01 / THE DOCKWhat the two trucks have in common, and where it ends
Both trucks will take the pallet. Both drivers will be polite. Both companies recycle electronics in the sense that the metal eventually reaches a smelter. If the comparison stopped at the dock, the free option would win every time, and this brief would not exist.
The comparison does not stop at the dock, because the pallet is not the thing being disposed of. The pallet is a container for two other things: data, which belongs to your customers, employees, and patients and which the law says you must destroy before it leaves your control; and waste, which the law says remains your responsibility until it reaches a lawful final destination. A certified ITAD provider is built to discharge both duties and hand you the proof. A scrap recycler is built to recover metal. Those are different businesses that happen to use the same kind of truck.
This is a different question from whether free pickup is ever fair — the free-pickup brief covers the economics of who pays. This brief is about the two things that never get on the truck.
02 / SIDE BY SIDEThe four differences that matter afterward
Set the two paths next to each other on the questions that will matter in a year, and the "free" column reads very differently.
| Question | Certified ITAD provider | Non-certified free scrap pickup |
|---|---|---|
| What happens to the data? | Sanitized or destroyed to NIST SP 800-88 Rev. 2; failed devices physically destroyed; a certificate per serial number naming method and standard. The destruction operation itself is audited (NAID AAA), including unannounced. | Typically nothing, or an unverified wipe before resale. No standard named, no per-device record, no audit of the process. |
| Where does the material go? | Reusable equipment refurbished under an audited process (R2v3 Appendix C) or destroyed; commodities routed through downstream vendors the facility must qualify and monitor to final disposition (R2v3 Appendix A). | Working units resold whole, often online or to brokers; boards and drives sold onward; no obligation to know or document the next stop. |
| What paperwork comes back? | Reconciled inventory at pickup; chain-of-custody record; serialized certificate of sanitization or destruction; certificate of recycling for the remainder. | A weight ticket, sometimes a generic one-line "certificate of recycling." Nothing that identifies a device. |
| Who is legally responsible afterward? | You still are — but the certificates and chain of custody are the evidence that the duty was discharged. | You still are — with no evidence at all. |
| Is anyone checking? | Yes: i-SIGMA (NAID AAA) audits on a schedule and unannounced; a SERI-authorized certification body audits R2v3 annually; both publish directories you can verify in. | Only the state environmental agency's permit, if one is required for the operation — and it checks the yard, not your drives. |
| What does it cost? | A service, priced by model (per-device, per-pound, or revenue-share) — see the pricing brief for how the models work. | Nothing at the dock. The cost arrives later, if it arrives, as a breach, a fine, or a cleanup. |
03 / THE DATAWhy the data duty does not transfer with the equipment
The data-destruction laws are written around the organization that held the information, not around whoever ends up with the hardware. New Jersey's statute requires the business to "destroy, or arrange for the destruction of" customer records containing personal information so they are unreadable; Delaware's requires commercial entities to take reasonable steps to destroy them; Maryland's requires reasonable steps against unauthorized access when destroying them; the federal FTC Disposal Rule requires reasonable measures when disposing of consumer report information. "Arrange for the destruction" is the phrase that matters: you may hire someone to do it, but the duty is discharged by the destruction happening — and being provable — not by the equipment changing hands. The Mid-Atlantic recap collects the statutes.
Now follow a drive through each path. At a certified provider it is logged by serial at pickup, transported under seal, sanitized or destroyed under a process that an auditor has examined, and recorded on a certificate that names the method and the standard. If the drive is later found, the certificate proves it was not yours — because yours was destroyed on a documented date. At a scrap recycler the drive may be pulled and sold to a broker, left in a chassis that is resold whole, or shredded with the metal; there is no record of which, and no way to answer the question when a customer's data turns up. A 2019 Blancco/Ontrack study of used drives bought online found that 42 percent still held sensitive data, though every seller believed the drives had been wiped. Under the breach-notification laws, an unaccounted-for drive with personal information on it is not a hypothetical; it is the fact pattern those laws were written for. The breach case files collect the public examples.
04 / THE WASTEWhy the environmental liability does not transfer either
Federal hazardous-waste law has a name for the principle: cradle to grave. Under RCRA, the generator of a waste is responsible for its proper management through to final disposition, and that responsibility is not extinguished by handing the waste to a hauler. Used electronics from a business are evaluated under the commercial rules (the household exemption does not apply), and in Pennsylvania and New Jersey, covered electronics are banned from disposal outright — Pennsylvania's Covered Device Recycling Act names generators, haulers, and landfills alike as parties who can be held liable for improper disposal. If a load of your monitors is later found in an unpermitted yard, or a container of your circuit boards is stopped at a port, the question of who generated the material is answered by the pickup slip with your name on it.
This is exactly the problem the R2v3 standard was created to solve. An R2v3-certified facility must qualify every downstream vendor before shipping to it and monitor the chain to final disposition (Appendix A), must follow a hierarchy that prefers reuse over recovery over disposal, and is audited on all of it by an accredited certification body. The R2v3 field guide explains how to read the certificate. A scrap recycler may be a perfectly lawful operator — many are — but it is under no obligation to know or tell you where the boards went after the broker picked them up, and its permit covers its yard, not your liability.
05 / THE RULEA routing rule by asset type
None of this means a scrap recycler has no role. It means the pallet has to be sorted before either truck arrives, by one test: does it have storage?
- Anything with storage goes to certified ITAD. Computers, servers, and laptops (with the drives still inside — do not pull them and hand the chassis to scrap; pulled drives are the box in the closet that becomes the breach); phones and tablets; copiers and multifunction printers; network equipment; DVRs and cameras; point-of-sale terminals; external drives, tapes, and USB media. These leave under chain of custody and come back as serialized certificates.
- Material with no storage may go to a permitted scrap recycler once you have confirmed it: racks, cabling, brackets, keyboards and mice, power supplies, bare monitors (subject to the state disposal rules for CRTs and covered devices). Keep the recycler's permit and your receipt in the file.
- When in doubt, it has storage. The devices that surprise people — the copier, the desk phone, the thermostat controller, the "dumb" display with a media player inside — are where the exposure lives.
A certified ITAD provider will take the whole pallet, sort it under this rule, and return paperwork for each stream; that is usually simpler than running two vendors. But if the operations team wants to keep a scrap relationship for the metal, the rule above is how to do it without handing a breach to the scrap truck. The Vendor Due Diligence Scorecard scores any vendor you are considering for the storage-bearing stream; the certificate test is the thirty-second version of the same idea.
06 / FAQCertified ITAD vs. scrap pickup FAQ
Is it legal to give old business computers to a scrap recycler for free?
Handing equipment to a recycler is not itself unlawful, and a permitted scrap recycler can lawfully process the metal. The legal problems arise from what the arrangement fails to do: state data-destruction statutes and the FTC Disposal Rule require your organization to render personal information unreadable before disposal, breach-notification laws treat an unsanitized device that surfaces as a potential breach, and state electronics-disposal bans and RCRA hold the generator responsible for where its waste actually ends up. A free scrap pickup typically discharges none of those duties, and the organization remains responsible for all of them.
Does the scrap recycler become responsible for the data once they take the equipment?
No. Under the state data-destruction laws and the federal FTC Disposal Rule, the obligation to destroy personal information belongs to the business that held it, and it is discharged by destruction, not by transfer. If an unsanitized drive from your equipment is later found or resold with your data on it, the breach analysis under state law starts with your organization. A certified ITAD provider takes custody under a contract and a documented chain of custody and returns a serialized certificate; that certificate is what shows the duty was discharged.
What actually happens to computers at a scrap recycler?
It varies, and that is the problem: there is no audited standard to compare it to. Common patterns include whole-unit resale of working equipment online or to brokers, often without sanitization; dismantling for commodity metals with circuit boards and drives sold onward to downstream brokers; and, historically, export of unprocessed electronics. None of these is necessarily illegal for the recycler, but none produces a record of what happened to a specific serial number or the data on it. An R2v3-certified facility, by contrast, is audited on its downstream vendor qualification (Appendix A) and, if it sanitizes, on its data sanitization process (Appendix B).
What paperwork should I expect from each?
From a scrap recycler, typically a weight ticket or a receipt for the load, sometimes a generic certificate of recycling. From a certified ITAD provider, an itemized inventory reconciled at pickup, a chain-of-custody record, a certificate of sanitization or destruction listing each data-bearing device by serial number with the method and standard (NIST SP 800-88 Rev. 2), and a certificate of recycling for the remainder, backed by the provider's audited downstream. The difference is whether you can answer the question 'where is drive serial number X' a year later.
Is there anything a scrap recycler can legitimately take?
Yes, with care. Non-data-bearing material such as metal racks, cabling, brackets, and power supplies with no storage can go to a permitted scrap recycler. The trap is that many things people assume are 'just metal' contain storage: copiers, printers, phones, network gear, DVRs, and any computer chassis with the drive still inside. The safe routing rule is that anything with storage goes to certified ITAD; anything without it may go to scrap once you have confirmed that is what it is, and even then you should keep the recycler's permit and your receipt.
THE PAPERWORK IS THE PRODUCT
Send the whole pallet. Get back a certificate for every serial number.
CyberCrunch sorts the load under the storage rule, destroys or sanitizes every data-bearing device to NIST SP 800-88 Rev. 2 with a serialized certificate, and routes the remainder through an R2v3-audited downstream — NAID AAA certified continuously since 2012, serving the Mid-Atlantic and all 50 states.
This brief is informational only and reflects publicly available sources as of September 2026 — the FTC Disposal Rule (16 CFR Part 682), N.J.S.A. 56:8-162, 6 Del. C. Chapter 50C, Md. Code, Com. Law § 14-3502, RCRA generator provisions, Pennsylvania's Covered Device Recycling Act, New Jersey's Electronic Waste Management Act, SERI's R2v3 standard and i-SIGMA's NAID AAA program as publicly described, and the 2019 Blancco/Ontrack used-drive study — described at the pattern level. It describes categories of vendors generally and does not characterize any specific company. It is not legal or environmental-compliance advice, does not create an attorney-client relationship, and states no pricing; confirm current requirements with qualified counsel before acting. CyberCrunch credential statements reflect certificates held at the time of publication.