When a piece of equipment leaves your building for disposal, your responsibility for it does not leave with it. Where that equipment holds data, the responsibility ends when the data is provably destroyed.
Proving it means being able to say which item went where. That is a question about identification, which makes it a question about labels. The same applies to plant, instruments, machinery and anything else with a statutory or environmental trail attached to its disposal.
Most organisations specify asset labels for the start of an asset's life. Very few think about the end, and the end is where an unreadable label costs the most. A label that failed quietly in year three is a label that fails you at the exact moment you need to account for what you sent for destruction.
What the regulator actually asks for
The ICO's guidance on disposing of IT equipment is not complicated. Assign responsibility for asset disposal to a member of staff with a suitable level of authority. Complete a full inventory of all equipment marked for disposal. Be clear about what happens to devices once you no longer need them.
Read that middle one again, because it is the one that quietly depends on your labelling. A full inventory of equipment marked for disposal is a list of specific, identified items. Not forty devices. Forty devices, each one identified, each one traceable to a record and to a certificate at the other end.
You cannot inventory what you cannot identify. If the asset ID has worn off, been picked off, or gone in the bin with a cracked case, that device does not appear on your disposal inventory as itself. It appears as a gap, or worse, as a guess.
The ICO has also been explicit that if personal data is compromised during the asset disposal process, even after it has left your organisation, you may still be responsible. The fine lands on the data controller, not the disposal company. Handing the problem to a contractor does not hand over the liability.
The enforcement history is unusually clear
This is not a theoretical risk, and the cases are worth knowing because they follow a pattern.
Brighton and Sussex University Hospitals NHS Trust was fined £325,000 in 2012 after around 252 of roughly 1,000 hard drives sent for destruction surfaced for sale on eBay, still carrying patient records. NHS Surrey was fined £200,000 in 2013 after a single second-hand computer bought online was found to hold more than 3,000 patient records. A council in the East Midlands was fined £100,000 after a hard drive containing sensitive children's services data was found sold on eBay.
Under UK GDPR, the ceiling is now £17.5 million or 4 per cent of global annual turnover, whichever is higher.
Notice what those cases have in common. In each one, the organisation believed the equipment had been destroyed. The failure was not a decision to cut corners. It was a gap between what the paperwork said had happened and what actually happened, and nobody could see the gap until the drives turned up for sale.
Closing that gap is exactly what per-item identification is for.
A certificate you cannot match to a device proves very little
Compliant disposal usually comes with a documented chain of custody and a Certificate of Destruction. Both are good practice. Both are also only as strong as the identification underneath them.
A certificate listing a serial number is useful if you can tie that serial number to a specific machine on your register, on a specific date, issued to a specific person. That is what an asset ID does. Without it you have two lists that look similar and no way to reconcile them, which is precisely the position every organisation in those enforcement cases was in.
The reconciliation is the whole point. Forty devices left, forty certificates came back, and the IDs match. That is a closed loop. Forty devices left and thirty eight certificates came back is a problem you can see and fix. Forty unidentified devices left and some paperwork came back is not a loop at all.
The label has to survive to be useful at the end
This is the part that makes disposal a labelling problem rather than only a process problem.
Equipment reaching disposal has usually been in service for years, sometimes a decade. In that time it has been cleaned, moved, serviced, reassigned, knocked about and in many cases exposed to weather, chemicals or washdown. Whatever label went on it in year one has had all of that done to it.
If it was a cheap surface printed label, there is a reasonable chance the barcode stopped scanning somewhere around year three and nobody mentioned it, because nothing depended on it that week. The failure is silent. You only discover it at the moment you most need the label to work, which is the audit or the disposal.
This is the argument for under surface printed tags on long lived equipment, where the ink sits behind the substrate and cannot wear away. It is also the argument for destructible vinyl on equipment that gets handled by a lot of people, because a label that fragments on removal is a label that is either fully there or visibly gone. What you want to avoid is the middle state: a label that is still attached but no longer readable, because that is the one that fails without telling you.
Specify for the end of the asset's life, not the start of it. The label needs to work on the last day, not the first.
There is a second obligation, and it needs the same information
Data protection is not the only duty attached to retired equipment. IT and electrical equipment is classified as Waste Electrical and Electronic Equipment under the WEEE Regulations 2013, and e-waste has to be processed by an Approved Authorised Treatment Facility. Putting IT equipment into general waste can bring Environment Agency enforcement.
So the same device generates two paper trails, one for the data and one for the waste, and both of them want to know which items you sent and how many. An organisation that can produce a clean, identified disposal list satisfies both at once. An organisation that cannot is writing two sets of approximate paperwork and hoping neither gets examined.
What a label cannot do
Worth saying plainly, because we manufacture these things and it would be easy to overclaim.
A label does not destroy data. It does not make you compliant, it does not audit your contractor, and it will not stop a disposal company selling drives it was paid to shred. Those are process and procurement problems, and no material we make solves them.
What a label does is make your own records checkable. It turns "we sent about forty items for destruction last spring" into a list you can hold against a set of certificates. That is not the whole of compliance. It is the part of it that has to exist before any of the rest can be evidenced.
None of this is legal advice, and your obligations depend on your own circumstances. It is the labelling half of a problem that is mostly about process.
Where structured IDs pay off
Disposal is one of the moments a structured asset ID earns its cost.
A label reading MAN-IT-0142 tells you the site and the asset category before anyone opens a database. When a batch of decommissioned equipment is sitting on a pallet waiting for collection, that is the difference between sorting by reading labels and sorting by scanning everything into a system first. It also makes anomalies obvious. A Facilities tag in a pile of IT disposals is visibly wrong, and someone will notice.
Only encode information that is stable, though. Site codes and categories are permanent enough to build into the ID. User names are not, because IT equipment gets reassigned constantly, and a label that names a leaver is worse than a label that names nobody.
One more thing that matters at disposal specifically. Keep your number history. When a device is destroyed, its ID should be retired rather than reissued, and that only works if somebody has the record. We keep records of every range we have produced as standard, and we will flag it before printing if a reorder would duplicate your existing numbers, but we would still advise keeping your own record at your end. Two sets of records is what prevents a retired ID quietly reappearing on a new machine three years later.
The practical version
If you are specifying labels for equipment that will eventually need disposing of, which is all of it, three things follow.
Choose a material that will still be readable at the end of the asset's life rather than one that is adequate on day one. Give every item an ID that means something without a database. And check, now rather than at the point of disposal, whether the labels on your oldest equipment are still scanning, because that is where you will find out what your last specification was actually worth.
Common questions
Who is responsible if a disposal company loses our data?
The data controller, which is your organisation. The ICO has been explicit that if personal data is compromised during the asset disposal process, even after the equipment has left your premises, you may still be responsible. Using a third party does not transfer the liability, which is why your own records of what you sent matter.
Does the ICO require an inventory of equipment being disposed of?
Its guidance says organisations should complete a full inventory of all equipment marked for disposal, assign responsibility for asset disposal to a member of staff with a suitable level of authority, and be clear about what happens to devices once they are no longer needed.
What happens if the asset label is unreadable by the time we dispose of a device?
You lose the ability to reconcile that item against your register and against any Certificate of Destruction. In practice it becomes something you believe you disposed of rather than something you can evidence disposing of. This is why the material specification matters as much as the process.
Which label material lasts long enough for a full asset lifecycle?
Under surface printed tags are the most durable option for plastics based labels, because the ink sits behind a clear substrate and cannot wear away, be chemically attacked or be picked off. For equipment handled by many people, destructible vinyl has the advantage of being either fully present or visibly gone, rather than degrading quietly.
Do we need to keep asset IDs after an item is destroyed?
Yes. Retire the ID rather than reissuing it, and keep the record. A reissued number makes your historic disposal records ambiguous, which defeats the purpose of having them.
Does a label help with WEEE compliance as well as data protection?
Indirectly. IT and electrical equipment is classified as Waste Electrical and Electronic Equipment under the WEEE Regulations 2013 and must go to an Approved Authorised Treatment Facility. The same identified disposal list supports both the data trail and the waste trail, so good identification serves both obligations at once.
Specifying for the whole life of the asset
If you are not sure whether your current labels will still be readable in five years, the quickest answer is to look at your oldest ones. If they are worn, the specification was wrong, and the next batch is the chance to fix it.
Sample packs go out within 24 hours, standard or made up with your own wording, so you can compare materials on the equipment you actually own. Request a sample pack, call our sales team on 01278 433800, or email sales@customlabels.co.uk. Custom Labels has manufactured asset labels in Bridgwater for nearly thirty years and holds ISO 9001:2015 and ISO 14001:2015.


Recent Comments