Who this reaches: the U.S. organization with EU data
The first question is not what the GDPR requires but whether it applies — and for many U.S. organizations the answer is more often yes than they expect.
Under Article 3, the regulation applies to processing by controllers or processors established in the EU, regardless of where the processing happens, and to processing by organizations not established in the EU where it relates to offering goods or services to people in the EU or to monitoring their behaviour there. A U.S. company with an EU subsidiary, EU customers, EU employees, or EU website users may hold personal data the regulation protects — and that data lives on the same laptops, servers, and phones as everything else.
The regulation’s definitions are broad. Personal data is any information relating to an identified or identifiable natural person; processing includes storage, erasure, and destruction expressly. A drive holding EU customer records is being “processed” while it sits in a storeroom, and erasing or destroying it is itself a processing operation the regulation governs. That is the conceptual bridge from a privacy law to a disposition program: end of life is not outside the regulation; it is a processing activity inside it.
Territorial scope, the controller/processor distinction, and the interaction with UK GDPR and member-state law are fact-specific questions. This guide describes the regulation’s text at the pattern level; whether and how it applies to a particular organization is a question for counsel.
Article 5: the two principles that govern the storeroom
Everything the GDPR asks of disposition flows from two principles in its fifth article.
Storage limitation — Article 5(1)(e): personal data shall be “kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.” A retired device that still holds identifiable personal data months after the purpose ended is, on its face, data kept longer than necessary. The principle does not require destruction of the hardware; it requires that identifiable data not persist beyond need — which sanitization achieves.
Integrity and confidentiality — Article 5(1)(f): personal data shall be “processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.” A drive sold on a secondary market with recoverable data is the paradigm case of unauthorised processing enabled by a security failure at disposal.
Article 5(2) adds accountability: the controller “shall be responsible for, and be able to demonstrate compliance with” the principles. Demonstrating compliance is where disposition records — serialized certificates, chain-of-custody logs, processor contracts — stop being paperwork and become the evidence the regulation asks for.
Storage limitation says the data must not outlive its purpose; integrity and confidentiality says its disposal must not expose it; accountability says you must be able to prove both. Sanitization plus records is how a disposition program answers all three.
Article 17: the right to erasure meets the decommissioned device
The “right to be forgotten” is usually discussed as a database problem. It is also a hardware problem.
Article 17(1) gives a data subject “the right to obtain from the controller the erasure of personal data concerning him or her without undue delay” where one of the listed grounds applies — the data is no longer necessary, consent is withdrawn, the subject objects, the processing was unlawful, erasure is required by law, or the data concerns a child’s online services. Article 17(2) extends the duty where the controller has made the data public: it must take “reasonable steps to inform controllers which are processing such personal data to erase any links to, or copies or replications” of it. Article 17(3) lists exceptions, including legal obligations and public-interest grounds.
The disposition connection is practical. An erasure right is only honorable if the organization knows where the personal data is — and personal data on decommissioned equipment sitting outside the inventory is data the organization cannot erase on request because it has lost track of it. A working disposition program is, among other things, the mechanism by which an organization keeps its erasure promises for data that has left production systems. Devices retired through documented sanitization are devices on which every erasure request has, in effect, already been honored.
Article 28: the ITAD vendor as processor
An ITAD vendor that takes custody of equipment holding personal data is processing that data on the controller’s behalf. The regulation has a name and a contract for that.
Article 28(1) permits a controller to use “only processors providing sufficient guarantees to implement appropriate technical and organisational measures” — a due-diligence obligation before engagement. Article 28(3) requires processing to be governed by a contract or other legal act that sets out the subject matter, duration, nature, and purpose of the processing and the controller’s obligations and rights, and that stipulates specific terms: the processor acts only on documented instructions; ensures confidentiality commitments from its personnel; takes the Article 32 security measures; respects the conditions for engaging sub-processors; assists the controller with data-subject rights and with security and breach obligations; makes available the information necessary to demonstrate compliance and allows audits; and — the term that speaks directly to disposition — under Article 28(3)(g), “at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data.”
Read against an ITAD engagement, Article 28 is a specification for the contract: documented instructions (which devices, which sanitization method, which downstream), confidentiality of the vendor’s staff, security measures, control over sub-processors (the vendor’s own downstream recyclers and transport partners), audit rights, breach-assistance duties, and deletion at end of service with evidence. Most of those terms already appear in a well-drafted ITAD master agreement under other names; Article 28 makes them mandatory where EU personal data is involved.
Under Article 28 an ITAD vendor handling EU personal data is a processor: due diligence before, a written contract with the enumerated terms during, and deletion-or-return with evidence at the end. The certificate of sanitization is how 28(3)(g) gets satisfied for hardware.
Article 32: security appropriate to the risk
The GDPR’s security article is deliberately technology-neutral, which means the burden of choosing the right measures — and justifying them — is on the organization.
Article 32(1) requires controllers and processors to “implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk,” taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing. It then names examples “as appropriate,” the first of which is “the pseudonymisation and encryption of personal data.” Article 32(2) directs attention to the risks presented by processing, “in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.”
Two disposition readings follow. First, encryption at rest is the regulation’s own named example of an appropriate measure — and it is also the pre-condition that makes cryptographic erase a valid purge technique under NIST SP 800-88 Rev. 2. A fleet encrypted from deployment is both more secure in service and more cheaply sanitizable at retirement; the two frameworks reward the same decision. Second, “state of the art” is a moving standard. A sanitization method the storage industry’s own standard (IEEE 2883) considers inadequate for flash media — software overwriting alone — is difficult to defend as appropriate to the risk in 2026.
Because the article is neutral, supervisory authorities and courts look to recognized standards to judge appropriateness. Sanitization to NIST SP 800-88 Rev. 2 with IEEE 2883 techniques, documented per device, is the most widely recognized way to demonstrate that disposal met the “state of the art.” The regulation does not name those standards; it creates the need for them.
Articles 33–34: the 72-hour clock, started by a drive
A retired device with recoverable personal data that leaves your control is a personal data breach under the regulation’s definition, and the clock starts when you become aware of it.
Article 4(12) defines a personal data breach as a breach of security leading to “the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.” Article 33(1) requires the controller to notify the competent supervisory authority “without undue delay and, where feasible, not later than 72 hours after having become aware of it,” unless the breach is unlikely to result in a risk to individuals’ rights and freedoms; late notifications must be accompanied by reasons for the delay. Article 33(2) requires a processor to notify the controller “without undue delay” after becoming aware of a breach. Article 34 requires communication to affected data subjects “without undue delay” where the breach is likely to result in a high risk to them, with exceptions including where the data was rendered unintelligible — for example, by encryption.
Disposition breaches have a specific timing problem: the device may have left months or years earlier, and awareness arrives when it surfaces. The 72 hours run from awareness, but the investigation has to reconstruct what the device held and when it left — which is only possible if the disposition records exist. And the Article 34 exception is the encryption argument again: a lost encrypted drive whose key was never exposed may fall outside the individual-notification duty because the data was unintelligible. The processor duty under 33(2) is the contractual bridge: an ITAD vendor that discovers a custody failure must tell the controller promptly, and the Article 28 contract should say how.
When a retired device surfaces, the questions a supervisory authority asks — what did it hold, when did it leave your control, was it encrypted, what did the vendor certify — are answerable only from the disposition file. The file is the difference between a 72-hour notification and a 72-hour scramble.
Article 83: the fine tiers, and the consistency behind them
The numbers are famous. The structure behind them is more useful.
Article 83 authorizes administrative fines in two tiers. Infringements of, among others, the controller and processor obligations in Articles 25 to 39 — which include the Article 28 processor terms and the Article 32 security duty — are subject to fines “up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.” Infringements of the basic principles in Article 5, the data-subject rights in Articles 12 to 22 (including erasure), and certain other provisions are subject to fines “up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.”
Article 83(2) lists what authorities weigh in setting a fine: the nature, gravity, and duration of the infringement; whether it was intentional or negligent; actions taken to mitigate damage; the degree of responsibility “taking into account technical and organisational measures implemented”; previous infringements; cooperation; the categories of data affected; how the authority learned of it; and adherence to approved codes of conduct or certification mechanisms. Nearly every factor rewards the same thing: a documented program with recognized measures, cooperative disclosure, and evidence. A disposition breach from a fleet with no sanitization records and no processor contract scores badly on the factors that matter; the same breach from a documented program with a certified vendor and encrypted media is a different case.
Two tiers — €10M/2% and €20M/4% of worldwide turnover, whichever is higher — and a factor list that turns on whether you had appropriate measures and can show them. The regulation punishes the absence of a program more than the occurrence of an incident.
The ITAD program, GDPR edition
Nothing in the regulation asks for a technique. Everything in it asks for an outcome you can demonstrate. This is how a disposition program demonstrates it.
- Know which devices hold EU personal data. Storage limitation and erasure both presuppose you can locate the data. Asset records that tag devices by data category are the foundation.
- Retire on a schedule, not on discovery. Identifiable data on a device past its purpose is data kept longer than necessary. A standing disposition cadence is a storage-limitation control.
- Encrypt from deployment. Article 32 names it; Article 34 rewards it; NIST 800-88 Rev. 2 makes cryptographic erase a valid purge because of it. One decision, three benefits.
- Contract your ITAD vendor as a processor. Due diligence before; a written agreement with the Article 28(3) terms, including sub-processor control over the vendor’s downstream, audit rights, breach-assistance, and deletion-or-return with evidence at end of service.
- Sanitize to a recognized standard. NIST SP 800-88 Rev. 2 with IEEE 2883 techniques, verified and validated, is how “state of the art” and “appropriate to the risk” are demonstrated for hardware.
- Keep per-device records. Serialized certificates of sanitization and chain-of-custody logs are the Article 5(2) accountability evidence, the Article 28(3)(g) deletion evidence, and the Article 33 investigation file, in one document set.
- Wire the breach clock into the contract. The vendor’s duty to notify you without undue delay (Article 33(2)) should be an explicit contractual obligation with a named contact and a defined timeline, so your 72 hours are not spent locating theirs.
- Map the exceptions. Legal retention obligations (Article 17(3)) can require keeping data that a storage-limitation reading would otherwise retire; records management, not IT, owns that call — the same role NIST 800-88 Rev. 2 names.
CyberCrunch operates as a disposition vendor under written agreements, sanitizes to NIST SP 800-88 Rev. 2 with IEEE 2883 technique selection, and documents every device with serialized certificates and downstream disclosures under R2v3 — the evidence set a controller needs to demonstrate its disposal met the regulation’s outcomes. Whether a specific engagement requires Article 28 terms is a determination for the controller and its counsel; the vendor due-diligence guide covers what to verify on the way there.
Locate, schedule, encrypt, contract as processor, sanitize to standard, record per device, wire the breach clock, respect retention. That is a GDPR-defensible disposition program — and, not by coincidence, a good one.
Frequently asked questions
Does the GDPR specify how to destroy data on retired hardware?
No. The regulation is technology-neutral. It requires outcomes: personal data kept no longer than necessary (Article 5(1)(e)), processed with appropriate security including protection against unauthorised access (Article 5(1)(f)), erased when the grounds in Article 17 apply, and protected by measures appropriate to the risk under Article 32, which names encryption as an example. Organizations demonstrate they met those outcomes by sanitizing to recognized standards, in practice NIST SP 800-88 Rev. 2 with IEEE 2883 techniques, and by keeping records that show it.
Is an ITAD vendor a 'processor' under the GDPR?
Where the vendor takes custody of equipment holding EU personal data and handles it on the controller's behalf, it is processing that data, and Article 28 governs the relationship. That means due diligence before engagement, a written contract containing the terms Article 28(3) enumerates, including deletion or return of personal data at the end of services with deletion of existing copies, control over sub-processors such as the vendor's downstream recyclers, audit rights, and assistance with breach obligations. Whether a particular engagement meets the definition is a legal determination for the controller and its counsel.
Is a lost or improperly wiped retired drive a GDPR breach?
If it held personal data and its loss or exposure amounts to unauthorised disclosure of or access to that data, it meets the Article 4(12) definition of a personal data breach. The controller must then notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals, and must inform affected individuals where the risk is high, with an exception where the data was rendered unintelligible, for example by encryption whose key was not compromised.
What are the maximum GDPR fines for a disposal-related failure?
Article 83 sets two tiers. Failures of the controller and processor obligations in Articles 25 to 39, which include the Article 28 processor terms and the Article 32 security duty, carry fines up to 10 million euros or 2 percent of total worldwide annual turnover, whichever is higher. Failures of the Article 5 principles or of data-subject rights such as erasure carry fines up to 20 million euros or 4 percent, whichever is higher. Authorities weigh factors including the technical and organisational measures implemented, mitigation, cooperation, and prior infringements.
Does the GDPR apply to a U.S. company's retired equipment?
It can. Under Article 3 the regulation applies to organizations established in the EU regardless of where processing occurs, and to organizations outside the EU whose processing relates to offering goods or services to people in the EU or monitoring their behaviour there. A U.S. organization with EU customers, employees, subsidiaries, or website users may hold EU personal data on the same devices as everything else, and erasing or destroying that data at retirement is itself processing the regulation governs. Applicability to a specific organization is a question for counsel.
Disposition documented to the standard the regulation points toward
CyberCrunch sanitizes to NIST SP 800-88 Rev. 2 with IEEE 2883 technique selection, operates under written agreements, and documents every device with serialized certificates and R2v3 downstream disclosures — the record set that demonstrates disposal met the GDPR’s outcomes.
This guide is informational only and reflects the text of Regulation (EU) 2016/679 as published in the Official Journal of the European Union (EUR-Lex), as of September 2026, together with the referenced NIST and IEEE standards. Quotations are from the regulation’s English text. It describes provisions at the pattern level and does not address UK GDPR, member-state implementing law, supervisory-authority guidance, or the facts of any organization; it is not legal advice, creates no attorney-client relationship, and should not be relied on to determine whether or how the regulation applies to a particular organization or engagement — consult qualified counsel. Laws and guidance change. CyberCrunch practice statements reflect its procedures at the time of publication and are not a representation of any customer’s compliance.