+91 973 973 2048 connect@privace.in Mon–Sat · 10:00–18:00 IST
Compliance

IT Asset Disposal Compliance in Maharashtra: What MPCB Authorization Actually Requires

IT Asset Disposal Compliance in Maharashtra: What MPCB Authorization Actually Requires

If your organisation operates in Maharashtra and retires laptops, desktops, servers, or networking equipment, your disposal process sits inside a regulatory framework whether or not anyone in your organisation has looked at it. Most IT teams discover this during a vendor review or an internal audit — which is the worst possible time to find out the paperwork isn't there.

This is a plain-language explanation of what actually applies, what MPCB authorization means when a vendor claims it, and which parts of the obligation stay with you no matter who you hire.

Who the rules actually apply to

India's e-waste framework operates under the E-Waste (Management) Rules, administered nationally by the Central Pollution Control Board (CPCB) and at state level by the State Pollution Control Boards — in Maharashtra, that's the Maharashtra Pollution Control Board (MPCB).

A common misreading is that these rules only bind manufacturers and recyclers. They don't. The framework assigns duties across several roles, and one of them is the bulk consumer — broadly, organisations that use electrical and electronic equipment at scale. Most enterprises, banks, BPOs, hospitals, and educational institutions fall into this category by virtue of the volume of IT equipment they operate.

The practical takeawayIf your organisation retires IT hardware in meaningful quantities, you are a participant in this framework, not a bystander to it. Your obligations centre on channelling that equipment to authorized handlers and maintaining records that show you did.

What MPCB authorization is — and isn't

When a vendor says they are “MPCB authorized,” they are usually referring to a Consent to Operate issued by the board. That document is specific in ways worth understanding:

  • It is site-specific. Authorization attaches to a named facility at a named address, not to a company in the abstract. A vendor with an authorized facility in one district cannot extend that authorization to an unlisted second site.
  • It is category-specific. The consent lists which waste categories the facility may handle. IT equipment falls under defined ITEW categories. A consent covering, say, only cable peeling does not cover dismantling laptops.
  • It is capacity-bound. Consents specify a maximum annual quantity in metric tonnes. A facility authorized for a modest tonnage cannot lawfully absorb unlimited volume.
  • It expires. Every consent carries a validity period. An expired consent is not authorization.

What authorization is not is a statement about the quality of a vendor's documentation, the security of their data destruction, or whether their chain-of-custody would survive an audit. It confirms they are permitted to operate. That is the floor, not the ceiling.

What stays your responsibility

This is the part that surprises people. Handing equipment to an authorized vendor does not transfer your obligation to have handled it properly. In practice, several things remain squarely yours:

  • Records of what left your premises. If you cannot produce an inventory of retired assets, you cannot reconcile it against whatever certificate a vendor gives you later.
  • Evidence of where it went. Movement and pickup records tie your inventory to a specific authorized handler on a specific date.
  • The data on the devices. E-waste rules govern the waste. Data protection obligations sit on top of them and are entirely separate. A perfectly compliant recycling chain does not help you if a drive left your building unwiped.
  • Vendor due diligence. Choosing an unauthorized handler because they quoted lower is a decision your organisation made, and it is documented in your procurement trail.

How to verify a vendor properly

Ask for the consent document itself, not a claim. Then check four things on it:

  1. The legal entity name matches the company you are actually contracting with. Mismatches between a trading name and the name on the certificate are common and worth resolving before signing.
  2. The facility address is where your equipment will physically be processed. If a vendor collects in Mumbai but processes elsewhere, the consent should cover the processing site.
  3. The listed categories include IT equipment, not just generic scrap or metals.
  4. The validity date has not passed.

A vendor who is comfortable with this request is a vendor who has the paperwork. Reluctance to share the actual document is itself information.

Where PrivAce sitsPrivAce Technologies operates as the Collection Partner of Green Life E Waste Recycling Pvt Ltd, an MPCB-authorized processing partner whose consent covers ITEW categories and runs through September 2028. We provide the consent document, ISO certifications, and device-level records on request for vendor onboarding and audit purposes.

A practical checklist

If you want to know where you stand before the next audit, work through this:

  • Do you maintain a documented inventory of retired IT assets?
  • Is your current disposal vendor's authorization document on file, in date, and covering IT categories?
  • Do you receive a Certificate of Destruction for data-bearing devices, per job?
  • Can you produce pickup and movement records for the last twelve months?
  • Is your EPR documentation maintained rather than assembled on request?
  • Is data destruction happening before devices leave your control or reach a resale channel?

If more than one of those is a “not really,” the gap is worth closing while it is still an internal matter rather than an audit finding. Our free IT Asset Exposure Score walks through these same checks in about ninety seconds and gives you a scored breakdown across security, compliance, and sustainability.

This article explains the general framework and is not legal advice. Rules are periodically amended; confirm current requirements with MPCB or a qualified environmental compliance advisor before relying on any specific position.

FAQ

Questions People Ask About This

No. Choosing an authorized handler is part of meeting your obligation, but the duty to maintain records, inventory retired assets, and ensure data is destroyed remains with your organisation as the waste generator.
Ask for the Consent to Operate document itself and verify four things: the legal entity name matches your contracting party, the facility address is where processing actually happens, the listed categories include IT equipment, and the validity date has not passed.
Not directly. E-waste rules govern the handling and recycling of the waste itself. Obligations around the data residing on those devices sit under separate data protection expectations and contractual commitments, which is why certified destruction and a Certificate of Destruction matter independently.

Score Your Own Disposal Process

Ten questions, ninety seconds, scored across Security, Compliance, and Sustainability. Your result appears immediately — no email needed to see it.

Get My Score

Need This Handled Properly?

Certified data destruction, documented chain-of-custody, and audit-ready certification across Mumbai, Navi Mumbai, Thane, and Pune.

Certified & government-authorized processing — via our MPCB-authorized, ISO-certified processing partner View all certifications →

WhatsAppTalk to an expert