All insights

How should you dispose of old business computers?

5 min readBy Brendon Whiting, Founder · 12 February 2026

Destroy the data first, document that you did, then dispose of the equipment responsibly. A retired machine with a readable drive is a data breach waiting to be reported, and the obligation follows the information rather than the hardware, so it remains yours after the device leaves the building.

The reason this deserves a process rather than a habit is that disposal is the one moment when business data leaves your control physically. Everything else in security is about controlling access to information you still hold. Here you are handing hardware to someone else, and if the drive is readable, so is everything that was ever on it: client records, financial data, saved passwords, email archives.

Deleting files does not remove them, and this is worth understanding rather than taking on faith. Deletion removes the reference while the data stays on the disk until overwritten, and a quick format does little more. Ordinary recovery tools, freely available, retrieve a great deal from a drive treated that way. That is why the standard is a proper wipe that overwrites the drive, or cryptographic erasure where the device supports it, or physical destruction.

For most small businesses the practical route is a documented wipe using proper tooling, with a record of the device, the serial number, the method and the date. That record matters as much as the wipe: if the question is ever asked, by an auditor, an insurer or a client, being able to produce a list is the difference between a documented process and an assurance nobody can verify. For genuinely sensitive material, physical destruction with a certificate is the safer answer and the small cost is easily justified.

Keep the disposal record with your other security evidence rather than in a drawer, because it gets asked for in the same conversations. An insurer's questionnaire, a tender response or an Essential Eight assessment can all touch on how retired equipment is handled, and a dated list of devices, serial numbers, method and operator answers it in seconds. Reconstructing that history afterwards is effectively impossible.

Encryption changes this in your favour, which is one of the quieter arguments for enabling it across the fleet in the first place. A drive that has been encrypted from day one can be rendered unreadable by destroying the key, which is faster and more reliable than overwriting. If your machines are managed and encrypted properly, disposal becomes a routine step rather than a project, and that is worth knowing when you are weighing whether encryption is worth the setup.

Do not forget the devices nobody thinks of as computers. Mobile phones hold email, files and saved credentials. Multifunction printers very commonly contain a hard drive holding images of everything scanned, copied and faxed, and a leased printer returned with that drive intact is a real and routinely overlooked exposure. Servers, network equipment and external drives all need the same treatment, and old backup media in a drawer is exactly the sort of thing found during an office move years later.

Then dispose responsibly, which is both an obligation and a reputational matter. Electronic waste should go through a proper e-waste path rather than into general rubbish, and reputable providers will supply documentation of what was received and how it was handled. Donation and resale are worthwhile where the equipment still has life, provided the data standard has been met first and the machine is still supported enough to be safe for whoever receives it.

Build disposal into the replacement rather than treating it as a separate task, because separate tasks are what create the cupboard. When a new machine is deployed, the old one is wiped, documented and sent for disposal as part of the same job, not set aside for later. Later is how a business accumulates a decade of drives, and it is also how a device that was going to be dealt with ends up in someone's car boot indefinitely.

The honest caveat is that the risk here is cumulative rather than dramatic. No single laptop in a cupboard is likely to cause an incident, and a business that has never had a disposal process usually has a decade of devices with data still on them scattered across storerooms, cars and someone's garage. The fix is an afternoon of inventory and a rule for next time. If you want your retirements handled and documented properly, call 1800 456 567.

Retire hardware without leaving data behind

We wipe and document drives to a defensible standard, then dispose of equipment responsibly, so retirement is not a future incident.

Frequently asked questions

No. Deleting removes the reference rather than the data, and a quick format is not much better, so ordinary recovery tools retrieve a great deal from both. Use a proper wipe that overwrites or cryptographically erases the drive, or physically destroy it, and keep a record of which was done.

The same standard applies, and arguably more care, because the device is going to a specific person rather than into a recycling stream. Wipe to a documented standard, confirm it, and if the machine held sensitive information, consider whether destruction is the safer choice despite the lost value.

Yes, and they are the ones people forget. Mobile phones hold email and files, and multifunction printers commonly contain a hard drive holding images of everything scanned and copied. A printer returned at the end of a lease with its drive intact is a genuine and frequently overlooked exposure.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.