waste.org.uk
Back to blog
IT Recycling

IT Recycling Certificates: What They Are and Why You Need Them

Published by Ewaste.org.ukDecember 6, 2025 9 min read

Key takeaways

  • An IT recycling certificate is your evidence of compliant, secure disposal.
  • The two key documents are the Waste Transfer Note and the Certificate of Destruction.
  • A Waste Transfer Note proves waste changed hands responsibly under your duty of care.
  • A Certificate of Destruction proves data-bearing media was sanitised under UK GDPR.
  • Keep records for at least two years to satisfy WEEE and data-protection obligations.
  • Serialised asset reports add device-level proof for regulated sectors.

An IT recycling certificate is the documentary proof that your business disposed of its technology legally, securely and responsibly. From the Waste Transfer Note to the Certificate of Destruction, this IT recycling documentation is what stands between you and a compliance problem if an auditor, the ICO or the Environment Agency ever asks how you handled your old equipment. The challenge for most UK businesses is that the paperwork is poorly understood: people know they should receive "a certificate" but cannot say which document proves what, who relies on it, or how long it needs to be kept. This guide breaks down each document in turn — what it covers, what it should contain, why it matters and the IT disposal compliance documents you should expect as standard from any reputable provider.

What is an IT recycling certificate?

An IT recycling certificate is not a single document but a term covering the paperwork you receive when technology is disposed of through a compliant provider. It is the evidence that disposal happened lawfully — that your waste went to an authorised party, that data was destroyed, and that materials were handled to a responsible standard. In practice, two documents do most of the work: the Waste Transfer Note and the Certificate of Destruction, supported where needed by a serialised asset report.

For a UK business, this documentation is the difference between being able to demonstrate compliance and merely asserting it. In an audit or an investigation, a verbal assurance counts for nothing; the certificate is what proves your case. Regulators, insurers and clients all work on the same principle — if it is not written down and evidenced, it did not happen.

Think of the paperwork as the visible output of an invisible process. Good documentation is a strong signal that the underlying collection, data destruction and recycling were equally disciplined — which is why the quality of a provider's certificates tells you a lot about the quality of its service. A provider that issues clear, consistent proof of IT disposal as standard is one that has nothing to hide downstream.

Who actually relies on this paperwork

It is easy to assume IT recycling documentation is only for the person who arranged the collection, but in reality several people across a UK business depend on it. Each reads the certificates for a different reason, which is why the detail they contain matters as much as their existence.

  • Your data protection officer or compliance lead, evidencing UK GDPR-compliant data destruction.
  • Finance and asset management, reconciling what left the building against the fixed-asset register.
  • Auditors checking ISO 14001 environmental or ISO 27001 information-security controls.
  • Procurement and sales teams answering client due-diligence questionnaires.
  • Directors, who carry ultimate duty-of-care responsibility for how waste is handled.

The Waste Transfer Note explained

What it is

The Waste Transfer Note (WTN) is a legally required record that documents the transfer of waste from your business to a registered waste carrier. It evidences that your waste electrical equipment changed hands responsibly, satisfying your duty of care under the Environmental Protection Act 1990 and the WEEE Regulations 2013.

The duty of care is a continuing obligation, not a one-off. It requires you to take all reasonable steps to ensure your waste is handled correctly all the way to its final destination, and the WTN is the document that records you discharged that responsibility at the point of transfer. Both parties are required to keep a copy.

What it contains

A WTN records the parties involved, the type and quantity of waste, the date and place of transfer and the carrier's registration details. Waste is also classified using the appropriate European Waste Catalogue (EWC) code, which describes exactly what is being moved. You should receive one for every collection, without exception.

  • A description of the waste and its EWC classification code.
  • The quantity and how it is contained or packaged.
  • The names and addresses of the transferor and the carrier.
  • The carrier's waste-carrier registration details.
  • The date, time and place the transfer took place.

Why the carrier's registration matters

A Waste Transfer Note is only as good as the carrier named on it. If that carrier is not properly registered with the Environment Agency, the note does not protect you — it simply records that you handed waste to an unauthorised party. Always confirm your provider is a registered upper-tier waste carrier before any collection, because the legal liability for choosing the wrong one rests with you, the waste producer.

The Certificate of Destruction explained

What it is

The Certificate of Destruction is your proof that data-bearing media was sanitised. It is the document that demonstrates compliance with UK GDPR by showing that personal and company data held on retired devices was irreversibly destroyed. Under UK GDPR and the Data Protection Act 2018 you remain the data controller until that data is provably gone, so this certificate is the data destruction certificate the ICO would expect to see in an enquiry.

This is also where deleting files or running a factory reset falls short. Those actions leave data recoverable, so a Certificate of Destruction is only meaningful when it is backed by certified wiping or physical destruction — not a quick format. The document records the method so an auditor can judge whether it was appropriate to the sensitivity of the data involved.

What it contains

A robust Certificate of Destruction records what was destroyed, when, how (certified wiping or physical destruction), the standard followed and by whom. Where serialised, it can tie destruction to individual devices for categorical, device-level proof.

  • A description of the media or devices destroyed and their quantity.
  • The method used — certified data wiping or physical destruction.
  • The recognised standard followed, such as NCSC guidance or DIN 66399.
  • The date of destruction and the operator or facility responsible.
  • Serial numbers, where serialised reporting has been requested.

Wiping versus physical destruction

The right method depends on the device and the data it held. Functional drives destined for reuse are typically wiped to a certified standard that overwrites every sector, while failed drives, solid-state media and the most sensitive data are physically destroyed by shredding or degaussing for absolute certainty. A good Certificate of Destruction makes clear which approach was applied, so there is no ambiguity about how thoroughly a given device was treated.

The serialised asset report

Beyond the two core certificates, many organisations ask for a serialised asset report. This lists every device collected by serial number alongside its outcome — wiped, destroyed, reused or recycled — so you can reconcile exactly what left your building against what was processed. It closes the loop between your fixed-asset register and the disposal itself, which is precisely the kind of proof of IT disposal an auditor wants to see.

For regulated sectors and ESG reporting, this level of detail is invaluable. It turns a general assurance into device-level evidence that auditors and data protection officers can rely on without further questions. Financial services, healthcare, legal and public-sector organisations in particular tend to treat serialised reporting as a baseline requirement rather than an optional extra.

A serialised report also makes internal reconciliation far simpler. If twenty laptops were booked for collection but only nineteen appear on the report, you find out immediately rather than during an audit, and you can resolve the discrepancy while the trail is still fresh. That early visibility is one of the strongest arguments for requesting serialised IT recycling documentation up front.

How the documentation is produced, step by step

Understanding when each document is generated helps you check you have received everything you should. The IT disposal compliance documents are not all issued at once — they map to distinct stages of the collection and treatment process.

  • At booking, the provider confirms the scope and what documentation you will receive.
  • At collection, the Waste Transfer Note is raised as the equipment is handed to the registered carrier.
  • On arrival at the processing facility, devices are logged against your asset list.
  • Data-bearing media is then certified-wiped or physically destroyed and recorded.
  • The Certificate of Destruction is issued once sanitisation is complete.
  • A serialised asset report is compiled and supplied where it has been requested.

Common mistakes UK businesses make with disposal paperwork

Even organisations that take compliance seriously trip up on the documentation. The errors are rarely deliberate — they usually come from treating the paperwork as a formality rather than a legal record. Recognising the common pitfalls is the quickest way to avoid them.

Accepting a vague or generic certificate

A certificate that does not say what was destroyed, when, how and to what standard is of limited evidential value. Generic, undated or unsigned documents may look reassuring but tell a regulator very little. Always check that your data destruction certificate names the method and the standard followed, not just the fact that "destruction took place".

Not checking the waste carrier is registered

Handing equipment to an unregistered carrier breaches your duty of care even if the equipment is ultimately recycled correctly. The Waste Transfer Note should carry valid registration details, and you can verify a carrier's registration through the Environment Agency's public register before you book.

Losing or never filing the documents

Certificates that sit in an inbox or a desk drawer cannot be produced on demand. Filing them centrally against your asset register, as soon as they arrive, is what makes them useful when an audit or ICO enquiry lands. The absence of a document is treated as the absence of compliance, regardless of how careful the actual disposal was.

Why these certificates matter

  • They prove compliance with the WEEE Regulations and your duty of care.
  • They evidence GDPR-compliant data destruction to the ICO.
  • They support ISO 14001 and ISO 27001 audits.
  • They underpin ESG and sustainability reporting.
  • They protect you from liability if equipment is later found to have been mishandled downstream.

The risk of disposing without certificates

Disposing of IT equipment without proper documentation leaves you exposed on every front. If data later surfaces from a device you cannot prove you sanitised, that is a reportable breach with no defence. If your waste is found to have been fly-tipped or exported irresponsibly, you can be held liable because you cannot show you used an authorised carrier. The certificate is, in effect, your insurance policy.

Crucially, the burden of proof sits with you. Regulators expect you to evidence compliant disposal, not merely claim it, so the absence of certificates is treated as the absence of compliance — even if the disposal itself was handled correctly.

How long to keep your documentation

Retain your IT recycling certificates for at least two years. Many organisations keep them longer to align with their wider records-retention and audit schedules. Store them somewhere central and accessible — ideally with your asset register — so they can be produced quickly if requested rather than hunted down after the fact.

Putting your certificates to work

Documentation is only useful if you can find it. Keep certificates with the relevant asset records, and cross-reference them so that any device can be traced from purchase through to certified destruction.

  • Store certificates centrally alongside your asset register.
  • Cross-reference each certificate to the collection and devices it covers.
  • Make them accessible to whoever handles audits, the DPO and ESG reporting.
  • Review retention against your wider records-management policy.

Common scenarios where certificates count

It is easy to treat disposal paperwork as a formality until the moment it is needed. In practice, there are several everyday situations where having the right certificates on file makes all the difference.

  • An ICO enquiry asking how personal data on retired devices was destroyed.
  • An Environment Agency check on how your electrical waste was handled.
  • An ISO 14001 or ISO 27001 audit requiring evidence of your processes.
  • ESG or sustainability reporting that needs proof of zero-to-landfill disposal.
  • A client or procurement due-diligence questionnaire about your data handling.

Getting the right paperwork as standard

With a reputable provider, this documentation is included as standard, not charged as an extra. Every collection through a compliant IT recycling service should come with a Waste Transfer Note, a Certificate of Destruction for data-bearing devices, and a serialised asset report where your sector requires it. If a provider is reluctant to supply any of these, treat it as a serious warning sign and look elsewhere.

Ewaste.org.uk issues a Waste Transfer Note and a Certificate of Destruction as standard for every collection, with serialised asset reporting available where it is needed. As a registered upper-tier waste carrier operating nationwide to a zero-to-landfill standard, it builds the paperwork into the service rather than treating it as an add-on. To arrange a collection, call 020 4524 7964.

Need help with this? Learn more about our IT recycling service or arrange a free, no-obligation collection today.

Ready to book a free collection?

Free, compliant, nationwide WEEE collection for UK businesses — with full documentation as standard.

Frequently asked questions

What is an IT recycling certificate?

It is the documentation proving your technology was disposed of compliantly — principally a Waste Transfer Note and a Certificate of Destruction, plus a serialised asset report where required.

What's the difference between a Waste Transfer Note and a Certificate of Destruction?

A Waste Transfer Note proves waste changed hands responsibly under your duty of care. A Certificate of Destruction proves data-bearing media was sanitised, evidencing GDPR compliance.

Do I get a certificate with free IT recycling?

Yes. With a reputable provider, the Waste Transfer Note and Certificate of Destruction are included as standard for qualifying collections, not charged as extras. Ewaste.org.uk issues both as standard for every collection, with serialised asset reporting available where it is needed.

Is a Certificate of Destruction a legal requirement?

The certificate itself is not named in legislation, but the obligation it evidences is. UK GDPR requires you to securely destroy personal data and be able to demonstrate it, so the Certificate of Destruction is the practical proof the ICO would expect to see if asked how data on retired devices was handled.

How long should I keep IT recycling certificates?

Keep them for at least two years to satisfy WEEE and data-protection obligations. Many organisations retain them longer to match their wider records-retention schedules.

What happens if I dispose of IT without a certificate?

You lose your defence. If data resurfaces or waste is mishandled downstream, you cannot prove compliant disposal, leaving you exposed to ICO and Environment Agency action.

What is a serialised asset report and do I need one?

It lists every device by serial number alongside its outcome, giving device-level proof. It is especially valuable for regulated sectors and ESG reporting, though not every business requires one.

Who in my organisation should hold the certificates?

Store them centrally — ideally with your asset register — and make them accessible to whoever handles audits, data protection and ESG reporting, so they can be produced quickly if requested.

Related articles