Why a Waste Transfer Note Is Not Enough: The ITAD Chain of Custody Evidence Your Business Needs

Author Image
Tad Vaas 11 Aug 2026

Share:

When redundant laptops, servers and mobile devices leave your premises, the job is not complete because a collection vehicle has driven away.

For many organisations, the file contains a single Waste Transfer Note, a supplier invoice and perhaps a generic recycling certificate. That can prove a collection took place. It does not necessarily prove what was collected, whether data-bearing assets were handled securely, or what happened once the equipment entered the downstream supply chain.

That distinction matters. In an ITAD audit, cyber-security review, ESG assessment or waste investigation, your organisation may need to demonstrate a continuous, credible chain of custody from the moment equipment is identified for retirement through to reuse, certified data destruction or compliant treatment.

A Waste Transfer Note is an important part of the evidence trail. It is not the entire evidence trail.

What a Waste Transfer Note Does and Does Not Prove

A Waste Transfer Note records the transfer of non-hazardous waste between parties. It should describe the waste, identify the parties involved and support the duty of care process.

However, a Waste Transfer Note is usually a batch-level document. It may identify a load as mixed WEEE or redundant IT equipment without recording every laptop serial number, every storage device, each custody handover or the final treatment route.

That creates a common misconception: that having a signed note means all compliance and data-security questions have been answered. It does not.

Where equipment is hazardous, contains batteries, or requires specialist treatment, different documentation and controls may apply. Where equipment contains personal, commercial or sensitive data, waste documentation also does not replace secure erasure or destruction evidence.

Build the Evidence Trail Before Equipment Leaves Site

The strongest chain of custody starts before collection day. Do not rely on a provider to recreate an accurate record after equipment has been loaded into cages or stacked on pallets.

Start with an asset inventory that is proportionate to the risk and value of the equipment being retired. For data-bearing and higher-value assets, this should normally include:

  • Asset type, manufacturer and model.
  • Serial number or other unique identifier.
  • Site, room or department of origin.
  • Whether the asset contains a drive, removable media or embedded storage.
  • Its intended route: redeployment, resale, refurbishment, data destruction or recycling.
  • The employee or team responsible for approving its release.

This asset-level record is what connects your IT register to the collection paperwork. Without it, you may be able to prove that a pallet left site, but not which specific devices were on it.

Do Not Mix Data Security With Waste Paperwork

Data-bearing equipment creates two connected but separate obligations: manage the physical asset responsibly and make sure data cannot be recovered by an unauthorised party.

A collection note does not prove that a drive was erased, that its erasure method was appropriate, or that a failed drive was physically destroyed. Your evidence should reflect the route selected for each asset.

  • For reuse or resale: retain device-level erasure records, including the device identifier, method, outcome and any exceptions.
  • For physical destruction: retain a certificate or report that links the destroyed media to the relevant asset identifiers or batch.
  • For failed or damaged equipment: record why the asset could not be reused and how its storage media was handled.

For IT teams, this is the point at which ITAD and information security meet. A clear custody trail protects the organisation from both waste-compliance failures and a later data-breach investigation.

Record Every Handover, Not Just the Final Collection

Equipment can pass through several hands before it reaches a treatment facility: an internal IT team, a facilities team, a secure storage area, a collection crew, a logistics hub, a refurbishment partner and a recycler.

Each handover is a point where equipment can be misplaced, mixed with the wrong stream or removed without authorisation. The most useful records identify:

  • Who released the equipment and who accepted it.
  • The date, time and location of the handover.
  • The asset or container reference involved.
  • Any seal number, cage number, pallet reference or collection manifest.
  • Any discrepancy, damaged item or late addition to the load.

For a one-off collection, this might be a signed manifest with serial-number records. For a national refresh programme, it may involve barcoded containers, collection scans and a consolidated report. The method can vary; the ability to account for the equipment should not.

Verify the Provider Behind the Vehicle

A branded collection vehicle and a Waste Carrier registration are not the whole due-diligence exercise. Your business should understand who is collecting the equipment, whether they are acting as a carrier, broker or dealer, and which organisations will handle the material afterwards.

Before appointing an ITAD provider, request evidence that is relevant to the service being supplied. This may include:

  • Current waste-carrier registration and the correct legal entity name.
  • Relevant site permits, exemptions or treatment arrangements.
  • Data-security and information-management controls.
  • Details of reuse, refurbishment and recycling partners.
  • Procedures for lithium-ion batteries, damaged equipment and other higher-risk items.
  • A sample chain-of-custody, data-erasure or destruction report.

Due diligence is not about collecting a folder of logos. It is about confirming that the provider can explain the route, control the risks and produce evidence that matches the service promised.

The Downstream Question: Where Did the Equipment Actually Go?

Responsible ITAD does not end at the first collection point. Equipment may be repaired and reused, stripped for parts, processed for material recovery or passed to specialist partners.

Those outcomes can all be legitimate, but your organisation should not have to guess which route was used. A meaningful final report should distinguish, where the service allows, between assets that were reused, resold, wiped, destroyed, recycled or handled as hazardous material.

This is particularly important when reporting carbon savings, reuse outcomes or ESG performance. Avoid claims that cannot be linked to actual downstream evidence. A high-level statement that equipment was "recycled responsibly" is much weaker than a report that shows the disposition of the assets you released.

Keep Your Records Ready for an Audit

The value of a chain of custody is often realised months or years after the collection. A procurement review, customer questionnaire, insurer, cyber-security team or regulator may ask for evidence long after the original project team has moved on.

Keep the records together under a project or collection reference. Your file should normally connect:

  • The approved asset inventory and disposal decision.
  • Collection booking, manifests and signed transfer records.
  • Relevant Waste Transfer Notes and, where applicable, hazardous-waste documentation.
  • Erasure reports, destruction certificates and exception reports.
  • Final asset-disposition, reuse or recycling reports.
  • Provider due-diligence checks and contract documents.

Retention requirements can vary depending on the record type, the nation in which the activity takes place, your contractual obligations and the sensitivity of the data involved. Your internal retention policy should reflect those requirements rather than treating every certificate as a disposable attachment.

The ITAD Chain of Custody Checklist

  • Inventory data-bearing and higher-value equipment before collection.
  • Assign a clear disposal route to each asset or asset group.
  • Secure devices in controlled storage while they await collection.
  • Record handovers with manifests, signatures and container references.
  • Check the legal entity, carrier registration and downstream arrangements of your provider.
  • Obtain device-level erasure or destruction evidence where data is involved.
  • Retain final disposition reports, not just initial transfer paperwork.
  • Store the complete evidence set under an auditable project reference.

Make Collection the Start of the Record, Not the End

Good ITAD is not measured by how quickly old equipment disappears from an office or server room. It is measured by whether you can account for it, protect the data it contained and evidence its final outcome.

A Waste Transfer Note remains an important compliance document. But it should sit within a wider chain of custody that gives your organisation confidence at every stage, from internal sign-off to final reuse, destruction or recycling.

TFix helps organisations plan secure IT decommissioning, maintain auditable collection records, protect data-bearing assets and arrange compliant WEEE recycling and asset recovery.

Further Guidance

For official guidance, see the Waste Duty of Care Code of Practice and GOV.UK guidance on disposing of business waste.

Ready to act on this?

Book a free ITAD assessment, compare your destruction options, or review provider-selection guidance before choosing a partner.