+91 973 973 2048 connect@privace.in Mon–Sat · 10:00–18:00 IST
Documentation

Chain of Custody in ITAD: 7 Questions to Ask Before You Sign

Chain of Custody in ITAD: 7 Questions to Ask Before You Sign
The short answer

Chain of custody is the documented sequence of who held your equipment, when, and what happened to it at each stage. Not a promise that it was handled carefully — a record that can be produced later.

Almost every ITAD vendor in India uses the phrase. The seven questions below establish, in about ten minutes, whether they have one.

What chain of custody actually means

The term comes from evidence handling. In a criminal case, if there is a gap in the record of who held a piece of evidence, the evidence becomes inadmissible — regardless of whether anything actually went wrong.

The same logic applies to your retired IT. If there is a break in the record, you cannot demonstrate what happened, even if the disposal was faultless. The disposal being fine and the disposal being provable are two separate things, and only one of them helps you in an audit.

The practical test: pick a device that left your building six months ago and try to establish what happened to it. If you cannot, you do not have a chain of custody.

The seven questions

Ask these before signing anything. Ask for answers in writing.

1. What is recorded at the point of collection, and who signs it?
There should be a document completed at your premises, before the vehicle leaves, that your representative signs. If the record is created later at the vendor's facility, the most important handover in the whole process is undocumented.

2. At what level are devices recorded?
Counts by category, or individual devices? Neither answer is automatically wrong — it depends on what your audit tests. What matters is that you find out before the job, not during the audit. Tell the vendor which level you need and get it confirmed.

3. Who physically transports the equipment, and are they your staff?
Subcontracted transport is normal. Undisclosed subcontracted transport is not. If a third party is in the chain, they should be named.

4. Where is it stored between collection and processing, and for how long?
This gap is where most real-world loss happens. Equipment that sits in a transit warehouse for three weeks is equipment nobody is watching.

5. When exactly does data destruction happen, relative to everything else?
It must be before resale assessment, before dismantling, before anything. If destruction happens after a resale grading step, working machines have been handled with your data on them.

6. What does the certificate state, and who issues it?
A named legal entity, an authorization reference, a certificate number, the destruction date as distinct from the collection date, and the method used. We covered this in detail in what a Certificate of Destruction should actually contain.

7. If we ask about a specific consignment in eighteen months, what can you retrieve?
This is the question that actually matters, and the one vendors are least prepared for. It tests whether records are kept, for how long, and whether anyone can find them.

What good answers sound like

How to read the answers you get.
QuestionWeak answerStrong answer
Record at collection“We send documentation afterwards”A named document, signed on site before departure
Recording level“We take care of everything”“Category counts as standard; device level if your audit needs it — tell us”
Transport“Our logistics partner” (unnamed)Named party, with the handover documented
Storage gap“It goes straight to the facility” with no detailA stated location and a stated typical duration
Destruction timing“Everything is destroyed”“Before grading, before dismantling, before anything else”
Certificate issuerA trading name onlyLegal entity plus authorization reference
Retrieval in 18 months“We keep everything”A stated retention period and how to request a record

Notice that the strong answers are not more impressive. They are more specific. Specificity is the whole signal here — a vendor who has actually built the process describes it in concrete terms, because they had to.

Where chains actually break

In practice, four points:

The collection itself. Someone turns up, loads a vehicle, and leaves without anything being signed. Everything after this is unverifiable regardless of how careful it was.

The transit gap. Between your building and the processing facility, often via an intermediate warehouse. Longest window, least documentation, no witnesses.

The resale diversion. A vendor spots a working machine worth reselling and pulls it out before destruction. This is the one that produces actual data breaches, and it is invisible to you because the machine simply never appears in the destruction record.

The retrospective certificate. Documentation created weeks later from memory rather than from a record made at the time. It looks identical on paper. It is worth nothing.

If you want to see how this maps to your current process, our exposure score covers it in ten questions, and the page for compliance teams lists the documentation we provide for vendor risk reviews.

Frequently Asked Questions

The documented sequence of who held the equipment, when, and what happened to it at each stage — from collection at your premises through transport, storage, data destruction and final processing.
Yes. A record created later at the vendor's facility leaves the most important handover in the process undocumented. It should be completed and signed before the vehicle leaves your site.
It depends on what your audit tests. Establish which level you need before the job rather than during the audit, and confirm it with the vendor in writing.
Before resale assessment and before dismantling. If grading happens first, working machines have been handled with your data still on them.
Ask for a stated retention period rather than an assurance that they keep everything. The useful test is whether they can retrieve a specific consignment eighteen months later.

Score Your Own Disposal Process

Ten questions, ninety seconds, scored across Security, Compliance, and Sustainability. Your result appears immediately — no email needed to see it.

Get My Score

Certified & government-authorized processing — via our MPCB-authorized, ISO-certified processing partner View all certifications →

WhatsAppTalk to an expert