Secure IT Disposal and Chain of Custody
Professional secure it disposal — chain of custody across 30+ UK cities. Available 24/7 with GPS tracking.
Birmingham office: +44 121 720 3841 (06:00–17:00) · Evening: +44 7737 778964 (08:00–22:00) · Quotes within 15 min
Secure IT Disposal — Chain of Custody pricing — from £50 (ex VAT)
One fixed price per dedicated job, quoted in full upfront before you book — fuel and goods-in-transit insurance included, no hidden fees. Final price depends on distance, vehicle, urgency and time of day.
| Distance | Miles from collection to delivery |
|---|---|
| Vehicle | Small van for documents/parcels → Luton or 7.5t for pallets & oversized |
| Urgency | Immediate dedicated dispatch vs a planned collection window |
| Time | Out-of-hours, weekends and bank holidays carry a premium |
| Waiting time | Standby at a cargo handler, dock or site |
| Route costs | Dartford Crossing, ULEZ / Clean Air Zone charges |
| Special handling | ADR dangerous goods, temperature control, two-person lift |
| Legs & stops | Return journey or multi-drop routing |
You pay for a dedicated vehicle, not a shared-parcel network rate — so there is no consolidation delay. Call +44 7963 400173 with your collection and delivery postcodes for an instant, all-in quote.
Chain of custody is the difference between believing your old drives were destroyed and being able to show it. Most IT disposal failures are not dramatic — they are a box of laptops that went into a shared van, arrived as a count rather than a list, and came back as a certificate saying forty-two drives were destroyed with no way to tell whether yours were among them. This service exists to close that gap on the transport link, where custody most often becomes untraceable, and to make sure what arrives at the processor can be matched to what left your building.
What is chain of custody in IT disposal?
Chain of custody is the documented record of who held specific assets at each point between decommissioning and destruction. It is a sequence of identified handovers, not a general assurance that equipment was handled carefully.
The test of a chain is whether any single asset can be traced through it. A record showing that a quantity of equipment moved between two organisations is not a chain of custody; a record showing that a listed set of serial numbers was signed out by a named party at a stated time is. This matters because the question asked after an incident is always specific — whether one particular drive was accounted for — and a chain built on quantities cannot answer it, however complete it looks.
Where does chain of custody usually break?
At the transport link, and almost always for the same three reasons. Each is avoidable at the point of booking and difficult to remedy afterwards.
| Failure | What it causes |
|---|---|
| Shared-load transport | Assets consolidated with other consignments; custody becomes a count, not a list |
| No asset list before collection | Nothing to reconcile later evidence against |
| Handover recorded as a quantity | Individual items untraceable from that point on |
| Intermediate storage between legs | An unrecorded custody gap nobody owns |
The common thread is that all four are decisions made before the vehicle arrives. None of them can be corrected by better paperwork at the far end, because the information they destroy was never captured.
How are data-bearing assets tracked from your site?
Against the list you capture before collection, item by item, signed at handover. The list is the baseline; everything downstream is checked against it.
That list has to come from you, because it is the only record created while the equipment is still in your control. Make, model, serial number and a flag for whether the item holds data is sufficient — elaborate asset management is not the point. At collection the items are checked against the list and the handover is signed by both sides, which fixes the moment custody transferred and to whom. From there, transport is dedicated rather than consolidated, so the assets are not merged with other consignments in transit. Our guide to IT disposal documentation covers how the list reconciles against later evidence.
What does dedicated transport actually add?
It keeps the load identifiable. On a dedicated movement the vehicle carries your consignment and goes to its destination, whereas a shared-parcel network is built on consolidation, sortation and multiple handling points by design.
Every one of those handling points is a custody event that is not individually recorded for your assets, which is precisely what makes a parcel network unsuitable for this work regardless of how reliable it is at delivering parcels. Dedicated transport also removes intermediate storage between legs — the unrecorded overnight in a depot that nobody owns. Vehicles are GPS-tracked and goods are covered in transit; cover levels are set out under goods-in-transit insurance. Where the load also contains items classified as dangerous for carriage, it runs under our hazardous goods procedures with ADR-licensed drivers.
What is the difference between secure transport and certified destruction?
They are separate links performed by separate parties. We move the assets under custody; erasure or physical destruction is carried out at the processing facility, which issues the certificate in its own name.
This division is deliberate rather than a limitation. A certificate is an assurance about work actually done, so it should come from whoever did it — a carrier certifying destruction it did not perform is precisely the kind of document that looks authoritative and proves nothing. What the transport link contributes is the guarantee that the items named on the destruction certificate are the items that left your building. Our guide to the certificate of data destruction sets out what a usable certificate contains and which destruction methods suit which media.
Does chain of custody satisfy UK GDPR?
It supports the obligation without discharging it. Under UK GDPR the data controller remains accountable for personal data through to disposal, and that accountability cannot be contracted away to a carrier or a processor.
What a documented chain provides is demonstrability: if asked how you ensured personal data on decommissioned equipment was rendered irrecoverable, the answer is an asset list, a signed handover, a transport record and an itemised destruction certificate that reconciles against the list. The supervisory authority here is the Information Commissioner's Office, which is asking a different question from the Environment Agency — the environmental documents for the same collection can be entirely correct while the data question remains unanswered. Both obligations run in parallel and need separate evidence.
Which organisations need a documented chain of custody?
Any organisation whose disposals are likely to be examined rather than merely recorded. In practice that means regulated sectors and anyone holding special category data.
Healthcare, financial services, legal practices and public-sector bodies operate under evidence expectations that make reconciliation genuinely useful rather than administrative overhead. Education is a distinct case — refresh cycles concentrate into short windows around term boundaries, so a large volume of data-bearing assets moves at once under time pressure, which is exactly the condition in which custody records get skipped. Organisations running a rolling replacement cycle across multiple sites face the opposite risk: many small movements, each individually unremarkable, with no single record tying them together.
Are seals and locked cages the same thing as chain of custody?
No. Physical controls reduce the chance of interference; they do not by themselves create a traceable record. A seal proves a container was closed, not what was inside it.
| Control | What it actually evidences |
|---|---|
| Tamper-evident seal | That a container was not opened between two points — says nothing about contents |
| GPS tracking | Where the vehicle went, not which assets were on it |
| Dedicated transport | That the load was not consolidated with other consignments |
| Itemised handover signed by both parties | Which specific assets transferred, to whom, and when |
Only the last of these answers the question an investigation asks. The others are worth having, and combine well, but a chain of custody built on physical controls without an itemised record is a chain with no links in it — which is why the asset list matters more than any piece of hardware.
What should be agreed before the vehicle arrives?
Five things, and none of them can be settled retrospectively. Each corresponds to a record that either exists by collection day or never exists at all.
- The asset list — serial numbers for every data-bearing item, captured by you during decommissioning.
- Who signs the handover, on both sides, and against what document.
- Whether the load is dedicated or consolidated, since consolidation converts a list into a count.
- Which party issues destruction evidence, and confirmation that it will itemise rather than summarise.
- The treatment destination, named and recorded against the job.
Agreeing these at booking costs a short conversation. Reconstructing them eighteen months later, from a mailbox and a finance system, is where the real cost of a thin custody record shows up.
How does chain of custody apply to equipment being resold?
It applies more sharply, not less. Equipment leaving in working order carries readable storage unless it has been erased to a verified standard first, so a resale route puts functioning drives into circulation rather than into a shredder.
Whereas a destruction route ends with the media physically gone, a reuse route ends with the asset in somebody else's hands, which makes the erasure evidence the only thing standing between you and a disclosure. Reuse remains the better environmental outcome and often recovers real residual value, so the answer is not to avoid it — it is to make the erasure step explicit, verified and certified before the asset changes hands, and to keep the same itemised reconciliation you would apply to destruction. The certificate of data destruction guide covers which methods preserve the asset and which do not.
What does T&C Logistics provide, and what does the partner provide?
We provide the carriage link and the custody record attached to it. T&C Logistics is registered with the Environment Agency as an upper tier waste carrier, broker and dealer under CBDU654368, transporting under our Operator's Licence with GPS-tracked vehicles and goods-in-transit cover.
Treatment takes place at a partner-operated approved facility, and erasure or physical destruction of data-bearing media is performed and certified there, in that facility's name. We do not operate a treatment site, do not issue WEEE evidence notes, and do not issue destruction certificates — stating otherwise would make the certificate worth less, not more. For the wider managed service see IT equipment collection and disposal, for the regulatory framework see the WEEE Regulations, or get in touch to discuss a collection.
Frequently Asked Questions
- Can you collect drives already removed from the equipment?
- Yes, and loose media is in some ways easier to evidence, because the asset list is a list of drives rather than a list of machines containing drives. The important detail is that serial numbers are captured before collection — a box of drives handed over as a quantity has the same traceability problem as a pallet of laptops handed over as a quantity.
- Is a tail-lift van with one driver really more secure than a parcel network?
- For traceability, yes. A parcel network is built on consolidation and sortation, so your assets pass through multiple handling points that are not individually recorded against your consignment. A dedicated movement keeps the load identifiable from collection to delivery, with no intermediate storage leg that nobody owns.
- What happens if the count at the facility does not match our asset list?
- That discrepancy is exactly what the reconciliation exists to surface, and it is far more useful found early than discovered during an audit. Because the handover is signed against an itemised list at collection, the point at which the numbers diverge is identifiable rather than a matter of speculation between three parties months later.
- Do you offer on-site destruction instead of transporting the drives?
- Destruction is performed at the processing facility rather than at your premises, so the assets travel under custody first. Where on-site destruction is a firm requirement, the party to specify it with is the processor that would carry it out, since the certificate has to come from whoever performed the work.
- How long does the custody record need to be kept?
- No single period is prescribed, because the records come from different regimes. The waste transfer note is retained for two years by both parties; the asset list and destruction certificate are not statutory, so retention follows your own policy and any sector requirements. Filing all of them against one job reference makes that a single decision.
- Can we send our own staff to observe the collection?
- Yes, and for high-sensitivity decommissioning it is a reasonable control. The more durable safeguard is documentary rather than observational: an itemised list signed at handover records what transferred and to whom in a form that can be produced later, whereas an observed loading leaves no evidence unless someone wrote it down.
