Under the new GDPR regulations that are being enshrined into UK law in May 2018 all organisations whether private or public sector have to adhere to the following:-
1) All organisations have to have a contract/agreement with their Asset Disposal Company
2) All IT Assets need to be tracked and when disposing of redundant equipment a full audit report, serialised data erasure certificates should be provided to you so that you can update your CMDB system
3) All organisations have to have an Asset Disposal Policy
4) All organisations have to designate their asset disposal company as their data processor
5) All physical data such as hard drives should be wiped or shredded using CESG Approved Methods. Media Tape should be shredded using CESG Approved Methods
6) Organisation should ensure that their asset disposal partner are accredited and undergo regular audits either by standards such as ADISA (Asset Disposal and Information Security Alliance) and/or audited by the organisations themselves to ensure that the processes that they follow meet all current/impending legislation.