Home
Services
Third-Party Maintenance Pre-Owned Hardware ITAD VMware Services
Resources
EOSL Library Blog FAQ
Request a Quote →
R2v3-Aligned Process

IT Asset Disposition

We don't just haul away old hardware. We take on your compliance and data-security risk, execute a documented chain-of-custody process, and hand it back to you solved — with the paperwork that protects you if anyone ever asks what happened to that equipment.

NIST
SP 800-88 Compliant
Data Sanitization Standard
100%
Asset-Level Serial
Number Tracking
0
Landfill Disposal —
Certified Downstream Only
CoDD
Certificate of Data Destruction
Per Device, Every Time

We Sell Trust, Documentation & Risk Reduction

IT Asset Disposition is the managed process of retiring your organization's end-of-life IT equipment — securely, responsibly, and with proof. The equipment is just what's inside the box. What you're actually buying is a documented, auditable process that absorbs your compliance liability.

When your IT assets leave your building under Global TPM's custody, that risk moves off your books. You receive serialized documentation — not just a pickup receipt — that protects you if you're ever audited, breached, or asked to produce records by legal or compliance.

The one-sentence version: Hardware sales = we sell equipment. ITAD = we sell trust, documentation, and risk reduction. The equipment is just what's inside the box.

Request an ITAD Assessment →
📋

Traditional Hardware Sale

Transaction ends when payment clears. Risk transfers to buyer. Documentation = invoice.

vs.
🛡️

Global TPM ITAD Service

Transaction ends when Certificates of Data Destruction and Recycling are delivered. We're on the hook for every step — including what our vetted downstream partners do.

Repeat Business Driver

Hardware customers come back when they need another purchase. ITAD clients come back for every future refresh cycle, relocation, and closure — because they trust us with their data.

Six Steps. Complete Chain of Custody.

Every asset is tracked by serial number from your site to final disposition. Nothing falls through the cracks — and you get paperwork to prove it.

01

Inventory & Asset Tagging

Every device is logged by serial number or asset tag before it leaves your site. Nothing moves without being recorded. This is the foundation of your chain-of-custody documentation and the reason asset-level reporting is possible at the end.

02

Secure Transport & Chain-of-Custody Controls

We maintain documented control from your loading dock to our facility (or perform on-site processing where required). Every handoff is logged. For high-sensitivity environments, we offer witnessed on-site data destruction before assets are moved.

03

Data Sanitization or Physical Destruction

All data-bearing devices are wiped to NIST SP 800-88 (Clear/Purge/Destroy) — the federal standard most enterprise, healthcare, and financial compliance teams require. Devices that can't be reliably wiped are physically shredded. A serialized Certificate of Data Destruction is issued per device, every time — not a batch report.

04

Testing, Grading & Value Recovery

Functioning equipment is tested, graded, and remarketed on the secondary market — and the recovered value is credited back to you. Value recovery is a bonus, not the headline. We don't compromise your data security or documentation for a better resale margin.

05

Responsible Downstream Recycling

Non-resalable materials go to vetted, R2v3-equivalent downstream partners — never landfill, never uncontrolled export. Every downstream vendor we use is audited and documented. We can show you where your materials went, not just tell you.

06

Asset-Level Reporting & Certificates

You receive a complete documentation package: chain-of-custody log, per-device Certificates of Data Destruction, Certificates of Recycling, and summary reporting your IT, legal, and sustainability teams can use for compliance reporting, audits, and ESG disclosures.

Every Data-Bearing Device.
Not Just the Obvious Ones.

Most organizations forget that "data-bearing device" means more than laptops and servers. If it can store data, we can disposition it properly.

🖥️ Servers & Blades
💾 Storage Arrays & SANs
💻 Laptops & Desktops
📱 Mobile Devices & Tablets
🌐 Networking Switches & Routers
🔥 Firewalls & Security Appliances
🖨️ Copiers & MFPs
💿 Hard Drives & SSDs (standalone)
📠 VoIP Phones & Unified Comms
🖥️ Thin Clients & VDI Endpoints
📡 Wireless Access Points
⚡ UPS & Power Equipment
⚠️
Don't overlook copiers and MFPs.

Modern multifunction printers store copies of every document they've ever scanned, faxed, or printed — on an internal hard drive. This is one of the most commonly forgotten data-bearing devices in any decommission project and a frequent source of compliance exposure.

What R2v3 Actually Means
for Our Clients

R2v3 ("Responsible Recycling," Version 3) is the leading certification standard for ITAD providers, maintained by SERI — an ANSI-accredited nonprofit. It's not a marketing badge. It's an independently audited operating standard covering 10 core requirements.

#
Requirement
In Plain English
1
Environmental, Health & Safety
Documented EHS system covering hazardous materials, worker safety, and emergency preparedness.
2
Legal & Regulatory Compliance
Every applicable law identified — federal, state, international — with demonstrated compliance at each level.
3
Sampling Requirements
Statistically valid sampling methodology used when auditing downstream vendors or export shipments.
4
Focus Materials Controls
Extra tracking for materials of environmental/health concern: batteries, CRT glass, mercury lamps, circuit boards.
5
Data Security ⭐
Documented, auditable NIST SP 800-88 data sanitization and destruction for every data-bearing device.
6
Facility Security
Physical access control, video surveillance, and secure storage for all data-bearing assets on-site.
7
Insurance & Financial Assurance
Adequate insurance to cover environmental and data-related liabilities — not just operational insurance.
8
Closure Financial Assurance
Financial planning ensuring materials aren't abandoned if a facility ever closes.
9
Throughput Tracking
Every asset and material stream tracked in and out of the facility by weight, unit count, and destination.
10
Downstream Chain ⭐
Every downstream vendor — all the way to final disposition — must be vetted and audited. No "it left our dock" excuses.
🏢

Why It Matters to Your Organization

Enterprise, healthcare, financial, government, and education organizations increasingly require R2v3 (or equivalent) as a condition of doing business with any ITAD vendor. It provides auditable proof for HIPAA, GDPR, FERPA, SOX, and ESG reporting obligations — proof that a "free recycler" or broker simply cannot provide.

📜

What a "Free Recycler" Can't Give You

A broker paying you a flat rate for old equipment cannot tell you what happened to your data or your assets after pickup. If a drive with customer data surfaces later, that liability comes back to you — not them. Our documented chain-of-custody process is insurance a check from a broker doesn't buy.

Which Regulations Require
Documented ITAD?

If your organization is subject to any of these frameworks, undocumented hardware disposal is a compliance gap — and a potential liability.

🏥

HIPAA

Healthcare organizations must demonstrate that PHI is destroyed on retired media. A Certificate of Data Destruction per device is the standard documentation required in a breach or audit.

🏦

SOX / GLBA / PCI-DSS

Financial institutions and public companies must maintain controls over sensitive financial data through end-of-life. Documented destruction is increasingly required by auditors and examiners.

🌍

GDPR / State Privacy Laws

GDPR requires demonstrable destruction of personal data on retired assets. US state laws (CCPA, VCDPA, etc.) are rapidly adopting similar requirements. The proof is in the CoDD.

🎓

FERPA

K-12 and higher education institutions handling student records must demonstrate secure disposal of equipment that stored that data — FERPA obligations don't end when the device is retired.

🏛️

Government & DoD

Public sector organizations often require NIST SP 800-88 compliance for media sanitization specifically, with per-device documentation as a standard audit deliverable.

🌱

ESG & Sustainability Reporting

Board-level ESG commitments and sustainability reports increasingly require documented, zero-landfill e-waste disposal. Our Certificates of Recycling provide the proof your sustainability team needs.

The Documentation Package

Our transaction isn't done when we load the truck. It's done when you have paperwork that proves the job was completed correctly — at an asset level, not a bulk count.

🔒

Certificate of Data Destruction

Serialized per device. Includes asset ID, destruction method (NIST SP 800-88 Clear/Purge/Destroy or physical shred), technician verification, and date. This is your proof in any audit or breach investigation.

♻️

Certificate of Recycling

Documents that all materials reached final, responsible disposition through our vetted downstream chain. Zero landfill. No uncontrolled export. Your ESG team can use this for sustainability reporting.

📊

Chain-of-Custody Report

An unbroken, asset-level record of who had physical possession of each device from pickup through final disposition. Includes all handoffs, processing steps, and final outcomes by serial number.

We Hear These a Lot

Honest answers to the most common objections and questions about ITAD — because you should go in with clear expectations.

💬 "We just give our old stuff to a recycler for free — or a broker offered us money for it."
A broker paying you a flat rate for old equipment cannot tell you what happened to your data or your assets after pickup. If a drive with customer data surfaces later, that liability comes back to you — not them. Our R2v3-aligned process gives you serialized proof, per device, that data was destroyed and materials were responsibly handled. That's insurance a check from a broker doesn't buy you.
💬 "We don't have anything sensitive on these machines."
Most breaches we hear about started with that assumption. Even machines that were "wiped" can carry residual data without certified sanitization to a documented standard. And data-bearing devices aren't just PCs and servers — copiers, VoIP phones, and networking gear all store data most people forget about. We'd rather document it and be certain than have your organization find out the hard way.
💬 "Can't our IT team just wipe these themselves?"
They can try — but unless it's performed to a documented standard like NIST SP 800-88 with serialized verification and a defensible audit trail, there's no way to prove it in an audit or breach investigation. A screenshot from the IT admin doesn't hold up the same way a per-device Certificate of Data Destruction does. We give you the paper trail, not just the wipe.
💬 "Isn't recycling just free? Why would we pay for this?"
Basic scrap recycling is free because the recycler profits from the metals. What you're paying Global TPM for isn't the recycling — it's the documented, audited chain of custody, the NIST-compliant data destruction, and the per-device certificates that protect you if you're ever audited, breached, or sued. The recycling is the byproduct. The documentation is the product.
💬 "We've been buying hardware from you — is this just a new product we're ordering?"
It's actually the opposite relationship. When you buy hardware from us, you're taking on an asset. With ITAD, we're taking custody of your risk and handing you back documentation instead of a box. It's a service engagement — with an ongoing contract, SLA, and a dedicated point of contact — not a purchase order.

ITAD for Every Industry
That Handles Sensitive Data

If your organization is subject to data privacy obligations — and nearly every one is — proper ITAD isn't optional.

🏥

Healthcare

HIPAA requires documented proof of PHI destruction on retired media. Don't leave it to chance.

🏦

Financial Services

SOX, GLBA, and PCI-DSS all require documented controls over financial data through end-of-life.

🏛️

Government & Public Sector

NIST SP 800-88 compliance and per-device documentation is standard in federal and state audits.

🎓

Education

FERPA obligations extend to retired hardware. Student records don't expire when the laptop does.

🏭

Manufacturing & Enterprise

Large-scale refresh cycles, multi-site decommissions, and ESG sustainability reporting requirements.

🔬

Technology & SaaS

Data centers, rapid hardware cycles, and customer data obligations make certified ITAD non-negotiable.

Retire Your Hardware the Right Way

Get a free ITAD assessment. We'll scope your project, answer your compliance questions, and tell you exactly what documentation you'll receive — before you commit to anything.