Why schools and MATs need a controlled IT disposal process
Schools and multi-academy trusts handle large volumes of technology across classrooms, offices, server rooms, libraries and remote users. Devices can contain pupil, parent, staff, safeguarding, SEND, HR, finance and operational information. Disposal therefore needs to be treated as a controlled information-security and asset-management process, not simply as recycling.
Department for Education guidance says schools, academies and trusts must protect personal data and demonstrate compliance. For most personal data, the school or multi-academy trust is the data controller. That responsibility continues when equipment reaches end of life.
MAT-wide governance versus individual school activity
A multi-academy trust may centralise IT support, procurement, asset registers, security policies and disposal contracts while individual academies still hold equipment locally. Define clearly which decisions belong to the trust and which can be made at school level.
A consistent trust-wide disposal standard can reduce variation between sites and make evidence, supplier management and audit easier.
1. Confirm who can authorise disposal
Define authorised roles before equipment is released. Depending on local governance, this may involve the headteacher, trust IT leadership, finance, data protection, asset owners or another delegated authority.
The disposal workflow should record approval rather than relying on an informal request to 'clear the old IT room'.
2. Check the asset register
DfE guidance recommends maintaining a fixed asset register for relevant assets, recording location, responsibility and condition, tagging assets and having procedures for moving, transferring and disposing of them.
Reconcile equipment proposed for disposal against the school's or trust's asset records. Missing, duplicate or unexpected assets should become visible exceptions.
3. Physically discover equipment
Asset registers can be incomplete. Survey classrooms, offices, cupboards, server/comms rooms, libraries, reception, reprographics areas, ICT suites and storage areas.
Include equipment held by remote staff or temporarily loaned to pupils where it remains trust property.
4. Identify ownership
Not every device on school premises necessarily belongs to the school or trust. Check leased laptops, managed print devices, telecoms equipment, contractor hardware, local-authority assets and equipment supplied under specific funding or service arrangements.
Do not sell, destroy or recycle equipment until the organisation is authorised to dispose of it.
5. Identify data-bearing devices
Look beyond laptops and desktops. Servers, SSDs, HDDs, tablets, phones, USB devices, external drives, printers, multifunction devices, CCTV systems and network/security appliances can retain information.
ICO guidance notes that personal data may remain on many devices with permanent memory and warns that a faulty device can still contain accessible data.
6. Check retention requirements
Before sanitisation or destruction, determine whether information on the device must be retained. DfE guidance says schools should use retention policies and schedules and dispose of information safely when it is no longer required.
Migrate or preserve authorised records before irreversible action.
7. Separate data retention from hardware retention
The school may need to retain information without retaining the original device. Where appropriate, authorised records can be migrated to managed systems before the hardware enters disposal.
Conversely, retaining a device indefinitely should not become a substitute for an effective records-retention process.
8. Back up required information
Confirm that required files, configuration, teaching resources or business records have been transferred to approved systems and can be accessed before sanitisation begins.
Do not assume cloud synchronisation has completed successfully; verify critical migrations where appropriate.
9. Remove equipment from active management
Coordinate disposal with identity, endpoint and management systems. Depending on the environment, this may include MDM, directory services, endpoint security, inventory tools, licensing systems and device-management portals.
Removing a device from management does not itself erase local data.
10. Revoke credentials and certificates
Network and security devices may retain credentials, certificates and configuration. NCSC guidance recommends revoking certificates associated with network devices before disposal and changing or revoking other credentials as appropriate.
Keep detailed secrets out of the disposal report; the technical change record can hold the sensitive evidence.
11. Choose the sanitisation outcome
Decide whether media will be securely sanitised for reuse, physically destroyed or handled by another approved route. The decision should reflect information sensitivity, media type, condition, organisational policy and intended disposition.
Avoid assuming that a factory reset or file deletion is always sufficient.
12. Treat failed equipment as data-bearing
A laptop that does not boot or a drive that reports errors may still contain recoverable information. Quarantine failed media and route it through the approved exception process.
Do not send failed devices directly to general recycling simply because normal wiping software cannot access them.
13. Securely stage equipment awaiting collection
ICO audit guidance recommends storing hardware awaiting destruction in a locked area with restricted access and maintaining logs of devices awaiting destruction and their location.
Keep unprocessed equipment separate from sanitised equipment and restrict access to authorised staff and contractors.
14. Maintain chain of custody
Record responsibility when equipment moves from the school to a trust hub, collection vehicle, ITAD facility or destruction process. Relevant fields can include releasing and receiving parties, date/time, site, consignment and asset/container references.
This becomes especially important for MAT projects collecting from several schools.
15. Use collection manifests
The collection manifest should be reconcilable to the approved disposal list. For data-bearing or higher-value equipment, serial-level records provide stronger traceability.
Where lower-risk peripherals are managed by quantity, agree that approach before collection.
16. Control multi-site collections
For MAT-wide refreshes, maintain site-specific manifests and project references so that assets from each academy remain identifiable. Consolidation at a central hub should not erase the source-school relationship where that information is needed for reconciliation.
17. Require appropriate supplier controls
ICO guidance says organisations should have appropriate contracts with third parties used to dispose of personal information, including security and accountability provisions, and should check that third-party services meet the agreed standard.
Review where assets are stored, who processes them, whether subcontractors are used, how failed sanitisation is handled and what evidence is produced.
18. Verify sanitisation results
A report should distinguish successfully sanitised media from failed or escalated media. NIST SP 800-88 Rev. 2 places emphasis on verification and validation of sanitisation outcomes.
Do not accept a report where every device is automatically marked successful despite known failures or missing media.
19. Physical destruction evidence
Where media is destroyed, the evidence should connect the destruction process to the relevant asset or media population. ICO guidance recommends maintaining destruction logs and obtaining certificates from third parties that securely destroy hardware.
20. Reuse before recycling where appropriate
Securely sanitised equipment that remains useful may be redeployed internally, sold or donated under an authorised process. Reuse can preserve asset value and extend equipment life.
The security gate comes first: equipment should not enter an external reuse route until the required sanitisation and validation are complete.
21. Asset recovery and resale
Recent laptops, workstations, servers and networking equipment may retain residual value. If the trust uses asset recovery to offset project costs, require transparent reporting that reconciles recovered value to the relevant assets.
Do not allow resale value to override ownership, retention or data-security controls.
22. Donation
Schools and trusts may choose to donate suitable equipment after secure sanitisation. Donation should still follow approval, inventory, data treatment and transfer controls.
Record which organisation received the equipment and when responsibility transferred.
23. Recycling
Equipment that is unsuitable for reuse should enter an appropriate recycling route. Keep recycling evidence separate from data-sanitisation evidence: a recycling certificate does not by itself prove that information on storage media was securely removed.
24. Update the asset register
After disposal, update fixed-asset and IT inventories so disposed devices no longer appear as active equipment. Record the authorised disposition and relevant project reference.
DfE guidance recommends procedures for moving, transferring and disposing of fixed assets and periodic checks that the register remains accurate.
25. Retain disposal evidence
Maintain evidence proportionate to the project. This may include approval, source inventory, collection manifest, chain-of-custody record, sanitisation report, destruction certificate, exception register, resale/reuse statement, recycling evidence and final reconciliation.
ICO guidance specifically recommends keeping secure-disposal records, destruction logs and certificates.
26. Check certificates against what was sent
A certificate should not simply be filed without review. ICO guidance recommends assigning someone to check that destruction certificates match what was sent for destruction.
For large MAT projects, reconcile certificates and processing reports against the site manifests.
27. Record exceptions
Common exceptions include missing assets, unreadable serial numbers, unexpected drives, failed sanitisation, disputed ownership and equipment collected from the wrong site.
Each exception should have an owner, status and documented resolution.
28. Protect the evidence pack
Asset reports may reveal names, locations, hostnames, device models, serial numbers and infrastructure details. Apply appropriate access control and retention to the disposal evidence itself.
Collect only the information needed to demonstrate accountability.
29. Audit the process
ICO guidance suggests internal audits to check that secure-disposal procedures are followed. MATs can use periodic sampling across academies to identify inconsistent local practices and improve the trust-wide process.
30. Review the supplier periodically
Do not treat due diligence as a one-off procurement event. Review service performance, security incidents, exception handling, certificates, downstream routes and contract requirements periodically, especially where the same provider serves multiple schools.
A practical MAT disposal workflow
Approve the project; identify participating schools; reconcile asset registers; perform physical discovery; establish ownership; check retention; migrate required data; define sanitisation/destruction routes; securely stage equipment; create site manifests; record custody; process and validate media; resolve failures; recover value or reuse where authorised; recycle remaining equipment; reconcile each site; update registers; and retain the evidence pack.
Suggested evidence pack for a school or MAT
A strong pack can include project approval, school/site list, source asset inventory, collection manifests, chain-of-custody records, sanitisation results, destruction certificates, exception register, asset recovery or donation statement, recycling evidence and final reconciliation.
The precise documents should reflect the trust's risk, policies and contractual requirements.
Common mistakes
Common mistakes include putting old computers in a general skip; assuming factory reset always sanitises data; forgetting printers and removable media; sending faulty drives to recycling without data treatment; failing to update the asset register; allowing equipment to accumulate in unlocked rooms; using a third party without adequate contract controls; accepting generic certificates with no reconciliation; and mixing equipment from multiple academies without source-site records.
Questions to ask an ITAD provider
Can you report by serial number and source school? How do you record chain of custody? Which sanitisation methods do you use for HDD, SSD and NVMe? How do failed drives appear in reports? Can you provide sample sanitisation and destruction evidence? Where is equipment stored? Are subcontractors involved? How is resale value reconciled? What happens to equipment that cannot be reused?
How Compritech can support schools and MATs
Compritech provides engineer-led IT asset disposition and infrastructure services across the UK. Depending on scope, this can include onsite discovery, serial-level asset capture, secure collection, chain of custody, data sanitisation and destruction, server/network decommissioning, asset recovery, donation/reuse support, recycling and final reconciliation.
For multi-site trusts, reporting can be structured around individual school locations while maintaining a consistent project-wide process.
Final takeaway
For schools and multi-academy trusts, secure IT disposal is an extension of data protection, asset management and cyber security. The strongest process begins with accurate inventory and authorised retention decisions, protects equipment while it awaits processing, maintains custody, validates sanitisation and ends with evidence that can be reconciled back to the school or trust's records.
A device is not safely disposed of merely because it has left the premises. The process is complete when its data, asset status and final disposition are accounted for.
Related Compritech guides
- IT Asset Disposal for Schools: A Straightforward Guide
- What Evidence Should an ITAD Provider Supply?
- NIST SP 800-88 Rev. 2: Clear, Purge or Destroy?
- When Can Resale Value Offset ITAD Project Costs?
Primary guidance
- Department for Education — Data protection in schools
- Department for Education — Record keeping and management
- Department for Education — Managing school fixed assets
- ICO — Disposal and deletion
- NIST SP 800-88 Rev. 2
Planning a school or MAT IT disposal project?
Compritech provides engineer-led ITAD, secure data sanitisation and destruction, multi-site collection, asset recovery and evidence-led reconciliation for UK organisations.
Discuss your projectOnsite data destruction