| Secure IT disposal is the controlled retirement of business hardware at the end of its life: taking the device out of service, provably destroying the data it holds by wiping to a recognised standard or physically destroying the drive, sending the remaining hardware to responsible e-waste recycling, and keeping a record that proves where every item went. |

There is a cupboard in most Christchurch offices. Behind the door sit eight or nine old laptops, a couple of desktops, a retired server and a shoebox of loose hard drives.
Nobody can say what is on any of them. Nobody wants to be the person who throws them out.
So they stay there, year after year, holding client records, payroll files, email archives and saved passwords belonging to three generations of staff.
That cupboard is not storage. It is an uncontrolled copy of your business data in a room half the building has a key to.
Secure IT disposal is how a business closes that door properly. It is the least interesting stage of the hardware lifecycle and the one most often skipped.
Doing it properly costs tens of dollars a device.
What Does Secure IT Disposal Involve?
Secure IT disposal involves two duties that both have to be done and evidenced: destroying the data on a device so it cannot be recovered, and disposing of the hardware responsibly instead of sending it to landfill. A third element ties them together, which is a record of what happened to each device and who handled it.
Most businesses manage one of the three. The laptop gets a factory reset and goes home with a staff member, or the pile goes to a recycler with no paperwork.
Neither of those is disposal. They are just the device leaving the building.
Suppliers call the managed version of this IT asset disposal, usually shortened to ITAD. The label matters less than whether the two duties are actually done and documented.
What is the difference between disposal and recycling?
Recycling deals with the materials. Disposal deals with the data first and the materials second. A recycler taking your old kit for the metal in it has no obligation to your clients’ information unless you put one in the contract, with a certificate against it.
Where does disposal fit in the hardware lifecycle?
At the very end, as the last entry in a device’s record. Your IT asset management register tracks a machine from purchase through to retirement, and secure IT disposal is the step that closes that record rather than leaving it open forever.
Deciding when a machine should be replaced is hardware lifecycle planning, a separate question with its own timing. Disposal deals with the machine coming out the other side. Businesses plan the first carefully and improvise the second, which is exactly how the cupboard fills up.
Does Deleting a File Remove the Data?
No. Deleting a file removes the pointer to it, not the contents. The data stays on the drive until something overwrites that space, and free recovery tools can pull it back in minutes. The same is true of emptying the recycle bin and running a quick format.
That one misunderstanding is why a machine that felt clean when it left the office can hand a client list to whoever buys it next.

Does a factory reset make a laptop safe to pass on?
Not on its own, and not predictably. On a recent laptop with disk encryption already switched on, a reset is usually sound, because the encryption key goes with it. On an older or unencrypted machine, or a phone with a memory card still in it, a reset can leave plenty behind.
You cannot tell which case you are in by looking at the device, so treat a reset as a convenience rather than as evidence.
What counts as secure data erasure?
Overwriting the whole drive with software that verifies the result and issues a report, physically destroying the drive, or cryptographically erasing an encrypted device by destroying its key. Anyone supplying government will also be held to the media disposal rules in the New Zealand Information Security Manual.
The reference most providers work to is NIST Special Publication 800-88, Guidelines for Media Sanitization, which sorts sanitisation into three levels: clear, purge and destroy. It was updated to Revision 2 in September 2025, so a supplier still quoting Revision 1 is working from a withdrawn document.
All three have to be verified, which in practice means a report you can still produce a year later.
How do you wipe a solid state drive?
Use the drive’s own secure erase command, crypto-erase it if the drive is encrypted, or destroy it. The flash storage in a modern laptop does not overwrite the way an old spinning disk did, so a wiping method that was sound ten years ago is not dependable on current hardware.
You do not need the mechanism, you need it in the quote. Ask for one line confirming that solid state drives are handled with the manufacturer’s secure erase or destroyed outright, and that the report says which. A supplier who cannot answer that is guessing.
Which Devices Need Secure Disposal?
Anything that has ever held business or personal information, which is a far longer list than laptops. Servers, phones, tablets, external drives, USB sticks, backup tapes, network equipment holding configurations and saved credentials, and multifunction printers with internal hard drives all store recoverable data.
The cupboard is only the part you can see. The rest is in desk drawers, in the server rack and in the leased printer beside the photocopier. If it had power and a purpose, assume it kept something.

Why are printers and copiers so often missed?
Because nobody thinks of a printer as a computer. Most office multifunction devices scan to an internal hard drive, and that drive keeps images of what has been copied, scanned and sent, sometimes going back years.
Leased machines are the sharper version. At the end of the term the device goes back to the finance company with the drive still inside, unless somebody asked for it to be removed or wiped. Almost nobody asks.
What about phones, tablets and USB sticks?
They carry the same obligation as a laptop and get a fraction of the attention. A staff phone that ran email, Teams and the payroll app holds business data, whoever paid for it.
USB sticks are worse, because they never appear on a register at all. They live in drawers and car consoles, and they leave without anyone recording that they went.
Do you have to destroy every drive?
No. Wiping to a verified standard is enough for the great majority of business data, and it leaves a working device usable, which is better for both the budget and the environment.
Save hard drive destruction for the drives that have failed and cannot be wiped, the ones holding your most sensitive material, and any drive whose history you cannot account for.
What Are the Steps in an IT Disposal Process?
Five stages, each of which leaves a record: decommission the device and mark it in the asset register, carry out data destruction by wiping to standard or physically destroying the drive, obtain a certificate evidencing that destruction, send the hardware on to a responsible e-waste recycler, and close the asset record with the outcome attached.
Written out like that it reads as bureaucracy. In practice it is one form and ten minutes per device, and it is the only version of secure IT disposal you can defend to a client, an insurer or the Privacy Commissioner.

What is chain of custody and why does it matter?
Chain of custody is an unbroken record of who held a device from the moment it left service to the moment it was destroyed or recycled. It answers the only question anybody asks after an incident, which is where that particular laptop went.
In practice it means serial numbers logged at collection, a signature at every handover, and a certificate that lists devices individually rather than describing a weight of equipment.
What should a certificate of destruction contain?
Serial numbers or asset tags for each device, the method used, the standard applied, the date it was done, and the name of the person or company that did it.
Keep those certificates with the asset record rather than in an inbox, because the request usually arrives without warning.
Should you handle disposal in house or use a provider?
Small volumes can be done in house if you have a verified wiping tool and somewhere to keep the reports. Larger volumes, failed drives, leased equipment and anything sensitive is better given to a provider who collects, wipes or shreds, certifies and recycles as one job.
The test is whether you could produce the evidence twelve months later, and if that depends on somebody remembering, use a provider.
What Are the Risks of Improper IT Disposal?
Three things go wrong, and none of them are visible on the day. Business and client information leaves the building on a device nobody was tracking, a privacy duty is breached without anyone noticing, and hardware that should have been recycled ends up in the ground. The first is the one that eventually reaches a client, and it usually looks like this.
Picture an accounting firm in Christchurch replacing fifteen laptops. Fourteen are wiped by someone in the office who knows what he is doing. The fifteenth will not boot, so it goes in the cupboard, because wiping a dead drive takes effort and nobody wants to own the decision.
Two years later the office moves, the cupboard is cleared, and the pile goes to a trader.
Nine months after that, a client rings. Their year-end file has turned up on a second-hand laptop somebody bought online.
None of what follows is a technical problem. The firm cannot say which drives were in that machine, who handled them, or what else was on them, because no record was ever kept. The answer to every question the client asks is that they do not know, and that is what loses the account.
That example is invented, but none of the steps in it are unusual.
What are the privacy obligations in New Zealand?
Two duties, in plain terms. Keep personal information secure for as long as you hold it, and do not hold it any longer than you need to. The Privacy Act 2020 sets both, and a device sold or skipped with readable data still on it fails both at once.
If information is exposed and the breach is likely to cause serious harm, you must notify the Office of the Privacy Commissioner and everyone affected as soon as you are practically able. A drive recovered from a resold machine is a notifiable breach like any other, and the age of the device is no defence.
The direct penalties are modest. Section 118 makes failing to notify the Commissioner an offence carrying a fine of up to $10,000, and the Commissioner can issue a compliance notice. The cost that hurts is the notification itself, because it means writing to clients to say you lost control of their information.
How does this relate to a data retention policy?
They are two halves of one duty and the two get confused all the time. A data retention policy decides which information you keep and for how long. Disposal deals with the hardware that information was sitting on, once you have decided you no longer need it.
A retention rule saying delete after seven years means very little if the drive holding year one is still sitting in the cupboard.
Is this the same as data loss prevention?
No, and both are needed. Data loss prevention stops information leaving through email, USB and cloud services while a device is in daily use. Secure IT disposal stops it leaving on the device itself once that device has been retired.
Most businesses spend real money on the first and almost nothing on the second.
Does the e-waste side matter commercially?
More than it did, because customers have started asking. Larger clients and tender panels now want to know how you dispose of equipment, and an accredited recycler with a paper trail answers that in one line.
The environmental case stands on its own. Electronic waste holds lead, mercury and flame retardants that should not go into the ground, alongside copper and gold worth recovering.
New Zealand declared electrical and electronic products a priority product for regulated product stewardship in 2020, but a nationwide take-back scheme has been slow to arrive, so in practice it still comes down to which recycler you choose.
What Does Secure IT Disposal Cost?
Budget roughly $15 to $40 per device for collection, verified wiping and certified recycling, with physical drive destruction usually charged per drive on top of that, and bulk clear-outs priced by the pallet rather than by the unit. It is one of the cheapest controls a business can buy and the easiest to postpone.
| What you pay for | What it covers | How it is usually priced |
|---|---|---|
| Collection and transport | Pickup from site, sealed transit, serial numbers logged at the door | Per collection, often waived above a minimum volume |
| Verified data wiping | Software erasure to a recognised standard with a per-device report | Per device |
| Physical destruction | Shredding or degaussing for failed, sensitive or unwipeable drives | Per drive |
| Certification and reporting | A certificate listing each device by serial number, plus the asset register update | Usually included, but confirm before booking |
| E-waste recycling | Responsible processing of the remaining hardware and materials | Per unit or per pallet, sometimes offset by resale value |
Equipment still in working order carries value. A recent laptop fleet can offset much of the disposal cost through resale once wiped, and any provider quoting should say whether that value comes back to you or stays with them.
Why do businesses put it off?
Because nothing has a deadline. No system fails when disposal does not happen, so it loses every argument with work that has a date on it.
The cost also arrives in a lump. Clearing ten years of accumulated equipment is a project, while twenty devices a year is a line in the budget. Start the line item now and treat the backlog as a one-off.
How Do You Clear a Backlog of Old IT Equipment?
Work through six steps in order. The first four deal with what has already accumulated, and the last two stop it accumulating again:
- Empty the cupboard onto a table and list every device, with a serial number wherever one is readable.
- Sort into three piles: definitely has a drive, might have a drive, definitely does not.
- For everything with a drive, decide wipe or destroy, then have it done under a process that issues a report.
- Send the hardware to a recycler who will tell you in writing where the materials end up.
- Add a disposal step to your leaver and refresh processes, so a device retired next month never reaches a cupboard at all.
- Record the outcome against each device in your asset register and file the certificates with it.
Almost no small business has anyone whose job this is, which is why it never gets done. Folding it into managed IT services turns disposal into a scheduled task with an owner, rather than a decision somebody keeps deferring about a pile of laptops.
Two things worth doing this week
Open the cupboard and count. Not an audit, just a number, because the number is usually what gets the work approved.
Then read one lease agreement and find what it says about the hard drive when equipment goes back. If the contract does not mention it, the finance company will not either.
Retire Your Old Kit Without Leaving Data Behind
Exodesk has supported South Island businesses since 1989 and works with organisations across Canterbury, Otago and Southland from offices in Christchurch and Dunedin. We collect retired equipment from site, wipe or destroy the data to a standard you can point at, return a certificate listing every serial number, and close the record in your asset register. Secure IT disposal is not expensive work, and most of it happens without you needing to be involved.
Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.
Frequently Asked Questions
What is secure IT disposal?
IT asset disposal is the practice of retiring redundant computer equipment so that no usable information survives on it and the materials stay out of landfill. It covers erasing or shredding storage media, documenting what was done to each item, passing what remains to an accredited recycler, and accepting that a business stays accountable for its information even after the equipment has gone.
How do I permanently erase data from an old computer?
Use software that overwrites the whole drive and produces a verification report, or physically destroy the drive. Deleting files, emptying the recycle bin and running a quick format all leave data recoverable with free tools. Solid state drives need different handling. Use the manufacturer’s secure erase command or crypto-erase an encrypted drive, because ordinary overwriting is unreliable on flash storage.
Is a factory reset enough before selling or donating a laptop?
Not reliably. On a recent laptop with full disk encryption already enabled, a factory reset usually discards the encryption key and leaves the contents unreadable. On an older or unencrypted machine it can leave recoverable files behind, and you cannot tell which case applies without checking. If the device carried business information, wipe it to a verified standard instead.
What is a certificate of destruction?
It is a document issued by whoever destroyed the data, listing each device by serial number or asset tag, the method used, the standard applied and the date. You produce it when a client, insurer or auditor asks what happened to a retired device, which is why a certificate describing a pallet of equipment rather than individual items is worth very little.
What does the Privacy Act 2020 require when disposing of devices?
The Privacy Act 2020 requires agencies to protect personal information with reasonable security safeguards and not to hold it for longer than it is needed. In practice that means personal information on a retired device must be securely destroyed rather than simply deleted. If it is exposed and the breach is likely to cause serious harm, you must notify the Office of the Privacy Commissioner and the individuals affected.
Which devices hold data that needs destroying?
Laptops, desktops, servers, phones, tablets, external drives, USB sticks and backup tapes all hold recoverable data, and so do multifunction printers with internal hard drives and network equipment storing configurations and saved credentials. Leased printers are the most commonly overlooked, because the machine returns to the finance company with its drive still inside.
Should we wipe drives or physically destroy them?
Wiping to a verified standard is sufficient for most business data and leaves a working device usable, which costs less and wastes less. Destruction is the right call for drives that have failed and cannot be wiped, drives holding highly sensitive material, and any drive whose history is unclear. Most businesses use both methods. The decision is made device by device rather than batch by batch.
How much does IT disposal cost in New Zealand?
Budget roughly $15 to $40 per device for collection, verified wiping and certified recycling, with physical drive destruction charged separately per drive. Bulk collections are normally priced per pallet rather than per unit. Recent equipment in working order can carry resale value that offsets part of the bill, so ask whether that value is returned to you.
Does a magnet erase a hard drive?
A strong enough magnetic field will, and the industrial version of that is called degaussing, but a household or fridge magnet comes nowhere near the strength required. Degaussing also destroys the drive electronics, so the device cannot be reused afterwards. It does nothing at all to a solid state drive, because flash memory does not store data magnetically. If you want a drive erased and still usable, wipe it to a verified standard instead.
Where can businesses recycle old computers in Christchurch and Dunedin?
Both cities have commercial e-waste recyclers and some councils run drop-off points, but a drop-off is not secure disposal, because it leaves no chain of custody and no record of what happened to the data. For business equipment, use a provider that collects from your site, destroys the data first and issues a certificate listing each device, which is what Exodesk arranges across Canterbury, Otago and Southland.
Can we just take old computers to the tip?
Not if they have ever held business or personal information, and it is a poor environmental choice besides. A device left at a landfill or a general drop-off is outside your control and outside any chain of custody, so you have no way to show what happened to it. Use a recycler who destroys the data first, lists what they took by serial number, and tells you in writing where the materials go.
Does Exodesk handle IT disposal for Christchurch and Dunedin businesses?
Exodesk works with organisations across Canterbury, Otago and Southland from offices in Christchurch and Dunedin, and has supported New Zealand businesses since 1989. The work covers collection from site, verified wiping or physical destruction, a certificate listing every serial number, responsible recycling of the hardware, and an update to your asset register. We handle both one-off backlog clear-outs and an ongoing arrangement for equipment as it retires.

