Key Takeaways
- The Digital Personal Data Protection Act, 2023 (DPDPA) imposes fines up to ₹250 crore for data breaches arising from improper device disposal under Section 33.
- The E-Waste (Management) Rules, 2022 mandate that all end-of-life IT equipment be channelled exclusively to CPCB-authorised dismantlers or recyclers — informal vendors are non-compliant by definition.
- NIST SP 800-88 Rev. 1 defines three media-sanitisation tiers (Clear, Purge, Destroy); your IT asset disposal SOP must map each device class to one of these tiers with documented evidence.
- BRSR Core (SEBI circular dated 12 July 2023) requires top-1,000 listed companies to report e-waste volumes generated and disposed of from FY 2024-25 onwards — disposal records are now a SEBI audit trail, not just an IT housekeeping matter.
Table of Contents
- Why the DPDPA Has Made IT Asset Disposal a Board-Level Risk in 2026
- The Regulatory Stack Every CIO Must Understand Before Signing Off
- The 9-Step IT Asset Disposal SOP (With Template Fields)
- Data Destruction Standards: NIST 800-88, NAID AAA and What Indian Auditors Accept
- ₹250 Crore: How DPDPA Section 33 Translates to a Disposal Audit Checklist
- BRSR Linkage: Turning Your Disposal Records Into ESG Disclosure Assets
- Choosing a Compliant ITAD Partner in India: The Four Non-Negotiables
- Related Articles
- Frequently Asked Questions
- Work With The National Recycling Corporation
- Sources and References
MeitY’s first round of DPDPA enforcement guidance, issued in late 2025, made one thing unambiguous: personal data does not stop being personal data because it sits on a decommissioned laptop. For Indian organisations undergoing office IT refreshes — and the post-pandemic hardware cycle means that most large enterprises are replacing 2019-era laptops and thin clients through FY 2026-27 — the gap between an informal vendor collecting old desktops and a documented, regulation-compliant IT asset disposal SOP is now measurable in crores of rupees in potential liability. This article gives CIOs, IT directors, and infosec heads a single, sign-off-ready SOP they can adapt, print, and anchor to three overlapping Indian regulatory regimes without reading a single government circular themselves.
Why the DPDPA Has Made IT Asset Disposal a Board-Level Risk in 2026
The Digital Personal Data Protection Act, 2023 (DPDPA) came into force in stages, with the Data Protection Board of India operationalised through rules notified by MeitY in 2025. Section 8(7) of the DPDPA obligates every Data Fiduciary to erase personal data — and instruct Data Processors to erase it — once the purpose for which it was collected is served. Section 33 provides the penalty structure: fines up to ₹250 crore per instance for data breaches attributable to failure in adequate safeguards. A decommissioned HR server shipped to an unauthorised scrap dealer, later found to contain employee Aadhaar-linked salary data, is precisely the scenario the Act was designed to catch.
Video: SOPs for utilisation of Hazardous Wastes Contaminated barrels and containers | Corpbiz – Corpbiz
The risk is not theoretical. In 2024 and 2025, multiple Indian organisations suffered data exposure incidents traced to improperly wiped hard drives resurfacing in secondary markets — concentrated in Delhi-NCR and Bengaluru grey-market electronics lanes, according to industry press reports. The DPDPA means that once the Data Protection Board begins adjudicating complaints, each such incident carries a separately assessable penalty. A 500-employee office refresh involving 600 devices, where 10% are inadequately wiped, is not one incident — it could be construed as multiple breaches across individual data subjects.
This is why the IT asset disposal SOP must be a CIO sign-off document, not an IT manager’s checklist. The liability rests with the organisation as Data Fiduciary, not the vendor who collected the machines.
The Regulatory Stack Every CIO Must Understand Before Signing Off
Three distinct Indian regulatory regimes converge on every corporate IT device at end of life. Understanding their interaction is essential before you design a disposal SOP that actually holds up under audit.
1. The E-Waste (Management) Rules, 2022
Notified by the Ministry of Environment, Forest and Climate Change (MoEFCC) and administered by the Central Pollution Control Board (CPCB), the E-Waste (Management) Rules, 2022 place bulk consumers — defined as organisations consuming IT equipment above notified thresholds — under a direct obligation to ensure their end-of-life devices reach only CPCB-authorised dismantlers or recyclers. Rule 16 prohibits bulk consumers from depositing e-waste with any person not authorised under the Rules. Violation attracts environmental liability under the Environment (Protection) Act, 1986, including potential closure directions and remediation costs that dwarf the scrap value of the equipment itself.
2. The Hazardous and Other Wastes (Management & Transboundary Movement) Rules, 2016
Certain components within IT equipment — lead-acid UPS batteries, cathode-ray-tube monitor glass, toner cartridges containing heavy metals — qualify as hazardous waste under the Hazardous and Other Wastes (Management & Transboundary Movement) Rules, 2016. Any organisation that generates such waste above the prescribed threshold must maintain a log of generation, storage, and disposal, and ensure disposal only through facilities with a valid Form 2 authorisation. The Rules require record retention for a minimum of 5 years (Schedule VI, Point 10). This intersects with your disposal SOP’s chain-of-custody documentation requirement.
3. The Digital Personal Data Protection Act, 2023 (DPDPA)
As outlined above, MeitY’s DPDPA framework imposes data erasure obligations that are functionally a pre-condition for any physical disposal. The Act does not prescribe a specific technical standard for erasure — that is your SOP’s job — but it does require that the Data Fiduciary be able to demonstrate that erasure occurred. A Certificate of Data Destruction from an accredited vendor, mapped to a specific device serial number, is the closest thing to an audit-ready defence you can produce.
Need a CPCB-Authorised E-Waste Disposal Partner Across India?
The National Recycling Corporation provides CPCB-authorised e-waste recycling and IT asset disposal for corporates across Mumbai, Pune, Delhi-NCR, Bengaluru and beyond — with serialised Certificates of Destruction and recycling documentation ready for BRSR and DPDPA audits.
The 9-Step IT Asset Disposal SOP (With Template Fields)
The following SOP is structured for a mid-to-large corporate IT refresh. Each step includes the minimum template fields your records must capture. Steps 1 through 4 occur before the device leaves your premises; Steps 5 through 9 generate the evidence trail you retain.
Video: Hazardous Waste || 4 Types of Hazardous Waste || Four Classifications of Hazardous Waste – HSE STUDY GUIDE
Step 1 — Asset Inventory Tagging
Before any device enters the disposal queue, it must be reconciled against your asset register. Template fields: Asset Tag ID | Serial Number | Device Type | Processor/RAM | Acquisition Date | Assigned User | Department | Data Classification (Confidential / Internal / Public). Devices carrying Confidential-class data automatically escalate to a Destroy-tier sanitisation path under Step 4.
Step 2 — Data Classification and Sanitisation Tier Assignment
Map each device to a NIST SP 800-88 Rev. 1 sanitisation tier at this stage, not at collection. Template fields: Sanitisation Tier Assigned (Clear / Purge / Destroy) | Basis for Classification | Assigned Technician ID | Date of Assignment. Laptops from Finance, HR, Legal, and Customer-facing teams default to Purge or Destroy. Shared conference-room terminals may qualify for Clear, provided no personal data was ever stored locally.
Step 3 — Chain-of-Custody Record Creation
A chain-of-custody document must be opened the moment a device is physically separated from active service. Template fields: Custody Transfer Date | Releasing Officer (Name, Designation) | Location (Building, Floor, City) | Transport Mode | Authorised Vendor Name | Vendor CPCB Authorisation Number | Vehicle Registration | Seal Number (if applicable). For multi-site organisations, each site generates its own custody form; the ITAD vendor consolidates these at collection.
Step 4 — On-Site Data Destruction (Where Mandated)
Highly sensitive devices — servers, storage arrays, CFO/CISO laptops, HR HRMS terminals — should receive on-site physical destruction of storage media before the chassis leaves your facility. Acceptable methods under NIST 800-88 Destroy tier include degaussing (for magnetic media), disintegration, and physical shredding. Template fields: Destruction Method | Equipment Used | Witnessing Officer (Name, Designation) | Date and Time | Photographic Evidence Reference Number.
Step 5 — Authorised Vendor Handover and Manifest
The ITAD vendor must present their current CPCB authorisation certificate at collection. Verify the certificate’s validity date — CPCB authorisations are typically issued for 5 years, but can be suspended. Template fields: Vendor CPCB Auth Number | Auth Expiry Date | Number of Devices Collected | Gross Weight (kg) | Manifest Number | Vendor Representative Name and Signature.
Step 6 — Certificate of Data Destruction (CDD) Receipt
The CDD is your primary DPDPA evidence document. A compliant CDD names each device by serial number, states the destruction method, cites the applicable standard (NIST SP 800-88 Rev. 1, or DoD 5220.22-M where relevant), and carries a tamper-evident reference number. If your vendor cannot produce a serialised CDD within 15 business days of collection, that is a contractual breach — build this into your vendor agreement. Retain CDDs for a minimum of 3 years, consistent with the DPDPA’s accountability expectations, and 5 years for any device classified as Hazardous under the 2016 Rules.
Step 7 — Certificate of Recycling (COR) Receipt
Separate from the CDD, the COR confirms that the physical device has entered an authorised recycling stream compliant with the E-Waste (Management) Rules, 2022. It should reference the recycler’s CPCB authorisation and specify the quantity recycled by material category (plastics, ferrous metals, precious metals, hazardous components). Template fields: COR Reference Number | Recycler Name | CPCB Auth Number | Quantity by Material Type (kg) | Date of Recycling Confirmation.
Step 8 — DPDPA-Aligned Data Protection Log Update
Update your organisation’s Data Processing Record (required under DPDPA’s accountability framework) to reflect that personal data on the disposed devices has been erased. Template fields: Data Category Erased (e.g., employee PII, customer records) | Volume (approximate records or device count) | Erasure Method Reference | CDD Reference Number | Date Logged | DPO / CIO Sign-Off. This log is what the Data Protection Board will request first in any investigation.
Step 9 — BRSR and Internal ESG Reporting Update
Record the disposal event in your ESG data system for BRSR reporting. The quantity of e-waste disposed of (in metric tonnes or kg), the authorised recycler’s name, and the split between reuse, refurbishment, and recycling are all reportable data points under BRSR Core’s Environment pillar. Template fields: E-Waste Volume Disposed (kg) | Recycler Name | Disposal Channel (Reuse / Refurbish / Recycle / Destroy) | Reporting Period | BRSR Principle Reference (Principle 2, Essential Indicator 2).
Data Destruction Standards: NIST 800-88, NAID AAA and What Indian Auditors Accept
NIST SP 800-88 Rev. 1 (“Guidelines for Media Sanitisation”), published by the US National Institute of Standards and Technology, has become the de facto global benchmark for IT asset data destruction — and Indian infosec auditors increasingly cite it in their checklists, even though it is not an Indian standard. Its three tiers — Clear (overwriting for reuse), Purge (degaussing or block erase to prevent laboratory recovery), and Destroy (physical destruction making recovery infeasible) — map neatly onto different device risk profiles.
NAID AAA Certification, administered by i-SIGMA (formerly the National Association for Information Destruction), is the vendor-side accreditation to look for when selecting an ITAD partner. A NAID AAA-certified vendor undergoes unannounced audits of its destruction processes, chain-of-custody controls, and employee background checks. In the Indian market, fewer than 20 vendors currently hold active NAID AAA certification — which means your procurement team needs to verify this specifically, not assume it. The Bureau of Indian Standards (BIS) has not yet issued an equivalent Indian standard for IT media sanitisation, making NIST 800-88 the practical benchmark by default.
The table below maps device class to the minimum acceptable sanitisation tier and the documentation output your SOP must capture:
| Device Class | Minimum NIST 800-88 Tier | Preferred Method | Required Documentation | Retention Period |
|---|---|---|---|---|
| Standard office laptop (non-sensitive user) | Clear | Certified overwrite (3-pass minimum) | Serialised CDD | 3 years |
| HR / Finance / Legal laptop or desktop | Purge | Degaussing + overwrite verification | Serialised CDD + witness sign-off | 5 years |
| Server / NAS / SAN storage | Destroy | Physical shredding of drive platters | CDD + photographic evidence + chain-of-custody manifest | 5 years |
| Mobile phones / tablets (BYOD returned) | Purge | Factory reset + cryptographic erase | Serialised CDD + MDM wipe log | 3 years |
| UPS / Lead-acid batteries | N/A (no data) | Authorised hazardous waste disposal | Hazardous waste manifest (Form 10, HW Rules 2016) + COR | 5 years |
| Printers / MFDs with internal drives | Purge | Internal drive removal + certified overwrite | CDD (drive-specific serial number) | 3 years |
₹250 Crore: How DPDPA Section 33 Translates to a Disposal Audit Checklist
Section 33 of the DPDPA establishes a tiered penalty structure administered by the Data Protection Board of India. The maximum penalty for a data breach attributable to failure to implement adequate safeguards — the category most likely to capture an improper disposal incident — is ₹250 crore. For failure to take reasonable security measures, a separate sub-clause provides for penalties up to ₹200 crore. These are not aggregate annual caps; they apply per complaint or per determination by the Board.
Video: Why do chemical process assets fail during their lifecycle? – PETROSULT ENGINEEERING ACADEMY
For a listed company, the reputational exposure often exceeds the financial penalty. A DPDPA adjudication is a disclosable event, relevant to SEBI’s continuous disclosure obligations under the Listing Obligations and Disclosure Requirements (LODR) Regulations, 2015. The compliance checklist below converts the Section 33 risk into concrete, quarter-by-quarter disposal audit actions:
- Audit your existing device estate this quarter (Q3 FY 2026-27): Identify all devices decommissioned in FY 2025-26 for which no Certificate of Data Destruction exists. Commission retrospective destruction where devices are still traceable.
- Amend vendor contracts by 31 December 2026: Insert a clause requiring the ITAD vendor to deliver a serialised CDD within 15 business days of collection, and to maintain CPCB authorisation as a standing contract condition.
- Classify all devices before disposal: Implement a data classification step in your IT asset management system (ServiceNow, Freshservice, or equivalent) that prevents a device from being marked “ready for disposal” without a sanitisation tier assigned.
- Establish a DPO-reviewed disposal log: Your Data Protection Officer must review and countersign the DPDPA-aligned data protection log (Step 8 of the SOP above) at least quarterly.
- Conduct an unannounced vendor audit at least once per FY: Visit your ITAD vendor’s facility or commission a third-party audit to verify that destruction equipment is operational, staff are trained, and certificates match destruction events — not batch-generated ex post facto.
- Test your incident response plan for a disposal breach scenario: The DPDPA requires notification to the Data Protection Board within 72 hours of becoming aware of a personal data breach. Run a tabletop exercise where the breach source is an improperly disposed device.
- Update your Records of Processing Activities (RoPA): The DPDPA’s accountability obligations require that data erasure events be traceable back to specific processing purposes. Ensure your RoPA has a “Disposed — Data Erased” lifecycle stage for every personal data category.
BRSR Linkage: Turning Your Disposal Records Into ESG Disclosure Assets
SEBI’s BRSR Core framework, introduced under its circular dated 12 July 2023 and made mandatory for the top 1,000 listed companies by market capitalisation from FY 2024-25, includes e-waste generation and disposal as an Essential Indicator under Principle 2 (Businesses should act in a manner sustainable for the environment). Specifically, companies must disclose the quantity of e-waste generated, the quantity disposed of through authorised channels, and the name of the authorised recycler.
This means that your IT asset disposal SOP is not merely a risk-mitigation instrument — it is a data-collection instrument for a SEBI-mandated disclosure. The Certificate of Recycling (COR) from Step 7, the CPCB authorisation number of your vendor, and the weight-based disposal records from Step 5 all feed directly into the BRSR disclosure table. Organisations that have invested in a clean disposal SOP are typically able to complete their BRSR e-waste disclosures in under two hours. Those without one spend weeks reconstructing records from vendor email trails — and sometimes cannot reconstruct them at all.
For unlisted companies, the BRSR is currently voluntary, but procurement teams at listed customers are increasingly requiring BRSR-equivalent ESG documentation from their supply chains. An IT asset disposal SOP that generates BRSR-grade records positions you well for those conversations. Our EPR compliance services page covers the broader regulatory documentation landscape for organisations managing multiple waste streams.
Want BRSR-Ready Disposal Documentation Without the Paperwork Burden?
The National Recycling Corporation provides serialised Certificates of Destruction and Certificates of Recycling for every collection event, formatted for direct insertion into your BRSR and DPDPA compliance records — with GST-compliant tax invoices included.
Choosing a Compliant ITAD Partner in India: The Four Non-Negotiables
The Indian ITAD market in 2026 ranges from genuinely compliant, audited operators to informal scrap dealers who have printed a letterhead. The price difference between them can be ₹3–₹8 per kg in residual value offered — a gap that is easy to close once you account for the liability the compliant vendor is actually removing. Here are the four criteria that must appear in any vendor qualification process.
1. Valid CPCB Authorisation Under the E-Waste (Management) Rules, 2022
Verify the authorisation number directly on the CPCB e-waste portal — do not accept a photocopy alone. The authorisation must cover the specific category of equipment you are disposing of (Category 1: IT and Telecom equipment, under Schedule I of the Rules). A recycler authorised only for Category 2 (Consumer Electrical and Electronic Equipment) is not compliant for laptops and servers.
2. NAID AAA Certification or Equivalent Auditable Destruction Protocol
If NAID AAA is not available, require the vendor to produce an audited destruction protocol with records of their last three unannounced internal audits. Critically, the CDD they issue must be serialised — one certificate per device, not one certificate per batch. Batch certificates are functionally useless for DPDPA evidence purposes.
3. GST-Compliant Invoicing and HSN-Correct Documentation
Your ITAD transaction is a commercial transaction. The vendor must issue a GST-compliant tax invoice with the correct HSN code for e-waste or scrap, and — where residual value is offered — a proper credit note. Organisations that accept informal payments or undocumented credits expose themselves to GST scrutiny. See our post on GST on scrap sale: HSN codes, reverse charge, and the documentation trap for the full picture.
4. Data Protection Agreement (DPA) in Place
Under the DPDPA, your ITAD vendor is a Data Processor if they handle devices before data destruction is complete. You must have a Data Processing Agreement in place that specifies the destruction standard, the timeline for CDD delivery, the vendor’s obligations in case of a breach, and their sub-processor restrictions. Without this agreement, the Data Fiduciary (your organisation) bears the full regulatory risk regardless of what the vendor does or does not do.
Related Articles
- Maharashtra Pollution Control Board Notices in 2025: What Triggered Them and How to Avoid Them
- GST on Scrap Sale: HSN Codes, Reverse Charge and the Documentation Trap
- Setting Up a Recycling Unit in India: Licences, Land, Capex and Approval Sequence
Frequently Asked Questions
What is the penalty for improper IT device disposal under the DPDPA?
Section 33 of the Digital Personal Data Protection Act, 2023 (DPDPA) provides for penalties up to ₹250 crore per instance for data breaches attributable to a Data Fiduciary’s failure to implement adequate security safeguards. A device disposed of without certified data destruction — and subsequently found to contain personal data — can constitute such a breach. The Data Protection Board of India, operationalised by MeitY under rules notified in 2025, has the authority to investigate and adjudicate such complaints.
Are Indian companies legally required to use CPCB-authorised e-waste recyclers?
Yes. Rule 16 of the E-Waste (Management) Rules, 2022 prohibits bulk consumers — which includes most corporate organisations — from depositing e-waste with any person not authorised by the CPCB under the Rules. Disposal through informal scrap dealers or kabadiwallas, regardless of the price offered, is a direct violation. Authorisation can be verified on the CPCB’s e-waste portal at cpcb.nic.in/e-waste/.
How long must we retain Certificates of Data Destruction and Recycling?
There is no single prescribed retention period that covers all scenarios. As a practical standard: retain Certificates of Data Destruction (CDDs) for a minimum of 3 years to align with DPDPA accountability expectations. For devices containing hazardous components (UPS batteries, CRT monitors), retain the associated hazardous waste manifests for 5 years as required under Schedule VI of the Hazardous and Other Wastes (Management & Transboundary Movement) Rules, 2016. BRSR disclosures must be auditable for at least 3 financial years following disclosure.
Does BRSR reporting require disclosure of IT e-waste disposal specifically?
SEBI’s BRSR Core framework (circular dated 12 July 2023) requires companies in the top 1,000 by market capitalisation to disclose e-waste generated and disposed of under Principle 2, Essential Indicator 2. This includes IT equipment. The disclosure requires the quantity in metric tonnes and the name of the authorised recycler. From FY 2024-25, this is a mandatory, assured disclosure — meaning it must be capable of surviving third-party verification. Disposal records from your ITAD SOP are the primary evidence base.
What is the difference between a Certificate of Data Destruction and a Certificate of Recycling?
A Certificate of Data Destruction (CDD) confirms that all data stored on a device’s storage media has been irreversibly destroyed using a defined standard (typically NIST SP 800-88 Rev. 1). It addresses your DPDPA obligation. A Certificate of Recycling (COR) confirms that the physical device — after data destruction — has been processed by a CPCB-authorised recycler in compliance with the E-Waste (Management) Rules, 2022. It addresses your environmental compliance obligation. You require both documents for every IT device disposal event; neither substitutes for the other.
Work With The National Recycling Corporation
The National Recycling Corporation is a Mumbai-headquartered, pan-India recycling and scrap trading company with a proven track record in corporate IT asset disposal for enterprises across Maharashtra, Karnataka, Delhi-NCR, Tamil Nadu, and Gujarat. We work with CPCB-authorised dismantlers and recyclers for all IT equipment categories, ensuring that every collection event generates the documentation your DPDPA, BRSR, and E-Waste Rules compliance requires.
Every disposal engagement through us includes: a serialised Certificate of Data Destruction mapped to individual device serial numbers; a Certificate of Recycling from a CPCB-authorised facility under the E-Waste (Management) Rules, 2022; a GST-compliant tax invoice with correct HSN coding; and a chain-of-custody manifest covering the full journey from your premises to the recycling facility. For organisations with bulk volumes, we offer on-site destruction events with witnessing officers, suitable for servers, storage arrays, and classified-data devices.
Our e-waste management service is structured for corporate clients who need disposal partners that understand DPDPA liability, BRSR disclosure formats, and E-Waste Rules authorisation — not just scrap value. We also support corporate e-waste donation programmes where devices are refurbished and donated to verified NGOs, with full documentation for CSR reporting. To schedule a pickup, discuss a bulk disposal programme, or receive a compliance-grade quote, contact us and our team will respond within one business day.
- Pan-India pickup coverage, including Tier-2 cities, coordinated from our Mumbai operations hub
- CPCB-authorised disposal partners for all Schedule I IT equipment categories under the E-Waste (Management) Rules, 2022
- Serialised, device-level Certificates of Data Destruction (NIST SP 800-88 Rev. 1 compliant)
- Certificates of Recycling formatted for direct insertion into BRSR Essential Indicator disclosures
- GST-compliant tax invoicing with correct HSN codes and reverse-charge handling where applicable
- Fair residual-value pricing for recoverable metals, indexed to prevailing market rates
- On-site destruction events for high-classification devices, with witnessing officer and photographic evidence
Sources and References
- CPCB E-Waste Portal — E-Waste (Management) Rules, 2022 and Authorised Recycler Registry
- Ministry of Environment, Forest and Climate Change (MoEFCC) — E-Waste Rules Notifications
- CPCB — Hazardous and Other Wastes (Management & Transboundary Movement) Rules, 2016
- Ministry of Electronics and Information Technology (MeitY) — Digital Personal Data Protection Act, 2023 and Rules
- SEBI — BRSR Core Framework, Circular dated 12 July 2023
- Bureau of Indian Standards (BIS) — IT Security and Media Sanitisation Standards
- NIST SP 800-88 Rev. 1 — Guidelines for Media Sanitisation (US NIST, adopted as global ITAD benchmark)
- i-SIGMA (formerly NAID) — NAID AAA Certification Programme for ITAD Vendors