When you hand your retired IT to an ITAD provider, you are trusting them with your data long after it leaves your building. Not all providers earn that trust equally. Choosing well is about a handful of criteria that actually matter: real certifications, verifiable data destruction, evidence you can hold, and responsible handling of what remains. This guide sets out what to look for, and the questions that separate a genuine partner from a logo on a truck.
Choose an IT asset disposition provider on evidence, not promises: genuine, current certifications; a documented, verifiable data destruction process with a certificate for every device; an unbroken chain of custody from your door to final outcome; transparent reporting at asset level; and responsible, traceable handling of what is reused or recycled. The reason these are the criteria that matter is that ITAD is a trust relationship carried out where you cannot see it. Once your equipment leaves, you are relying on the provider to destroy the data and handle the hardware exactly as they said, and your only protection is the evidence they give you and the standards they actually hold. A provider who can show certifications, prove destruction with certificates, and account for every asset is one you can stand behind if you are ever asked. Choosing on price or convenience alone, without that evidence, is where disposal risk hides. It is the difference between a passing arrangement and a real IT asset disposal partner.
Choosing an ITAD provider looks like a procurement task and is really a risk decision. The equipment is easy to hand over; the consequences of handing it to the wrong provider, data that resurfaces, a breach traced back to a drive you thought was destroyed, land entirely on you. This is different from choosing a general recycler for household electronics; for a discussion of that, see our guide on how to choose an e-waste recycler. Here the focus is on choosing a partner to trust with business data and assets.
Most providers will say the right things. The difference is which of them can prove it, and give you evidence you could rely on later.
The first differentiator is certification, and specifically certification that is real, current and relevant. Certifications to recognised standards indicate that a provider's processes for information security, environmental management, quality and safety have been independently assessed, rather than merely claimed. It is worth checking what a provider actually holds rather than accepting a general assurance of being certified, because the value is in the specific, verifiable standards. ITC holds certification to ISO/IEC 27001:2022 for information security, ISO 14001:2015 for environmental management, ISO 9001:2015 for quality, and ISO 45001:2018 for occupational health and safety, and processes e-waste in line with AS/NZS 5377.
The second differentiator is whether data destruction is verifiable. Any provider can say they wipe drives; the ones worth choosing destroy data to a recognised standard such as NIST 800-88, verify it, and issue a certificate for each device. Evidence is the whole point: a certificate of destruction is what turns your data was destroyed from a hope into something you can demonstrate. The third differentiator is chain of custody, an unbroken, documented record of your assets from collection to final outcome, so there is never a point where your equipment is simply unaccounted for. The fourth is transparency: clear reporting of what happened to each asset, and honest handling of what is reused or recycled, so nothing disappears into a vague general process.
The single most useful test is to ask a provider to show you what you would receive: the certificate, the report, the chain-of-custody record, the actual certifications. A genuine partner produces these readily. A provider who talks in reassurances but cannot show the evidence is telling you what your protection would look like if something went wrong.
Five things to weigh when comparing ITAD providers, roughly in the order they protect you.
Look for real certification to recognised standards for information security, environment, quality and safety, and check what the provider actually holds. Certifications are independent evidence that the processes behind the promises have been assessed.
Confirm data is destroyed to a recognised standard, verified, and evidenced with a certificate per device. This is your proof, and the thing you will most want if a question ever arises.
Require a documented chain of custody from collection to outcome, with no gap where your assets are untracked. Custody is what closes the window in which equipment could go astray.
Choose a provider who tells you what happened to each asset, not just that a collection occurred. Clear reporting lets you reconcile disposals against your own records and stand behind the outcome.
Favour providers who handle reuse and recycling responsibly and return value from serviceable assets through buyback, so disposal is both accountable and economical.
The provider worth choosing is the one who can demonstrate every one of these, not just claim them. If you want to see what that evidence looks like in practice, talk to our team and ask us to show you the certificate, the report and the certifications up front.
For each thing a provider tells you, there is a piece of evidence that proves it. Ask for the right-hand column.
When disposal goes wrong, the provider is not the one who answers for the breach. You are. Figures from named sources.
Responsibility for your data does not transfer with the boxes. If a drive you handed to an ITAD provider surfaces with data on it, it is your organisation that faces the breach, the notification and the potential penalty, not the provider whose truck took it away. That is the whole reason the selection criteria are about evidence rather than assurances: the certificate, the chain-of-custody record and the certifications are precisely what you would rely on to show you took reasonable care, and what you would lack if you chose on price and convenience alone. Choosing an ITAD provider well is not about finding the cheapest collection; it is about choosing the partner whose evidence you would be comfortable standing behind if you were ever asked to prove what happened to your data. Against a maximum penalty of $50M or more, the provider who can show you the proof up front is the one worth choosing.
The questions organisations ask most when selecting an IT asset disposition partner.
Whether the provider can prove what they claim. The most important test is asking to see the actual evidence you would receive, the certificate of destruction, the chain-of-custody record and the certifications held, rather than accepting general reassurances. A provider who produces these readily is one you can rely on; one who cannot is showing you exactly how little you would have to fall back on if something went wrong.
Look for genuine certification to recognised standards covering information security, environmental management, quality and safety, and check what is actually held rather than accepting a vague claim of being certified. ITC, for example, holds ISO/IEC 27001:2022, ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018, and processes e-waste in line with AS/NZS 5377. The point is verifiable, specific standards, not a general badge.
An e-waste recycler focuses on responsibly processing electronic waste. An ITAD provider does that too, but also takes on the data, the value and the accountability: secure data destruction with evidence, chain of custody, asset-level reporting and value recovery. For business equipment holding data, you are choosing a data and asset partner, not just a recycler, which raises the bar on the evidence you should expect.
Only if it also meets the evidence criteria. Price matters, but a low price that comes without verifiable certifications, certificates of destruction and chain of custody is not a saving; it is unpriced risk, because the cost of a disposal breach dwarfs any collection fee. The right approach is to shortlist providers who can prove the fundamentals, then compare on price and value among those, rather than letting price override the safeguards.
A good one will where value exists. Serviceable assets can carry resale value, and a provider who recovers it through buyback and reports it back turns disposal into something that offsets cost rather than only incurring it. Value recovery should never come at the expense of data security, so the sequence is always destroy the data with a certificate first, then value the cleared hardware, but a partner who does both is preferable to one who only disposes.
Through chain of custody. A documented chain of custody records your assets at every step from collection to final outcome, so there is never a point where they are simply unaccounted for. Combined with asset-level reporting, it means you can see what happened to each device rather than trusting that a collection was handled properly. Ask any prospective provider how they maintain custody and what record you receive.
See what a genuine ITAD partner looks like: real certifications, data destruction verified to a recognised standard, a certificate for every device, chain of custody, and asset-level reporting you can stand behind.
Work with ITC
ITC Asset Management has run IT asset disposal for Australian businesses since 2018, under four ISO certifications covering information security, environment, quality and safety. Every collection is documented, every data-bearing device is sanitised to the NIST 800-88 standard, and every job closes with a Certificate of Data Destruction and a Certificate of Recycling. Material is processed in line with AS/NZS 5377.