Saturday, 10:20. The upgrade pile finally goes to e-waste: two dead laptops, a monitor, a five-year-old NAS, and the office copier nobody will miss. Someone does a last courtesy check of the top laptop — and finds the finance director's browser still signed into the company drive, remembered.
Nothing malicious, just machines nobody formally owned at the end. That is what a disposal process prevents: the moment of handoff is the last moment your data is your problem, and it is the moment most small teams treat like a trash run. The asset inventory tells you what you own; this checklist is the exit lane for what you stop owning.
The one rule that runs the whole page: no storage device leaves the building until its data state is verified and written down.
1. The pile gets an inventory row before anything powers off
- Every device, one row: serial, assignee, data state, planned method. Six rows beat a shoebox of "laptops, assorted" — the row is what you hand the client who asks what happened to the laptop with their quarterly decks on it.
- Copiers, printers, and NAS boxes are computers too. The office multifunction has a hard disk holding every scan of the last five years; the NAS holds the actual backups. The pile that leaks is the one with paper trays.
- Photograph the pile as you tag it. Serial, condition, damage. When a recycler's manifest and your rows disagree later, photos end the argument.
- Pull the drive from any machine that will not boot. A firmware-error machine is not exempt; its disk is as full as the day it died. Dismantle at the bench; drives join the pile as first-class devices.
2. Deregister before you wipe, or the wipe creates ghosts
- MDM and enrollment first. Remove from the management console before erasing — a device wiped while enrolled comes back on someone else's login screen still claiming to belong to your company.
- Activation locks and BIOS/EFI passwords second. The Mac that went to the recycler with Find-My still set is un-recyclable and un-sellable, and the fix now needs the original owner's credentials.
- Software licenses third. The decommissioned laptop still holds a paid design-suite seat; the NAS a perpetual license nobody transferred. Cancel or reassign while the device is still in the building.
- Shared accounts the device knew, last. The label kiosk, the door-code tablet, the conference-room screen. Rotate the credentials — the offboarding sweep for people, extended to machines.
3. The wipe, per device class — one method, verified
- Company laptops/desktops: built-in secure erase (the FileVault/BitLocker key destruction path) for modern machines; physically pull the SSD for anything older or unencrypted. "I deleted my files" is not a wipe; the file table lost the address, not the data.
- Phones/tablets: factory reset is enough — after deregistration. Reset before MDM removal and you get a locked orphan; skip the reset and you get a phone that boots to the ex-employee's photo album.
- External drives and USB sticks: the ones that walk out in desk drawers. Small, unencrypted, unlogged — and often holding the client folder copied "just for the meeting" in 2023.
- NAS and server disks: wipe, then verify with a read-back. These held the backups themselves; the restore test already proved the backups live somewhere safe, so the old disk gets treated like any other device. Sentiment is not a retention policy.
- Verify, don't assume: boot it one last time. Setup assistant on a laptop, setup wizard on a phone, blank in an enclosure. "I watched the progress bar" is a claim; "it booted to the setup screen" is evidence.
4. Drives that cannot be wiped get destroyed — documented
- Failed-drive triage: firmware errors may resist software erasure; switch from wipe to destroy, never "send it and hope." Degauss or professional shred destroys platters and data together.
- SSDs change the math: shredding works only if it is fine enough — every NAND chip holds data, so "no chip larger than a grain of rice." If the recycler can't state their particle size, their truck is a transport risk with your logo on the boxes.
- The certificate of destruction is the point. Serial, method, date, provider certificate. That PDF answers the client question, the insurer question, and the access review's "disposed assets?" line at once.
5. The paper trail: one spreadsheet that closes the loop
Columns: serial, description, assignee, data state, method, date, initials, receipt. For any disposed device, one row answers what left, what was on it, what you did about it, who saw it done. Auditors, clients, and cyber-insurance questionnaires all read this document; none of them read the recycling bin.
Close the asset inventory row the same day — "disposed 12 Sep, wiped, verified" is the difference between an inventory and a museum. Keep the log under your existing log-retention policy rather than inventing a new one.
6. The handoff: choose the recycler, watch the boxes out the door
- One sentence question: "if a device from my box shows up resold in another country, what is your accountability?" Certified recyclers answer with a certification and a manifest; the free bin behind the electronics store answers with a shrug.
- You hand it over; you don't leave it in the lobby. The handoff is when custody transfers — sign the manifest, keep the paper, tie the serials to your inventory rows.
- Reuse and resale are the same checklist with one extra step: after wipe, verification boot, and deregistration, a fresh OS install so the new owner gets a working machine rather than a mystery.
The whole discipline fits one sentence: every device that leaves is wiped or shredded, every wipe is verified by a reboot, every fact is a row, every row has a receipt.
Full checklist with links on the ops-notes site: Old Hardware Disposal Checklist.
Top comments (0)