Finding an ITAD provider is easy. Finding one that you can entrust with your hard drives, customer data, and reputation is more difficult. On paper, almost everyone promises the same things: secure, certified, sustainable. This checklist helps IT management, procurement, and data protection see the differences – with twelve questions that you should ask each provider.
The most important in a nutshell
- ITAD (IT Asset Disposition) means: safely collecting decommissioned IT equipment, deleting data, repurposing the devices, and documenting everything.
- The biggest differences between providers lie in the transport chain, extinguishing technology, the quality of the certification, and the use of subcontractors.
- Request certificates with a validity date and have a sample proof of payment shown to you.
- A good provider not only provides security, but also revenue and data for your sustainability reporting.
What an ITAD provider should do
IT Asset Disposition describes the entire process of disposing of obsolete hardware: from collection to data deletion to re-marketing or proper disposal. A detailed introduction to the term can be found in our post. IT asset disposition and GDPR-compliant data deletion. Here the question arises: How do you choose the right partner?
A complete ITAD process typically includes these steps:
- Supply and purchase
- Collection and transportation
- Inspection in the incoming goods
- Data deletion
- Audits and reports
- Repair and Refurbishment
- Remarketing
- Proper disposal
The more of these steps an operator carries out themselves, the fewer points of handover there are – and the fewer places where something can go wrong.
The 12 test questions for each ITAD provider
Security and privacy
- How do the devices get to you from us? Own vehicles or changing freight forwarders? Direct shipment or intermediate storage? Tracked and located?
- With which software is it deleted? Is it independently audited? Are hidden areas such as HPA and DCO covered? How are SSDs treated?
- What does the proof of payment look like? Is there a certificate per data carrier with serial number, procedure and result? Have a sample shown to you.
- What happens with defective data carriers? Will they be destroyed in their own premises in accordance with DIN 66399? What level of safety?
- How is the area secured? Access control, video surveillance, security zones, and an obligation on employees to maintain data confidentiality.
Evidence and organization
- What certificates are available – and how long are they valid? Relevant standards include ISO/IEC 27001, ISO 9001, ISO 14001, DIN 66399, and the status as a waste disposal company.
- Are subcontractors employed? For which steps? Where are these companies located? This should be included in the contract for order processing.
- How often is externally reviewed? How many audits are carried out by independent bodies per year?
- Can we watch the status live? Is there a customer portal with device status and documents?
Economic efficiency and sustainability
- How is the purchase price determined? Based on current market data? How quickly will an offer be available?
- What happens to the devices after deletion? Are they processed and marketed themselves or passed on to intermediaries?
- What data do we receive for our sustainability reporting? Are there any disposal certificates, recycling certificates, or an environmental balance sheet?
Key point: Don't be given promises; demand proof. A sample destruction certificate says more than any brochure.
Warning signs when choosing
- Collecting receipts instead of individual proofs: „Deleting 150 devices“ without serial numbers does not help in the audit.
- Unclear transport chain: If no one can say where the devices are between collection and disposal.
- Expired or not submitted certificates: A logo on the website does not replace a valid certificate.
- No contract for order processing: The person who processes your data usually needs it.
- Prices without inventory: Serious offers are based on your device list.
- No statement regarding the whereabouts of the devices: Where do the devices that are not being marketed go?
Rating matrix for your provider comparison
Transfer this table into your tender or comparison and prioritize the criteria according to your priorities.
| Criterion | What to look out for | Weighting (example) |
|---|---|---|
| Transport safety | Own logistics, direct travel, plugs, GPS, insurance | high |
| Disposal procedure | Certified software, HPA/DCO, SSD procedures | high |
| Proof quality | Certificate per serial number, digitally signed | high |
| Destruction | In-house, DIN 66399, safety level | medium to high |
| Certifications | ISO/IEC 27001, ISO 9001, ISO 14001, Waste management company | high |
| Transparency | Customer portal, audit reports, external audits | medium |
| Revenue | Market-oriented, data-based prices | medium |
| Speed | Supply and processing in clear deadlines | medium |
| Sustainability | Reuse before recycling, environmental impact | medium |
Tip: Ask each provider to submit the answers in writing and with supporting documentation. This way, you can compare the offers fairly and already have the basis for the later contract at hand.
This is how Second IT answers the twelve questions
Transparency starts with ourselves. Here are the short answers:
- Transport: Customized security logistics, direct trips without intermediate storage, GPS monitoring, tamper-proof locking, insured transport – throughout Europe. More information Logistics.
- Deletion: Blancco ITAD Gold Partner, including deletion of HPA/DCO and remap sectors, digitally signed certificate per device. More information available here. Data deletion.
- Destruction: In your own home according to DIN 66399, safety level H-5, video-monitored, with destruction certificate.
- Location: Biometric access control, video surveillance, security zones, processing according to VS-NfD guidelines are possible.
- Certificates: ISO 9001, ISO 14001, ISO 45001, ISO/IEC 27001, DIN 66399, waste disposal company according to § 56 KrWG. All certificates available under Certificates.
- External audit: At least three external audits per year.
- Transparency: Customized customer portal with live status and audit reports.
- Price and speed: Database-based price determination, offer in an average of 48 hours.
- Recycling: In-house refurbishment in Schwäbisch Hall, marketing through own online shop and store.
- Sustainability: Recycling and disposal certificates for CSR and ESG reporting, as well as an annual individual environmental balance sheet.
Since our founding in 2011, we have processed around 1.8 million devices and safely deleted around 500,000 TB of data.
How to start the provider comparison
- Describe the need: Device types, quantities, locations, and the need for data protection.
- Set requirements: Minimum standards for transport, deletion, destruction and verification.
- Request from providers: With a list of devices and the twelve questions.
- Check the evidence: Certificates, sample proof of delivery, contract for order processing.
- Conducting a pilot: Test with a smaller batch of processes and proofs.
- Concluding a framework agreement: This will ensure that future rollouts can be carried out without a new tender.
Three departments, three perspectives
When choosing an ITAD provider, there are often three different parties involved. Each has different priorities – and they are all right.
IT management
The IT department wants a smooth process: fixed contact points, predictable pick-up times, minimal effort for the in-house team, and a portal where the status of each device is visible. It is also important that the provider can handle all types of devices – from smartphones to storage systems.
Shopping
The purchasing department prioritizes cost-effectiveness and contract security: transparent pricing, clear specifications of the services provided, deadlines, liability, and insurance. A framework agreement saves time during recurring rollouts.
Data protection and information security
Data protection officers and information security officers review the contract for order processing, the technical and organizational measures, the use of subcontractors, and the quality of the documentation. For them, every single serial number counts in the end.
A good ITAD provider answers the questions in all three areas – preferably in writing and with supporting documentation.
Frequently asked questions about choosing an ITAD provider
What is an ITAD provider?
An ITAD provider takes on the secure disposal of IT hardware. This includes collection, data deletion, destruction of defective data media, processing, resale, and disposal. A good provider documents every step and provides proof for each device. Many also buy usable devices for resale.
What certificates should an ITAD service provider have?
Important factors are primarily ISO/IEC 27001 for information security, a certified destruction procedure according to DIN 66399, and the status as a waste disposal company. ISO 9001 and ISO 14001 demonstrate audited quality and environmental management. Please present the certificates with their expiration date. Additionally, ask about the used deletion software and its testing.
Do I need to apply for ITAD?
That depends on your organization. Public contracting authorities are bound by procurement law; companies often have their own purchasing guidelines. Regardless of this, clear minimum requirements and an evaluation matrix help. For regular needs, a framework agreement makes sense.
How do I recognize a good proof of purchase?
A good proof of recovery lists each data medium with its serial number, the method used, the date, and the result of the examination. It is digitally signed so that it cannot be altered. A collection proof without serial numbers usually is not sufficient for an audit. Please ask each provider in advance for a sample.
What does an ITAD service provider cost?
This depends on the type of device, quantity, condition, and desired services. For devices with a market value, the purchase price can cover or exceed the costs for logistics and disposal. For devices without a market value, costs for disposal, destruction, and recycling are more likely to be incurred. A reliable quote always depends on your device list.
Ask us the twelve questions – we will answer them in writing.
Send us your list of devices and your requirements. You will receive a quote within an average of 48 hours – and answers to all twelve questions.