ITAD & E-Waste Glossary.
Plain-English definitions of the terms that appear in disposal contracts, audit questions and vendor proposals — written for people who have to make decisions, not pass an exam.
Most disputes about IT asset disposal come down to two parties using the same word to mean different things. “Certified data destruction”, “chain of custody” and “zero landfill” all sound definite and are all used loosely.
These are the working definitions we use. If a vendor uses one of them differently, that is worth establishing in writing before the equipment moves rather than after.
Terms and Definitions
The end-to-end process of retiring IT equipment: collecting it, destroying the data on it, recovering any residual value, and recycling the remainder through an authorized facility, with documentation at each handover. ITAD differs from e-waste recycling in that the data and the audit trail are treated as the primary concerns rather than the material. IT Asset Disposition service →
A document issued after data destruction has taken place, stating what was destroyed, by which method, and on what date. Issued by the processing entity. A certificate produced at the point of collection certifies an intention rather than an outcome, because the destruction has not yet happened. What a Certificate of Destruction should contain →
The statutory record accompanying a consignment of e-waste from the generator to an authorized recycler, required under the E-Waste (Management) Rules, 2022. It records what moved, when, and to whom. It is an environmental compliance document, not a data-destruction record.
Under the E-Waste (Management) Rules, 2022, an entity that uses electrical and electronic equipment in bulk — companies, government bodies, banks, educational institutions, hospitals. Bulk consumers are expected to channel end-of-life equipment to an authorized recycler and to maintain records of having done so.
The permanent removal of data from storage media, achieved by overwriting with certified erasure software, degaussing magnetic media, or physically destroying the media. Deleting files and reformatting a drive achieve neither — both leave the underlying data recoverable. Certified Data Destruction service →
Exposing magnetic storage media to a magnetic field strong enough to destroy the magnetic domains holding the data. Effective on traditional hard disk drives and backup tape, and permanent — a degaussed drive cannot be reused. Degaussing has no effect on SSDs, which store data in flash cells rather than magnetically. Hard Drive Destruction service →
The documented sequence of who held an asset, when, and what happened to it at each stage — from collection at your premises to final processing. A break anywhere in the chain means the disposal cannot be evidenced, regardless of what actually happened to the equipment.
The Central Pollution Control Board, India's national environmental regulator. It frames the e-waste rules and maintains the framework under which state boards issue recycler authorizations.
The Maharashtra Pollution Control Board, the state authority that issues the Consent to Operate under which an e-waste recycler in Maharashtra is legally authorized to collect, dismantle and recycle e-waste. View our processing partner's certifications →
The authorization issued by a state pollution control board permitting a facility to operate, specifying which waste categories it may handle and for how long. Ask any disposal vendor for their current one, including the expiry date and the categories it covers.
NIST Special Publication 800-88, Guidelines for Media Sanitization — the international reference standard for destroying data on storage media. It defines three outcomes: Clear (protects against simple recovery), Purge (protects against laboratory recovery), and Destroy (renders the media itself unusable). PrivAce follows NIST SP 800-88 as its media sanitisation reference.
The three sanitisation outcomes defined in NIST SP 800-88. Clear uses standard read/write commands to protect against simple recovery. Purge applies techniques such as cryptographic erase or degaussing to defeat laboratory recovery. Destroy physically renders the media unusable. When a vendor says they “wipe drives”, the useful question is which of these three they achieve.
The technique SSD controllers use to spread writes across physical memory cells and extend drive life. It is also why conventional overwriting is unreliable on SSDs: the controller may map a write to a different physical cell than the one holding the original data, leaving fragments intact in cells the overwrite never reached. Shredding vs degaussing vs wiping →
Destroying the encryption key on a self-encrypting drive, rendering the stored ciphertext unreadable. Fast, and effective where the drive genuinely encrypted everything it stored. It relies entirely on the encryption having been correctly implemented, which is why it is often paired with physical destruction for the most sensitive media.
Assessing and realising the residual resale value of retired IT equipment. In a properly ordered ITAD process, recovery assessment happens after data destruction, so value is returned without the data leaving alongside the hardware. Asset Recovery service →
The movement of goods from the end user back up the supply chain — in ITAD, the collection, consolidation and transport of retired equipment from multiple sites to a processing facility. Server Decommissioning service →
The planned removal of IT infrastructure from service — most often a server room or data centre. It involves powering down, de-racking, accounting for every data-bearing drive, and removing racks, switches, storage arrays and UPS units without damaging the premises. Server Decommissioning service →
The regulatory principle that producers of electronic equipment are responsible for its collection and recycling at end of life. Producers meet EPR targets through registered recyclers. EPR is a producer obligation; it does not remove the separate obligations that sit on a bulk consumer disposing of its own equipment.
Waste Electrical and Electronic Equipment — the European Union's term and directive for e-waste. Encountered in India mainly through multinational parent-company policies, which often require Indian subsidiaries to apply WEEE-equivalent standards.
The practice of tracking IT assets across their whole lifecycle — procurement, deployment, maintenance, retirement. ITAD is the final stage of ITAM. Where ITAM records are accurate, disposal is straightforward; where they are not, the disposal is usually the point at which the gaps become visible.
India's Digital Personal Data Protection Act, 2023. It applies to all digital personal data, creates the accountable role of Data Fiduciary, and includes an erasure obligation once the purpose for holding personal data has ended — an obligation that extends to personal data on retired devices. What the DPDP Act requires when you retire a laptop →
Under the DPDP Act 2023, the entity that determines the purpose and means of processing personal data. For a company disposing of its own retired laptops, the company is the Data Fiduciary and remains accountable for the personal data on them.
The international standard for an information security management system. In IT asset disposal it is the credential that speaks directly to how sensitive data is handled during processing, as distinct from ISO 9001 (quality) or ISO 14001 (environmental management). View our processing partner's certifications →
Any device containing storage media capable of holding data. The category is wider than most inventories assume: alongside laptops, desktops and servers it includes copiers and multifunction printers, networking equipment, backup tapes, USB drives, memory cards and phones.
A commitment that no fraction of collected e-waste is sent to landfill — every material stream is either recovered, recycled or routed to an authorized treatment facility. It is a claim worth asking a vendor to evidence rather than accepting at face value.
Last reviewed 30 August 2026. Primary sources: E-Waste (Management) Rules, 2022, DPDP Act, 2023, NIST SP 800-88.
Still Not Sure What You Need?
Send us a rough device list. We will tell you which of these actually applies to your situation, and what documentation you would receive.