RAAL Logo

IT Asset Disposal and ITAD for Remote Teams in Europe: GDPR, Wiping, and What Actually Happens to Old Laptops

Andres KõivaAugust 18, 2026
12 MIN READ
IT Asset Disposal
IT Asset Disposal and ITAD for Remote Teams in Europe: GDPR, Wiping, and What Actually Happens to Old Laptops

TL;DRIT asset disposal (ITAD) for remote teams in Europe involves three things most companies underestimate: GDPR-compliant data wiping with documented evidence, WEEE (Waste Electrical and Electronic Equipment) regulations that govern how electronic devices must be recycled, and the practical challenge of retrieving devices from employees scattered across multiple countries before disposal can happen at all. This guide covers the full process, including the decisions around redeployment vs disposal and what certificates you need to keep.

A laptop issued to a new hire in 2022 is now four years old. It has been carried through airports, left on home desks, and connected to home Wi-Fi networks in three different countries as its owner moved. The battery no longer holds a full charge. The keyboard has a sticky key.

What happens to it now?

For a distributed team, "retiring a device" is not a simple exercise. The device is not in your office. It is in the employee's home in another country. Getting it back requires the same retrieval process as any offboarding. Deciding what to do with it once you have it requires understanding data wiping standards, European e-waste law, and whether refurbishment for redeployment is worth the cost.

Most IT teams have detailed processes for issuing devices. Very few have equally detailed processes for retiring them. This guide covers the full ITAD lifecycle for distributed teams in Europe.

What Is ITAD?

IT asset disposal (ITAD) is the process of securely decommissioning IT hardware at end of life. It includes data destruction, device refurbishment or recycling, documentation for compliance purposes, and, where possible, residual value recovery through resale or redeployment.

For distributed teams, ITAD begins earlier than the formal disposal process: it begins with retrieving the device from the employee's location, which for remote teams may be in a different country from the disposal facility.

When Should a Device Be Retired?

Most companies operate on a 3-4 year device refresh cycle, but the trigger for retirement should be based on condition and fitness for purpose, not just age. A 4-year-old laptop in good condition with adequate performance for its user's workload has real value for redeployment. A 3-year-old laptop with a damaged screen, failing battery, and significant wear may cost more to refurbish than its redeployment value warrants.

Device Age Typical Condition Recommended Action
Under 3 years Good to excellent, minor cosmetic wear Redeploy to next hire, prioritise over new purchase
3-4 years Moderate wear, battery at 70-80% capacity Assess: redeploy if performance is adequate for next user's role; recycle if significant issues
4-5 years Noticeable wear, battery degraded, may have hardware issues Redeploy to lower-demand roles (admin, ops) or recycle
Over 5 years Likely below modern performance requirements Recycle via certified ITAD provider

The redeployment calculation should also factor in logistics cost. Retrieving a device from an employee in the Netherlands for redeployment to a hire in Germany costs logistics fees. If the device is at the borderline of redeployability, compare the logistics cost against the saving on new hardware before committing to retrieval.

Related: Device Redeployment: The Money Most IT Teams Are Leaving on the Table

GDPR-Compliant Data Wiping: What the Standard Actually Requires

Data wiping for GDPR compliance is not as simple as "delete everything" or even a factory reset. The standard for secure data destruction depends on whether the device will be redeployed or recycled, and on the sensitivity of the data it contained.

For redeployment (device stays in service)

When a device will be redeployed to another employee, data destruction must ensure no data from the previous user is accessible to the next user. The accepted standard in Europe is overwrite wiping according to the NIST 800-88 guidelines or equivalent (such as the BSI guidelines in Germany). For solid-state drives (SSDs), which are now standard in most laptops, the preferred approach is cryptographic erasure: destroying the encryption key rather than overwriting the storage, which renders all data on the drive mathematically irretrievable.

Most MDM tools can initiate a device wipe that includes cryptographic erasure. Apple's Erase All Content and Settings (available via Jamf, Kandji, and other MDM tools) performs cryptographic erasure on FileVault-encrypted drives. Microsoft's Autopilot Reset performs a similar function for BitLocker-encrypted Windows devices.

After the MDM-initiated wipe, verify the wipe is complete in the MDM dashboard. The MDM should show the device as wiped and unenrolled. Document this confirmation as part of your records.

For physical disposal or recycling

When a device will not be redeployed, the data destruction standard is higher, because the device will pass outside the company's control entirely. Options include:

  • Software wipe plus physical destruction of storage. The storage medium (SSD or HDD) is physically destroyed (shredded or degaussed) after the software wipe. A certificate of physical destruction is issued by the ITAD provider.
  • Physical shredding of the entire device. For devices whose storage cannot be reliably wiped (hardware failure, encrypted and key lost), physical shredding is the only reliable option.
  • Certified ITAD provider recycling. The provider performs the wipe and/or destruction, then recycles the remaining components according to WEEE regulations.

The certificate of destruction

For GDPR documentation purposes, every disposed device should have a corresponding certificate of destruction or data erasure certificate. This document states: the device identifier (serial number), the date of destruction, the method used, the name of the operator or ITAD provider, and confirmation that destruction was verified.

This certificate is retained as part of your data processing records. If you are ever asked by a supervisory authority to demonstrate that personal data was properly destroyed at end of employment or device lifecycle, this certificate is the evidence.

Raal issues a certificate of data destruction for every device returned via the retrieval service and wiped before redeployment or disposal. The certificate references the device serial number and the wipe verification date. Get a retrieval estimate.

WEEE Regulations for European Teams

In Europe, the disposal of electronic equipment, including laptops, is governed by the WEEE Directive (Waste Electrical and Electronic Equipment Directive, 2012/19/EU), implemented in national law across all EU member states. Similar regulations apply in the UK post-Brexit under the UK WEEE Regulations 2013.

The core requirement: electronic equipment must not be disposed of through general waste streams. Laptops must be collected and recycled through authorised WEEE collection schemes or certified ITAD providers.

What this means in practice for distributed teams

For office-based teams, WEEE compliance is straightforward: arrange collection with a certified ITAD provider. For distributed teams with devices in multiple EU countries, it is more complex, because WEEE compliance obligations vary in their detail by country and the recycling must happen via an authorised channel in the relevant jurisdiction.

Country WEEE Recycling Approach Producer Responsibility
Germany Authorised collection points (ElektroG). Many retailers accept returns. Strong: companies must register as producers if selling EEE in Germany
France Eco-organisations (Ecologic, E-Dec, Recylum). Mandatory recycling Strong: mandatory eco-participation fees
Netherlands ICT Milieu collective; producer responsibility schemes Strong
Poland WEEE collection organisations; growing network Moderate
Estonia Eesti Elektroonikaromu (e-waste recycling); collection points Moderate
UK Authorised Treatment Facilities (ATFs) under UK WEEE Regs 2013 Strong: registration required for producers

For most distributed teams, the practical solution is to use a certified ITAD provider that holds WEEE authorisation across the EU and issues country-specific compliance documentation. Attempting to manage WEEE compliance country by country without specialist support is operationally complex and prone to error.

The ITAD Process for a Distributed Team: End to End

Step-by-step ITAD process for a remote employee device

1

Device identified for retirement. Based on age, condition, or employee departure. Asset record updated to "pending disposal."

2

Redeployment assessment. Device condition assessed against redeployment criteria (age, battery health, physical condition, performance). Decision: redeploy or dispose.

3

Retrieval initiated. Packaging dispatched to employee's current location. Collection coordinated. International customs documentation prepared if device is in a different country from the disposal or redeployment destination.

4

Device received. Condition logged. Any discrepancies from last known state noted.

5

Data destruction performed. For redeployment: cryptographic erasure via MDM, verified and documented. For disposal: software wipe to NIST 800-88 standard or physical destruction of storage medium.

6

Certificate of destruction issued. References device serial number, wipe date, method, and verifying operator.

7

Device redeployed or transferred to WEEE-certified recycler. For disposal: ensure the recycler provides a waste transfer note or WEEE compliance certificate for your records.

8

Asset record closed. Record updated with disposal date, method, certificate reference, and recycler details. Retained in asset management system for audit purposes.

Related: IT Device Security for Remote Employees: A Practical Guide for 2026

Related: IT Offboarding Process for Distributed Teams

Related: How to Recover Laptops from Remote Employees

Redeployment vs Disposal: The Financial Case

Redeployment is almost always the financially preferable option when the device is in good condition. The maths are straightforward.

A retrieved laptop in good condition with a standard 3-year-old spec has a redeployment value of the cost avoided on new hardware. For a device that would otherwise cost around the price of a mid-range business laptop to replace, the saving on new hardware minus the retrieval and refurbishment logistics cost typically represents a meaningful reduction in hardware spend per hire.

Disposal also has a cost: WEEE-certified recycling is not free. Logistics to the recycling facility, recycler fees, and administrative overhead all apply. In some cases, the recycler will pay a small residual value for devices with recoverable components (lithium batteries, aluminium chassis), but for most standard business laptops this is minimal.

The decision tree is therefore: retrieve the device in either case (both redeployment and WEEE-compliant disposal require physical retrieval). Then assess condition. If the device is redeployable, the logistics cost of retrieval pays for itself in avoided hardware spend. If it is not redeployable, the logistics cost of retrieval is the cost of GDPR compliance and WEEE compliance, which are not optional.

Do not skip retrieval for "convenience." Leaving a retired device with a former employee, or allowing an employee to keep an end-of-life device, creates both a GDPR data risk (company data remains on the device) and a WEEE compliance problem (the device is not being disposed of through an authorised channel). Both are regulatory obligations, not optional best practices.

FAQ

What is ITAD and why does it matter for remote teams?

ITAD stands for IT asset disposal: the secure decommissioning of hardware at end of life. It matters especially for remote teams because the devices are distributed across multiple countries, making retrieval and compliant disposal more complex than for office-based teams. For European companies, ITAD is not optional: GDPR requires documented data destruction, and WEEE regulations require that electronic devices are recycled through authorised channels. Failing to retrieve and properly dispose of remote employee devices creates both data protection liability and e-waste compliance risk.

What data wiping standard should be used for devices being redeployed?

For solid-state drives (SSDs), which are standard in modern laptops, cryptographic erasure is the preferred method: the encryption key is destroyed, rendering all data on the drive mathematically irretrievable. This is implemented via MDM (Apple's Erase All Content and Settings for macOS, Autopilot Reset or full wipe for Windows). For older hard disk drives, NIST 800-88 compliant overwrite wiping (one or more overwrite passes) meets the standard. In both cases, the wipe should be verified in the MDM dashboard and documented with a certificate of erasure.

What are WEEE regulations and do they apply to my company?

WEEE regulations (the EU WEEE Directive and UK WEEE Regulations 2013) govern the disposal of electrical and electronic equipment. They require that electronic devices, including laptops, are not disposed of through general waste and must instead be recycled through authorised collection schemes or certified ITAD providers. If your company places electronic equipment on the market in an EU country, producer responsibility obligations may apply. For most distributed teams, the relevant obligation is simpler: when disposing of a company laptop, use a WEEE-certified recycler and keep the compliance documentation.

What is a certificate of destruction and do I need one?

A certificate of destruction (also called a certificate of data erasure or data destruction certificate) is a document that records the secure destruction of data on a specific device. It typically includes: the device serial number, the destruction date, the method used (cryptographic erasure, overwrite, or physical shredding), and the name of the certifying operator or ITAD provider. For GDPR documentation purposes, this certificate is evidence that data lifecycle obligations were fulfilled. It is the document you would produce if asked by a data protection authority to demonstrate that a former employee's device was properly wiped before disposal or redeployment.

How do you retrieve and dispose of devices from employees in multiple EU countries?

The process is the same as any international device retrieval: packaging is dispatched to the employee's current location, a pickup is scheduled via a carrier with customs capability, and the device is shipped to the designated processing location. International customs documentation is required for cross-border returns. A managed logistics service like Raal handles the cross-border logistics layer. Once received, the device goes through data destruction and then either redeployment or transfer to a WEEE-certified recycler. For WEEE compliance, ensure your ITAD provider is certified for the EU countries involved and issues country-specific compliance documentation.


About Raal: Raal handles device retrieval for distributed teams across 150-plus countries, including international logistics, customs clearance, and certificates of data destruction for GDPR compliance. European-based, with strong coverage across EU markets. Get a retrieval estimate.

Andres Kõiva

A practical guide to IT asset disposal and ITAD for remote teams operating in Europe. Covers GDPR-compliant data wiping standards, WEEE regulations, certified recycling, redeployment vs disposal decisions, and certificates of destruction.

Keep Reading