. Stat. 42-471) require personal information to be destroyed or made unreadable before disposal. Your legal adviser decides which apply to you.
Can old computers go in the trash in New York, New Jersey or Connecticut?
No. New York has barred businesses from sending electronic waste, including computers, monitors, printers and televisions, to landfills, waste-to-energy plants or trash collection since 2012. New Jersey and Connecticut have barred disposing of computers, monitors and televisions as ordinary solid waste since 2011. Equipment that is not reused goes to an electronics recycler, and the recycler and its certification are named in your records.
How much does IT asset disposition cost?
It depends on how many devices there are and of what kind, how many drives need destroying rather than wiping, how many locations we collect from, and whether any devices go back to a lessor. Recycling can carry its own charge: in New York, manufacturer take-back programs can charge for-profit businesses with 50 or more full-time employees. We scope each job and confirm the cost before anything is collected. We work on site across New York City, Long Island, Westchester, the Hudson Valley, North Jersey and Fairfield County, CT; for offices farther away, where we support clients remotely, collection is arranged when we scope the job.
Sources and technical references
- NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization (September 2025): Clear, Purge and Destroy, cryptographic erase, verification and the sample certificate of sanitization
- 45 CFR 164.310, HIPAA Security Rule physical safeguards: disposal and media re-use at (d)(2)(i) and (ii)
- 16 CFR Part 682, the FTC Disposal Rule for consumer report information
- 16 CFR 314.4, FTC Safeguards Rule: secure disposal of customer information at (c)(6)
- New York General Business Law 399-h: disposal of records containing personal identifying information
- SERI: the R2v3 standard for electronics reuse and recycling, including Appendix B data destruction
- Microsoft Learn: deregistering a device from Windows Autopilot after deleting it from Intune
Guides on this topic
- Hardware lifecycle management: inventory, refresh plans and retirement
- IT procurement for the replacement hardware
- IT for an office move
- Intune and Windows Autopilot management
- Windows 11 upgrade and PC refresh
- HIPAA compliance for practices
- FTC Safeguards Rule compliance
- NY SHIELD Act compliance
- IT asset management for a small business
- Office move IT checklist
Tell us what is leaving, and when.
Send a rough count of devices, where they are and any lease return or move dates. We will set the method for each device, confirm the records you will receive and explain the next step.
