Professional · Lesson 4 · ~7 min
Decommissioning & Data Destruction.
Eventually devices leave the organisation — through ITAD partners, donation channels, or as e-waste. The end-of-life phase has the smallest carbon footprint of the lifecycle (<1 %), but the largest security, audit and reputational risk. A single unwiped drive on a sold laptop is a data breach. A single uncertified ITAD partner is a compliance hole.
This lesson covers the rules: NIST 800-88 sanitisation, ITAD partner selection, donation cascades before recycling, and the paperwork that makes everything defensible to an auditor.
Three things to get right, in order
Data, donation, recycling
1. Wipe the data — with a certificate. The risk is no longer 'someone might recover a photo'; it is 'are you GDPR-compliant'. The standard is NIST SP 800-88 Rev. 1 (Guidelines for Media Sanitization). Every drive that leaves the organisation needs a sanitisation certificate referencing the level applied (Clear, Purge, or Destroy).
2. Cascade to donation channels where possible. A 5-year-old corporate laptop is often a digital-inclusion non-profit's primary inventory. Multiple Luxembourg programs (Digital Inclusion among them) take corporate donations at scale — often picking up by truck, providing tax receipts and tracking documentation.
3. ITAD only for true end-of-life. When the device truly cannot serve another role, IT Asset Disposition (ITAD) partners handle dismantling, material recovery, and the documentation needed for environmental audit (waste manifests, material-recovery reports).
Each step has audit consequences. Get step 1 wrong and you have a data breach. Skip step 2 and you waste resources. Skip step 3 properly and you have an environmental compliance hole.
Choosing an ITAD partner
Three certifications, one paperwork standard
• ISO 14001 (environmental management) — the partner's own operations are documented and audited for environmental impact. Without this, you cannot defend the environmental side of your decommissioning.
• ISO 27001 (information security) — the partner's own operations are documented and audited for information security. Without this, GDPR liability for any breached data follows you, not them.
• NIST SP 800-88 sanitisation certificates per device — written confirmation that each drive was sanitised, to which level, by which technician. The audit trail that makes data destruction defensible.
• R2 (Responsible Recycling) or e-Stewards certification — global ITAD certifications covering downstream tracking. Confirms that the materials you hand over don't end up in informal recycling streams overseas.
What to ask for in the RFP: copies of the certifications, sample audit reports, sample sanitisation certificates, and the downstream supply-chain map (where do the materials actually go after dismantling).
Correct.
Not quite — review the section above.
Donation cascade before recycling
Working devices belong with new users, not in a shredder
In Luxembourg, the primary corporate donation channel is Digital Inclusion Luxembourg (digital-inclusion.lu). They accept corporate bulk donations, will pick up by truck for larger volumes, and provide tracking documentation that can support tax receipts.
What they want:
• Working laptops, desktops, monitors, tablets, smartphones recent enough to still receive security updates.
• Drives wiped to NIST 800-88 Clear or higher (they re-image anyway, but you must do this for GDPR compliance).
• Volume preferred — they have the logistics for 20+ devices in one drop.
What they cannot use:
• Devices > 8–10 years old (too old to install modern Linux comfortably).
• Devices with non-functional displays, motherboards or batteries that can't be replaced economically — those go to ITAD.
Other cascade paths: schools, training NGOs, employee-buy-out programmes (one-time discount sale to staff at end of cycle), regional refurbishers who buy ex-corporate fleet stock in bulk.
Correct.
Not quite — review the section above.
What good material recovery looks like
What the ITAD partner should be reporting
From a typical laptop, current technology recovers:
• Aluminium chassis at near 100 %.
• Copper in cables and traces at ~95 %.
• Gold and silver in connectors and IC pins at ~70–80 %.
• Lithium and cobalt in batteries at ~50–70 % (rising as EU Critical Raw Materials Act incentivises recovery infrastructure).
• Rare earths (neodymium, dysprosium) at <30 % — current technology, improving slowly.
The material recovery report supports two things: CSRD reporting (Scope 3 lifecycle disclosures, see Lesson 5) and the corporate sustainability narrative. 'We decommissioned X devices, recovering Y tonnes of aluminium, Z kg of copper, A grams of gold' is the language that survives an audit. 'We sent them to a recycler' is not.
Why this matters for the rest of the path
Connecting the dots
Lesson 5 — Reporting & Compliance covers what to measure, how to report it, and which EU instruments (CSRD, ESRS E1+E5, Right to Repair, Critical Raw Materials Act) require what from the IT lifecycle.