Not every company that calls itself a recycler actually recycles responsibly, and for a business the wrong choice risks both a data breach and a compliance failure. This guide gives you the certifications that matter in Australia, the exact questions to ask, a scorecard to compare providers, and the red flags that should end a conversation.
Check three things above all: the certifications that match your risk, how they destroy your data, and whether they can prove what happens to the equipment afterwards. For a business with data-bearing equipment, prioritise ISO/IEC 27001 for information security and certified data destruction to the NIST 800-88 standard, alongside ISO 14001 and treatment in line with the AS/NZS 5377 standard for the environmental side. A responsible recycler gives you a documented chain of custody and a certificate for every device. If they cannot, keep looking.
Choosing a recycler feels like it should be simple. In practice the market is full of look-alike claims. Every provider says they are secure, certified, and environmentally responsible, and the certifications they list are an alphabet soup, some of which do not even apply in Australia. Meanwhile the stakes are real: hand your old equipment to the wrong operator and your data can end up recoverable in someone else's hands, or your e-waste can be quietly exported to an informal processing site overseas, with your company's name still on the assets.
This guide cuts through that. It explains which certifications actually matter for an Australian business, gives you a structured set of questions and what a good answer sounds like, provides a scorecard you can use to compare providers side by side, and lists the warning signs of an operator to avoid. It is written for the person who has been handed the job of clearing out old IT and wants to get it right the first time.
Written by the ITC Asset Management team. ITC is a Sydney-based IT asset disposition provider operating since 2018, holding ISO/IEC 27001:2022, ISO 14001:2015, ISO 9001:2015, and ISO 45001:2018 certifications, and sanitising data to the NIST 800-88 standard with Blancco certified erasure. We are on the answering end of these questions every week, so this guide reflects what a genuine answer to each one looks like.
The reason to take this seriously is that the two things that can go wrong are both expensive and both land on you, not the recycler. The first is data. A drive that is not properly destroyed can be read by whoever ends up with it, and deletion or a basic wipe is not enough: a study by Blancco Technology Group and Kroll Ontrack found 42 percent of second-hand drives sold online still held recoverable data. Under the Privacy Act 1988, the obligation to destroy that data is yours, and the penalty for a serious or repeated breach reaches $50 million or more.
The second is where the equipment actually goes. Responsible recycling is more expensive than dumping, so a cheap operator may be cutting corners you cannot see, sending hazardous material to landfill or exporting it to informal processing overseas. If the assets still carry your asset tags or serial numbers, that is your brand attached to an unsafe outcome. Choosing well is not about paying the most. It is about being able to prove, if anyone ever asks, that your data was destroyed and your equipment was handled properly.
Before comparing individual companies, work out which kind of provider your situation calls for. They are not interchangeable, and using the wrong type is the most common mistake.
| Provider type | Best for | Data destruction | Documentation | When to use |
|---|---|---|---|---|
| Certified ITAD provider | Business IT, fleets, data-bearing equipment | Certified, to NIST 800-88 | Serialised certificates, chain of custody | Anything that held company or customer data, or needs an audit trail. |
| General e-waste recycler | Mixed office e-waste with no data risk | Varies, often none | Basic or none | Bulk non-data equipment where the concern is purely environmental. |
| Council or retailer drop-off | Households, single devices | Self-service wipe only | None | A personal laptop or phone you have already wiped yourself. |
| Waste broker | Convenience, not accountability | Subcontracted, unclear | Often opaque | Rarely the right choice for data-bearing equipment, because the actual processor is one step removed from you. |
The trap is treating these as the same. A business that hands data-bearing equipment to a general recycler or a broker to save money has usually saved nothing and taken on the full risk, because the one thing it needed, certified destruction with proof, is the one thing those channels do not provide.
Certifications are the shortcut to knowing a recycler does what it says, but only if you know which ones apply here. Match the certification to the risk you are managing.
The international standard for information security management. For any business handing over data-bearing equipment, this is the single most important certification, because it governs how the recycler protects your information end to end.
The recognised standard for media sanitisation, covering Clear, Purge, and Destroy. A recycler should sanitise drives to this standard, using verified software such as Blancco or physical destruction, and certify it.
The international standard for environmental management. It is independent proof that the recycler runs a genuine environmental system rather than simply claiming to be green.
The Australian and New Zealand standard for the collection, storage, transport, and treatment of e-waste. Look for a recycler that treats equipment in line with the AS/NZS 5377 standard, the benchmark for safe processing in this country.
The international standard for quality management systems. It signals consistent, documented processes, which matters when you are relying on a recycler to repeat the same secure procedure on every asset.
The international standard for occupational health and safety. It shows the recycler manages the real hazards of dismantling equipment responsibly, for its workers and for the material.
You will often see recyclers, especially those copying US content, promoting R2 or e-Stewards certification, or DoD and NSA standards. These are United States schemes. They are legitimate overseas, but they are not the Australian benchmark, and their presence or absence tells you little about a recycler's fitness for an Australian business. In Australia, the combination that matters is information-security certification for your data, environmental certification and treatment in line with AS/NZS 5377 for the recycling, and a certificate of destruction for your records. Do not be swayed by a longer list of foreign acronyms.
Certifications tell you a recycler is capable. These questions tell you whether they will actually do the right thing with your equipment. Ask all seven.
"We wipe everything" is not an answer.
A good recycler distinguishes between verified erasure to the NIST 800-88 standard for reusable drives and physical destruction for the rest, and can tell you which they will use on your equipment and why.
Good answer: Blancco erasure to NIST 800-88, or shredding, with a certificate per drive.
Ask to see the actual certificates, not a logo on a website.
A genuine recycler will send you their current ISO certificates with numbers and dates you can verify with the certifying body. Vague answers or expired certificates are a warning sign.
Good answer: current ISO 27001 and ISO 14001 certificates, provided on request.
You need to know your equipment is tracked, not just collected.
The recycler should log every asset, ideally by serial number, from the moment it leaves your site to the point it is destroyed, so nothing can go missing or be diverted along the way.
Good answer: serial-level tracking from collection to destruction, with a report.
The paperwork is the proof you met your obligations.
Expect a serialised Certificate of Destruction and a Certificate of Recycling. These are what an auditor, insurer, or regulator will ask for, and they are your evidence under the Privacy Act.
Good answer: Certificate of Destruction and Certificate of Recycling for the job.
Downstream accountability separates a recycler from a dumper.
They should be able to tell you what is reused, what is recovered, where the material streams go, and confirm that hazardous material is not exported to informal processing. Reuse should be checked before recycling.
Good answer: reuse first, then material recovery, no export of hazardous waste.
Transport is where equipment is most exposed.
For business volumes, the recycler should collect from your premises with secure transport and a clear handover, not ask you to drop data-bearing equipment at a public tip.
Good answer: booked site collection with secure transport and a signed manifest.
Responsible does not have to mean expensive.
A good provider assesses whether any equipment can be refurbished and remarketed, returning value to offset the cost, with data destruction still included. See IT asset buyback.
Good answer: buyback on qualifying assets, with secure data destruction included.
Why the questions above are worth asking. Figures from named public sources.
If you are weighing up two or three providers, score each one out of 100 across these six areas. The suggested weightings reflect what matters most for a business with data-bearing equipment.
The value of scoring rather than gut feel is that it forces you to weigh the things that matter most. A provider with a beautiful website and a long list of overseas acronyms can still score poorly if it cannot destroy your data to standard or prove where the equipment went. Conversely, a provider that scores full marks on data security, certifications, and chain of custody has covered the three categories that carry two-thirds of the weight, which is exactly where a business is most exposed.
Some signals tell you almost immediately which kind of operator you are dealing with. Watch for these on both sides.
A claim is only as good as your ability to check it, and the good news is that verification is quick. Ask for the recycler's ISO certificates as documents, not screenshots, and confirm the certificate number and expiry with the certifying body named on them. Ask for a sample Certificate of Destruction so you can see exactly what you will receive and that it records serial numbers and the method used. Ask the recycler to describe, in plain terms, what happens to a drive and to a whole device once it reaches them, and listen for whether the answer is specific or a slogan.
For a larger or more sensitive contract, ask whether you can witness the destruction or visit the facility. A recycler confident in its process will welcome it. One that deflects is telling you something. The whole point of a responsible recycler is that the process and the paperwork are the product, so a good one is happy to show its work in detail rather than ask you to take its word for it.
Households do not need all of this: a council drop-off or retailer program is fine for a single device, as our guide to how to recycle electronics in Australia explains. This checklist is for businesses and anyone disposing of equipment that held data, where the certifications, the certificate of destruction, and the chain of custody are not optional extras but the whole reason to use a professional.
Common questions about choosing an e-waste recycler in Australia.
For a business, it is how they destroy your data and whether they can prove it. Prioritise ISO/IEC 27001 for information security and certified data destruction to the NIST 800-88 standard, with a serialised certificate for every device. The environmental side matters too, but a data breach is the risk that lands hardest and fastest on your business.
The ones that matter here are ISO/IEC 27001 for information security, ISO 14001 for environmental management, and treatment in line with the AS/NZS 5377 standard for the e-waste itself, supported by ISO 9001 and ISO 45001. Data should be sanitised to NIST 800-88. US schemes such as R2 and e-Stewards are legitimate overseas but are not the Australian benchmark.
For a business, yes. Under the Privacy Act 1988 you must take reasonable steps to destroy personal information you no longer need, and a serialised Certificate of Destruction is your evidence that you did. It is what auditors, insurers, and regulators ask for. See our certificate of data destruction guide.
A chain of custody is a documented record that tracks each asset from the moment it leaves your site to the point it is destroyed, ideally by serial number. It matters because it is the only way to be certain nothing was lost or diverted along the way, and it is a core part of proving your equipment and data were handled properly.
No. R2 and e-Stewards are United States certification schemes. They are meaningful overseas, but they are not the Australian requirement, and a recycler without them can still be entirely responsible here. In Australia, look for information-security certification, ISO 14001, and treatment in line with AS/NZS 5377 instead.
Ask what happens to the equipment and materials downstream, and expect a specific answer: what is reused, where the recovered metals, plastics, and glass go, and a clear statement that hazardous material is not exported to informal processing. A responsible recycler is transparent about this; an evasive answer is a reason to look elsewhere.
For business volumes and any data-bearing equipment, the recycler should collect from your premises with secure transport and a documented handover. Dropping data-bearing equipment at a public tip or council point leaves it exposed and gives you no record. Collection with a chain of custody is the safer and more compliant route.
Be cautious. Responsible recycling and certified data destruction cost money, so a price far below everyone else usually means a corner is being cut somewhere you cannot see, such as skipped data destruction or cheaper disposal. The better economics come from value recovery: a good recycler offsets cost through buyback on working equipment rather than by cutting the process.
Yes, and you should. Ask for the actual ISO certificates as documents, note the certificate number and the certifying body, and confirm they are current. Ask for a sample certificate of destruction to see what you will receive. For a larger contract, ask to witness the destruction or visit the site; a confident recycler will agree.
It checks for reuse before recycling. Working equipment is tested and, where possible, refurbished and remarketed, which keeps more value and embodied carbon in use than breaking it down for materials. For a business, that reuse can return value through buyback, with data destruction still carried out first.
ITC destroys data to the NIST 800-88 standard with Blancco certified erasure or witnessed shredding, issues serialised certificates, tracks every asset by chain of custody, and recovers value through buyback, all under ISO-certified processes.