Office IT Refresh and DPDPA: The Disposal SOP Every CIO Should Sign Off On

Updated: September 12, 2026 · 18 min read

Key Takeaways

  • The Digital Personal Data Protection Act, 2023 (DPDPA) imposes fines up to ₹250 crore for data breaches arising from improper device disposal under Section 33.
  • The E-Waste (Management) Rules, 2022 mandate that all end-of-life IT equipment be channelled exclusively to CPCB-authorised dismantlers or recyclers — informal vendors are non-compliant by definition.
  • NIST SP 800-88 Rev. 1 defines three media-sanitisation tiers (Clear, Purge, Destroy); your IT asset disposal SOP must map each device class to one of these tiers with documented evidence.
  • BRSR Core (SEBI circular dated 12 July 2023) requires top-1,000 listed companies to report e-waste volumes generated and disposed of from FY 2024-25 onwards — disposal records are now a SEBI audit trail, not just an IT housekeeping matter.

MeitY’s first round of DPDPA enforcement guidance, issued in late 2025, made one thing unambiguous: personal data does not stop being personal data because it sits on a decommissioned laptop. For Indian organisations undergoing office IT refreshes — and the post-pandemic hardware cycle means that most large enterprises are replacing 2019-era laptops and thin clients through FY 2026-27 — the gap between an informal vendor collecting old desktops and a documented, regulation-compliant IT asset disposal SOP is now measurable in crores of rupees in potential liability. This article gives CIOs, IT directors, and infosec heads a single, sign-off-ready SOP they can adapt, print, and anchor to three overlapping Indian regulatory regimes without reading a single government circular themselves.

Why the DPDPA Has Made IT Asset Disposal a Board-Level Risk in 2026

The Digital Personal Data Protection Act, 2023 (DPDPA) came into force in stages, with the Data Protection Board of India operationalised through rules notified by MeitY in 2025. Section 8(7) of the DPDPA obligates every Data Fiduciary to erase personal data — and instruct Data Processors to erase it — once the purpose for which it was collected is served. Section 33 provides the penalty structure: fines up to ₹250 crore per instance for data breaches attributable to failure in adequate safeguards. A decommissioned HR server shipped to an unauthorised scrap dealer, later found to contain employee Aadhaar-linked salary data, is precisely the scenario the Act was designed to catch.

Video: SOPs for utilisation of Hazardous Wastes Contaminated barrels and containers | Corpbiz – Corpbiz

The risk is not theoretical. In 2024 and 2025, multiple Indian organisations suffered data exposure incidents traced to improperly wiped hard drives resurfacing in secondary markets — concentrated in Delhi-NCR and Bengaluru grey-market electronics lanes, according to industry press reports. The DPDPA means that once the Data Protection Board begins adjudicating complaints, each such incident carries a separately assessable penalty. A 500-employee office refresh involving 600 devices, where 10% are inadequately wiped, is not one incident — it could be construed as multiple breaches across individual data subjects.

This is why the IT asset disposal SOP must be a CIO sign-off document, not an IT manager’s checklist. The liability rests with the organisation as Data Fiduciary, not the vendor who collected the machines.

The Regulatory Stack Every CIO Must Understand Before Signing Off

Three distinct Indian regulatory regimes converge on every corporate IT device at end of life. Understanding their interaction is essential before you design a disposal SOP that actually holds up under audit.

people collecting trash in garbage truck | The National Recycling Corporation
Photo by zibik on Unsplash

1. The E-Waste (Management) Rules, 2022

Notified by the Ministry of Environment, Forest and Climate Change (MoEFCC) and administered by the Central Pollution Control Board (CPCB), the E-Waste (Management) Rules, 2022 place bulk consumers — defined as organisations consuming IT equipment above notified thresholds — under a direct obligation to ensure their end-of-life devices reach only CPCB-authorised dismantlers or recyclers. Rule 16 prohibits bulk consumers from depositing e-waste with any person not authorised under the Rules. Violation attracts environmental liability under the Environment (Protection) Act, 1986, including potential closure directions and remediation costs that dwarf the scrap value of the equipment itself.

2. The Hazardous and Other Wastes (Management & Transboundary Movement) Rules, 2016

Certain components within IT equipment — lead-acid UPS batteries, cathode-ray-tube monitor glass, toner cartridges containing heavy metals — qualify as hazardous waste under the Hazardous and Other Wastes (Management & Transboundary Movement) Rules, 2016. Any organisation that generates such waste above the prescribed threshold must maintain a log of generation, storage, and disposal, and ensure disposal only through facilities with a valid Form 2 authorisation. The Rules require record retention for a minimum of 5 years (Schedule VI, Point 10). This intersects with your disposal SOP’s chain-of-custody documentation requirement.

3. The Digital Personal Data Protection Act, 2023 (DPDPA)

As outlined above, MeitY’s DPDPA framework imposes data erasure obligations that are functionally a pre-condition for any physical disposal. The Act does not prescribe a specific technical standard for erasure — that is your SOP’s job — but it does require that the Data Fiduciary be able to demonstrate that erasure occurred. A Certificate of Data Destruction from an accredited vendor, mapped to a specific device serial number, is the closest thing to an audit-ready defence you can produce.

Need a CPCB-Authorised E-Waste Disposal Partner Across India?

The National Recycling Corporation provides CPCB-authorised e-waste recycling and IT asset disposal for corporates across Mumbai, Pune, Delhi-NCR, Bengaluru and beyond — with serialised Certificates of Destruction and recycling documentation ready for BRSR and DPDPA audits.

Request a Compliant Disposal Quote

The 9-Step IT Asset Disposal SOP (With Template Fields)

The following SOP is structured for a mid-to-large corporate IT refresh. Each step includes the minimum template fields your records must capture. Steps 1 through 4 occur before the device leaves your premises; Steps 5 through 9 generate the evidence trail you retain.

Video: Hazardous Waste || 4 Types of Hazardous Waste || Four Classifications of Hazardous Waste – HSE STUDY GUIDE

Step 1 — Asset Inventory Tagging

Before any device enters the disposal queue, it must be reconciled against your asset register. Template fields: Asset Tag ID | Serial Number | Device Type | Processor/RAM | Acquisition Date | Assigned User | Department | Data Classification (Confidential / Internal / Public). Devices carrying Confidential-class data automatically escalate to a Destroy-tier sanitisation path under Step 4.

Step 2 — Data Classification and Sanitisation Tier Assignment

Map each device to a NIST SP 800-88 Rev. 1 sanitisation tier at this stage, not at collection. Template fields: Sanitisation Tier Assigned (Clear / Purge / Destroy) | Basis for Classification | Assigned Technician ID | Date of Assignment. Laptops from Finance, HR, Legal, and Customer-facing teams default to Purge or Destroy. Shared conference-room terminals may qualify for Clear, provided no personal data was ever stored locally.

Step 3 — Chain-of-Custody Record Creation

A chain-of-custody document must be opened the moment a device is physically separated from active service. Template fields: Custody Transfer Date | Releasing Officer (Name, Designation) | Location (Building, Floor, City) | Transport Mode | Authorised Vendor Name | Vendor CPCB Authorisation Number | Vehicle Registration | Seal Number (if applicable). For multi-site organisations, each site generates its own custody form; the ITAD vendor consolidates these at collection.

Step 4 — On-Site Data Destruction (Where Mandated)

Highly sensitive devices — servers, storage arrays, CFO/CISO laptops, HR HRMS terminals — should receive on-site physical destruction of storage media before the chassis leaves your facility. Acceptable methods under NIST 800-88 Destroy tier include degaussing (for magnetic media), disintegration, and physical shredding. Template fields: Destruction Method | Equipment Used | Witnessing Officer (Name, Designation) | Date and Time | Photographic Evidence Reference Number.

Step 5 — Authorised Vendor Handover and Manifest

The ITAD vendor must present their current CPCB authorisation certificate at collection. Verify the certificate’s validity date — CPCB authorisations are typically issued for 5 years, but can be suspended. Template fields: Vendor CPCB Auth Number | Auth Expiry Date | Number of Devices Collected | Gross Weight (kg) | Manifest Number | Vendor Representative Name and Signature.

Step 6 — Certificate of Data Destruction (CDD) Receipt

The CDD is your primary DPDPA evidence document. A compliant CDD names each device by serial number, states the destruction method, cites the applicable standard (NIST SP 800-88 Rev. 1, or DoD 5220.22-M where relevant), and carries a tamper-evident reference number. If your vendor cannot produce a serialised CDD within 15 business days of collection, that is a contractual breach — build this into your vendor agreement. Retain CDDs for a minimum of 3 years, consistent with the DPDPA’s accountability expectations, and 5 years for any device classified as Hazardous under the 2016 Rules.

Step 7 — Certificate of Recycling (COR) Receipt

Separate from the CDD, the COR confirms that the physical device has entered an authorised recycling stream compliant with the E-Waste (Management) Rules, 2022. It should reference the recycler’s CPCB authorisation and specify the quantity recycled by material category (plastics, ferrous metals, precious metals, hazardous components). Template fields: COR Reference Number | Recycler Name | CPCB Auth Number | Quantity by Material Type (kg) | Date of Recycling Confirmation.

Step 8 — DPDPA-Aligned Data Protection Log Update

Update your organisation’s Data Processing Record (required under DPDPA’s accountability framework) to reflect that personal data on the disposed devices has been erased. Template fields: Data Category Erased (e.g., employee PII, customer records) | Volume (approximate records or device count) | Erasure Method Reference | CDD Reference Number | Date Logged | DPO / CIO Sign-Off. This log is what the Data Protection Board will request first in any investigation.

Step 9 — BRSR and Internal ESG Reporting Update

Record the disposal event in your ESG data system for BRSR reporting. The quantity of e-waste disposed of (in metric tonnes or kg), the authorised recycler’s name, and the split between reuse, refurbishment, and recycling are all reportable data points under BRSR Core’s Environment pillar. Template fields: E-Waste Volume Disposed (kg) | Recycler Name | Disposal Channel (Reuse / Refurbish / Recycle / Destroy) | Reporting Period | BRSR Principle Reference (Principle 2, Essential Indicator 2).

Data Destruction Standards: NIST 800-88, NAID AAA and What Indian Auditors Accept

NIST SP 800-88 Rev. 1 (“Guidelines for Media Sanitisation”), published by the US National Institute of Standards and Technology, has become the de facto global benchmark for IT asset data destruction — and Indian infosec auditors increasingly cite it in their checklists, even though it is not an Indian standard. Its three tiers — Clear (overwriting for reuse), Purge (degaussing or block erase to prevent laboratory recovery), and Destroy (physical destruction making recovery infeasible) — map neatly onto different device risk profiles.

four assorted-color trash bins beside gray wall | The National Recycling Corporation
Photo by Pawel Czerwinski on Unsplash

NAID AAA Certification, administered by i-SIGMA (formerly the National Association for Information Destruction), is the vendor-side accreditation to look for when selecting an ITAD partner. A NAID AAA-certified vendor undergoes unannounced audits of its destruction processes, chain-of-custody controls, and employee background checks. In the Indian market, fewer than 20 vendors currently hold active NAID AAA certification — which means your procurement team needs to verify this specifically, not assume it. The Bureau of Indian Standards (BIS) has not yet issued an equivalent Indian standard for IT media sanitisation, making NIST 800-88 the practical benchmark by default.

The table below maps device class to the minimum acceptable sanitisation tier and the documentation output your SOP must capture:

Device Class Minimum NIST 800-88 Tier Preferred Method Required Documentation Retention Period
Standard office laptop (non-sensitive user) Clear Certified overwrite (3-pass minimum) Serialised CDD 3 years
HR / Finance / Legal laptop or desktop Purge Degaussing + overwrite verification Serialised CDD + witness sign-off 5 years
Server / NAS / SAN storage Destroy Physical shredding of drive platters CDD + photographic evidence + chain-of-custody manifest 5 years
Mobile phones / tablets (BYOD returned) Purge Factory reset + cryptographic erase Serialised CDD + MDM wipe log 3 years
UPS / Lead-acid batteries N/A (no data) Authorised hazardous waste disposal Hazardous waste manifest (Form 10, HW Rules 2016) + COR 5 years
Printers / MFDs with internal drives Purge Internal drive removal + certified overwrite CDD (drive-specific serial number) 3 years

₹250 Crore: How DPDPA Section 33 Translates to a Disposal Audit Checklist

Section 33 of the DPDPA establishes a tiered penalty structure administered by the Data Protection Board of India. The maximum penalty for a data breach attributable to failure to implement adequate safeguards — the category most likely to capture an improper disposal incident — is ₹250 crore. For failure to take reasonable security measures, a separate sub-clause provides for penalties up to ₹200 crore. These are not aggregate annual caps; they apply per complaint or per determination by the Board.

Video: Why do chemical process assets fail during their lifecycle? – PETROSULT ENGINEEERING ACADEMY

For a listed company, the reputational exposure often exceeds the financial penalty. A DPDPA adjudication is a disclosable event, relevant to SEBI’s continuous disclosure obligations under the Listing Obligations and Disclosure Requirements (LODR) Regulations, 2015. The compliance checklist below converts the Section 33 risk into concrete, quarter-by-quarter disposal audit actions:

  1. Audit your existing device estate this quarter (Q3 FY 2026-27): Identify all devices decommissioned in FY 2025-26 for which no Certificate of Data Destruction exists. Commission retrospective destruction where devices are still traceable.
  2. Amend vendor contracts by 31 December 2026: Insert a clause requiring the ITAD vendor to deliver a serialised CDD within 15 business days of collection, and to maintain CPCB authorisation as a standing contract condition.
  3. Classify all devices before disposal: Implement a data classification step in your IT asset management system (ServiceNow, Freshservice, or equivalent) that prevents a device from being marked “ready for disposal” without a sanitisation tier assigned.
  4. Establish a DPO-reviewed disposal log: Your Data Protection Officer must review and countersign the DPDPA-aligned data protection log (Step 8 of the SOP above) at least quarterly.
  5. Conduct an unannounced vendor audit at least once per FY: Visit your ITAD vendor’s facility or commission a third-party audit to verify that destruction equipment is operational, staff are trained, and certificates match destruction events — not batch-generated ex post facto.
  6. Test your incident response plan for a disposal breach scenario: The DPDPA requires notification to the Data Protection Board within 72 hours of becoming aware of a personal data breach. Run a tabletop exercise where the breach source is an improperly disposed device.
  7. Update your Records of Processing Activities (RoPA): The DPDPA’s accountability obligations require that data erasure events be traceable back to specific processing purposes. Ensure your RoPA has a “Disposed — Data Erased” lifecycle stage for every personal data category.

BRSR Linkage: Turning Your Disposal Records Into ESG Disclosure Assets

SEBI’s BRSR Core framework, introduced under its circular dated 12 July 2023 and made mandatory for the top 1,000 listed companies by market capitalisation from FY 2024-25, includes e-waste generation and disposal as an Essential Indicator under Principle 2 (Businesses should act in a manner sustainable for the environment). Specifically, companies must disclose the quantity of e-waste generated, the quantity disposed of through authorised channels, and the name of the authorised recycler.

This means that your IT asset disposal SOP is not merely a risk-mitigation instrument — it is a data-collection instrument for a SEBI-mandated disclosure. The Certificate of Recycling (COR) from Step 7, the CPCB authorisation number of your vendor, and the weight-based disposal records from Step 5 all feed directly into the BRSR disclosure table. Organisations that have invested in a clean disposal SOP are typically able to complete their BRSR e-waste disclosures in under two hours. Those without one spend weeks reconstructing records from vendor email trails — and sometimes cannot reconstruct them at all.

For unlisted companies, the BRSR is currently voluntary, but procurement teams at listed customers are increasingly requiring BRSR-equivalent ESG documentation from their supply chains. An IT asset disposal SOP that generates BRSR-grade records positions you well for those conversations. Our EPR compliance services page covers the broader regulatory documentation landscape for organisations managing multiple waste streams.

Want BRSR-Ready Disposal Documentation Without the Paperwork Burden?

The National Recycling Corporation provides serialised Certificates of Destruction and Certificates of Recycling for every collection event, formatted for direct insertion into your BRSR and DPDPA compliance records — with GST-compliant tax invoices included.

Get BRSR-Grade Disposal Documentation

Choosing a Compliant ITAD Partner in India: The Four Non-Negotiables

The Indian ITAD market in 2026 ranges from genuinely compliant, audited operators to informal scrap dealers who have printed a letterhead. The price difference between them can be ₹3–₹8 per kg in residual value offered — a gap that is easy to close once you account for the liability the compliant vendor is actually removing. Here are the four criteria that must appear in any vendor qualification process.

1. Valid CPCB Authorisation Under the E-Waste (Management) Rules, 2022

Verify the authorisation number directly on the CPCB e-waste portal — do not accept a photocopy alone. The authorisation must cover the specific category of equipment you are disposing of (Category 1: IT and Telecom equipment, under Schedule I of the Rules). A recycler authorised only for Category 2 (Consumer Electrical and Electronic Equipment) is not compliant for laptops and servers.

2. NAID AAA Certification or Equivalent Auditable Destruction Protocol

If NAID AAA is not available, require the vendor to produce an audited destruction protocol with records of their last three unannounced internal audits. Critically, the CDD they issue must be serialised — one certificate per device, not one certificate per batch. Batch certificates are functionally useless for DPDPA evidence purposes.

3. GST-Compliant Invoicing and HSN-Correct Documentation

Your ITAD transaction is a commercial transaction. The vendor must issue a GST-compliant tax invoice with the correct HSN code for e-waste or scrap, and — where residual value is offered — a proper credit note. Organisations that accept informal payments or undocumented credits expose themselves to GST scrutiny. See our post on GST on scrap sale: HSN codes, reverse charge, and the documentation trap for the full picture.

4. Data Protection Agreement (DPA) in Place

Under the DPDPA, your ITAD vendor is a Data Processor if they handle devices before data destruction is complete. You must have a Data Processing Agreement in place that specifies the destruction standard, the timeline for CDD delivery, the vendor’s obligations in case of a breach, and their sub-processor restrictions. Without this agreement, the Data Fiduciary (your organisation) bears the full regulatory risk regardless of what the vendor does or does not do.

Related Articles

Frequently Asked Questions

What is the penalty for improper IT device disposal under the DPDPA?

Section 33 of the Digital Personal Data Protection Act, 2023 (DPDPA) provides for penalties up to ₹250 crore per instance for data breaches attributable to a Data Fiduciary’s failure to implement adequate security safeguards. A device disposed of without certified data destruction — and subsequently found to contain personal data — can constitute such a breach. The Data Protection Board of India, operationalised by MeitY under rules notified in 2025, has the authority to investigate and adjudicate such complaints.

Are Indian companies legally required to use CPCB-authorised e-waste recyclers?

Yes. Rule 16 of the E-Waste (Management) Rules, 2022 prohibits bulk consumers — which includes most corporate organisations — from depositing e-waste with any person not authorised by the CPCB under the Rules. Disposal through informal scrap dealers or kabadiwallas, regardless of the price offered, is a direct violation. Authorisation can be verified on the CPCB’s e-waste portal at cpcb.nic.in/e-waste/.

How long must we retain Certificates of Data Destruction and Recycling?

There is no single prescribed retention period that covers all scenarios. As a practical standard: retain Certificates of Data Destruction (CDDs) for a minimum of 3 years to align with DPDPA accountability expectations. For devices containing hazardous components (UPS batteries, CRT monitors), retain the associated hazardous waste manifests for 5 years as required under Schedule VI of the Hazardous and Other Wastes (Management & Transboundary Movement) Rules, 2016. BRSR disclosures must be auditable for at least 3 financial years following disclosure.

Does BRSR reporting require disclosure of IT e-waste disposal specifically?

SEBI’s BRSR Core framework (circular dated 12 July 2023) requires companies in the top 1,000 by market capitalisation to disclose e-waste generated and disposed of under Principle 2, Essential Indicator 2. This includes IT equipment. The disclosure requires the quantity in metric tonnes and the name of the authorised recycler. From FY 2024-25, this is a mandatory, assured disclosure — meaning it must be capable of surviving third-party verification. Disposal records from your ITAD SOP are the primary evidence base.

What is the difference between a Certificate of Data Destruction and a Certificate of Recycling?

A Certificate of Data Destruction (CDD) confirms that all data stored on a device’s storage media has been irreversibly destroyed using a defined standard (typically NIST SP 800-88 Rev. 1). It addresses your DPDPA obligation. A Certificate of Recycling (COR) confirms that the physical device — after data destruction — has been processed by a CPCB-authorised recycler in compliance with the E-Waste (Management) Rules, 2022. It addresses your environmental compliance obligation. You require both documents for every IT device disposal event; neither substitutes for the other.

Work With The National Recycling Corporation

The National Recycling Corporation is a Mumbai-headquartered, pan-India recycling and scrap trading company with a proven track record in corporate IT asset disposal for enterprises across Maharashtra, Karnataka, Delhi-NCR, Tamil Nadu, and Gujarat. We work with CPCB-authorised dismantlers and recyclers for all IT equipment categories, ensuring that every collection event generates the documentation your DPDPA, BRSR, and E-Waste Rules compliance requires.

Every disposal engagement through us includes: a serialised Certificate of Data Destruction mapped to individual device serial numbers; a Certificate of Recycling from a CPCB-authorised facility under the E-Waste (Management) Rules, 2022; a GST-compliant tax invoice with correct HSN coding; and a chain-of-custody manifest covering the full journey from your premises to the recycling facility. For organisations with bulk volumes, we offer on-site destruction events with witnessing officers, suitable for servers, storage arrays, and classified-data devices.

Our e-waste management service is structured for corporate clients who need disposal partners that understand DPDPA liability, BRSR disclosure formats, and E-Waste Rules authorisation — not just scrap value. We also support corporate e-waste donation programmes where devices are refurbished and donated to verified NGOs, with full documentation for CSR reporting. To schedule a pickup, discuss a bulk disposal programme, or receive a compliance-grade quote, contact us and our team will respond within one business day.

  • Pan-India pickup coverage, including Tier-2 cities, coordinated from our Mumbai operations hub
  • CPCB-authorised disposal partners for all Schedule I IT equipment categories under the E-Waste (Management) Rules, 2022
  • Serialised, device-level Certificates of Data Destruction (NIST SP 800-88 Rev. 1 compliant)
  • Certificates of Recycling formatted for direct insertion into BRSR Essential Indicator disclosures
  • GST-compliant tax invoicing with correct HSN codes and reverse-charge handling where applicable
  • Fair residual-value pricing for recoverable metals, indexed to prevailing market rates
  • On-site destruction events for high-classification devices, with witnessing officer and photographic evidence

Sources and References

Leave a Comment

Your email address will not be published. Required fields are marked *