Buyback is where secure disposal and value recovery meet: your data is destroyed to standard, and the value of your working equipment comes back to you. If you have wondered how that actually works, and whether the data is safe, this guide walks through the whole process step by step, from a rough inventory to money returned, with the data destroyed and documented along the way.
You share a rough inventory, the provider assesses the equipment and gives you a firm valuation, the gear is collected under a documented chain of custody, every device is wiped or destroyed to a recognised standard with a certificate, working equipment is refurbished and remarketed, and the agreed value is returned to you with a full report. The single most important point is the order: the data is always destroyed and certified before anything is resold. So buyback is not a trade-off between recovering value and protecting your data; it depends on protecting your data first. The result is that a retiring fleet, instead of costing you money to dispose of, returns some of its value, often enough to offset the disposal entirely. See IT asset buyback for the service.
Most businesses treat retiring IT as a cost. Buyback reframes it as an asset to recover, and the reason it is not more widely used is usually a simple worry: how can equipment that held sensitive data be sold safely. The answer is in the sequence, and once you see how the process is ordered, the worry falls away. This guide sets out each step, what happens to your data at every stage, and how the value comes back.
Five stages, with your data destroyed and certified before anything is resold.
The order is the whole point: assess, collect under custody, destroy and certify the data, then refurbish and return the value.
Data destruction (step 3) always precedes refurbishment and resale (step 4). Nothing is remarketed while it still holds recoverable data.
You share a rough count of what you are retiring by type, make and age. The provider assesses it against model, specification, condition, volume and current market demand, and returns a firm figure before anything is committed. No obligation to proceed. How that figure is arrived at is covered in our guide to what your old IT is worth.
The equipment is collected under a documented chain of custody, so every data-bearing device is logged and tracked from the moment it leaves your site. Collection is scheduled to suit you, including around a refresh or an office move.
Before anything is refurbished or resold, every data-bearing device is wiped to a recognised standard such as NIST 800-88, or physically destroyed where a drive cannot be reliably wiped, with a certificate issued for each one.
With the data destroyed, working equipment is tested, refurbished and remarketed through established channels. The hardware that is resold is the same equipment with its storage verifiably cleared.
The agreed value is returned to you, along with a full report: the asset list, the destruction method and certificate for each device, and the recycling outcome for anything past reuse. You recover value and hold the evidence.
The single feature that makes buyback safe is that data destruction comes before resale, never after.
The worry that stops businesses reselling old equipment is understandable: how can a device that held sensitive data be sold on without risk. Buyback answers it structurally. In a proper program, no device is refurbished or remarketed until its data has been destroyed to a recognised standard and certified. The machine that is eventually resold is not carrying your data; it is the same hardware with its storage verifiably cleared, and you hold a certificate proving it. Where a drive cannot be reliably wiped, it is physically destroyed and only the remaining hardware is resold, or the device is recycled. So value recovery does not sit in tension with data security; it is built on top of it. This is also what makes buyback compatible with compliance obligations, because the destruction and its certificate are exactly the evidence that standards like the Privacy Act, and for financial institutions APRA CPS 234, expect.
Buyback is not a broker taking your equipment on trust and hoping the data was cleared, and it is not shredding everything and forgoing the value. It is a single accountable process that destroys the data first, then recovers the value from what is worth reselling, and recycles the rest. One provider, one chain of custody, one report covering the lot.
Not every device returns value, but more do than most businesses assume. Here is how to gauge it.
Buyback is most worthwhile for recent, working, business-grade equipment retired at a refresh: laptops and desktops within a few years of purchase, recent servers, and current networking and monitors. These hold real resale value, and a uniform batch from a single rollout is worth more per unit than a mixed pile because it is easier to test and remarket. Older or faulty gear trends toward materials value rather than resale, though it should still be disposed of securely and is rarely worth nothing. The decisive factor is timing: equipment loses value every month it sits in storage after being replaced, so the most valuable moment to run buyback is when you retire the equipment, not months later during a clear-out. Pairing it with an EOFY refresh captures the value while it is highest.
The clearest sign buyback is worth pursuing is scale and recency together. A large refresh of recent equipment can recover enough value to offset the entire cost of the disposal, including the certified destruction, and sometimes return a credit toward the new fleet. A handful of very old machines will recover little beyond materials. Because a valuation costs nothing and carries no obligation, the practical answer is simply to have the equipment assessed before writing off its value, rather than assuming it has none.
A business retiring IT faces two problems. Buyback handles both in a single process. Figures from a named source.
Retiring IT poses two problems that are usually handled separately, and worse for it: the data has to be destroyed securely, and the value in the hardware is easily lost. Handled apart, businesses pay to destroy and pay again to dispose, and scrap value they could have banked. Buyback collapses both into one process. The data is destroyed to standard and certified, removing the breach risk, and the value of working equipment is recovered and returned, turning a cost into a credit. The reason to run it as one program rather than three tasks is that the seams between separate vendors are exactly where data goes missing and value gets scrapped. One provider, ordered correctly, closes those seams.
The questions businesses ask most about how buyback works.
Yes, because the data is destroyed before anything is resold. Every data-bearing device is wiped to a recognised standard, or physically destroyed where it cannot be reliably wiped, with a certificate, before it is refurbished or remarketed. The hardware that is eventually sold has had its storage verifiably cleared, and you hold the certificate proving it. Value recovery is built on top of data destruction, not in place of it.
No, and it is better not to. A botched DIY wipe can leave data recoverable without you knowing, and it is unnecessary. Hand the equipment over as it is, and the certified process wipes or destroys the data to standard and certifies it. Your job is simply to archive anything you need to keep before collection; the destruction is handled for you.
Against the make, model, age, specification, condition and volume of the equipment, and current market demand. Recent, working, business-grade gear in good condition and uniform batches carry the most value. A rough inventory gives an initial estimate; a firm figure follows an assessment. Our guide to what your old IT is worth explains the drivers in detail.
Often. When the value recovered from working equipment is offset against the cost of collecting, wiping and recycling the whole fleet, a large or recent refresh is frequently cost-neutral or better, and can return a credit toward new equipment. Smaller or older fleets may not fully cover the cost. A valuation tells you the net position before you commit.
A certificate of destruction for every data-bearing device, plus a full report covering the asset list, the destruction method for each item, the value recovered, and the recycling outcome for anything past reuse. This gives you both the evidence that your data was destroyed and a clean record of what was recovered, which your finance team and any auditor will want.
Send a rough inventory of what you are retiring by type, make and age, and ITC will assess it and return a firm figure with no obligation. From there, collection is scheduled under chain of custody, the data is destroyed and certified, and the agreed value is returned with a full report. There is no charge to ask.
Send us a rough inventory and we will return a firm, no-obligation valuation. Every device wiped or destroyed to standard with a certificate, working equipment refurbished, and the value returned to you.
Before you recycle it
A large share of retired business equipment still carries resale value, and that value falls every month it sits in storage. ITC assesses the fleet, sanitises every drive to the NIST 800-88 standard before anything is resold, pays you for what has value, and recycles the rest in line with AS/NZS 5377.