GDPR and Old IT Equipment: What Schools and Offices in Wiltshire Need to Know

GDPR

Every few years, the same scenario plays out in schools and offices across Wiltshire. New laptops arrive, the old ones go into a storeroom “for now”, and a few months later somebody finally asks the obvious question: what are we actually supposed to do with all of this?

 

It’s a fair question, and the answer matters more than most people assume.

 

The Data Doesn’t Care That the Device Is Old

 

A laptop that hasn’t been switched on in a year can still hold pupil records, staff HR files, client correspondence, or financial data , exactly as it did on the day it was retired. Age doesn’t reduce the risk. Neither does sitting in a cupboard. The data is either destroyed properly, or it isn’t.

 

Under the UK GDPR, organisations that hold personal data , and that includes practically every school, engineering firm, architectural practice, and office in Wiltshire , are legally required to protect that data through its entire lifecycle, including the point at which the hardware holding it is retired. “We formatted it before it left the building” is not, on its own, a compliant position.

 

Why Schools Face a Particular Level of Risk

 

Schools are data controllers, and the data they hold is amongst the most sensitive in the UK GDPR framework: pupil records, SEND information, safeguarding notes, staff HR and payroll data. In school IT and business manager communities, the same worry comes up repeatedly , “we’ve got a stack of old laptops, can we just donate them or send them for recycling?” The honest answer is: not without certified data destruction and documentation to prove it.

 

Why Offices and Firms Are Not Exempt

 

It’s easy to assume this is mainly a schools issue, but it isn’t. Engineering firms, architectural practices, and general offices routinely hold staff records, client files, project data, and financial information on retired desktops, laptops, and servers. Under UK GDPR, the responsibility for what happens to that data sits with the organisation that held it , not with whoever eventually ends up with the old device.

 

What Compliant Disposal Actually Looks Like

 

Getting this right doesn’t need to be complicated. It comes down to two things:

 

  1. Certified destruction. Every storage device should be processed using NIST 800-88 compliant data wiping, or physically destroyed where a device can’t be wiped. This is the recognised standard the ICO expects  not a format, not a factory reset.

 

  1. Documentation. Every device processed should appear individually on a certificate of data destruction  make, model, serial number, method, and date  so there’s a clear record if anyone ever needs to see it.

 

How EcoTech IT Handles It

 

EcoTech IT provides secure data destruction and GDPR compliant data disposal for schools, multi-academy trusts, and businesses across Wiltshire, Somerset, Dorset, and Hampshire. Collections for schools are arranged around the school day , term time, holidays, or INSET days, whichever suits you best. For offices and firms, we work around your schedule too, with same-week availability in most cases.

 

Every device is either NIST 800-88 wiped or physically destroyed, and every device is listed individually on the certificate of data destruction you receive once the work is complete. It’s straightforward, it’s documented, and it’s exactly what you’d want on file if your organisation is ever asked to show how it handles end-of-life IT equipment. Learn more about Why a Certificate of Data Destruction Matters Under UK GDPR

 

Getting Started

 

If you’ve got old IT equipment sitting in a storeroom and you’re not sure what your obligations are, the simplest step is to get in touch. We’ll talk you through what’s involved, give you a straightforward quote, and arrange a collection time that works for you.

Scroll to Top