Jakub Wolanski, Founder, CirculaTech
Keeping device disposal in-house looks free because there’s no vendor invoice — but it isn’t. The real cost shows up as unmanaged data-breach exposure, IT staff time spent on a non-core task, and resale value that’s written off instead of recovered. Outsourcing to a certified ITAD partner usually costs less overall, not more.
Why does in-house device disposal look cheaper than it is?
The comparison most organisations make is narrow: “a vendor charges a fee, our own IT team does it for nothing.” That framing misses three costs that don’t show up on an invoice. First, staff time — someone in IT has to physically wipe, box and route every retired device, and that’s time not spent on higher-value work. Second, foregone resale value — devices wiped with a factory reset and put in a cupboard or handed to a general waste contractor generate zero return, when graded, certified-erased hardware has real resale value. Third, and largest, is unmanaged risk: if something goes wrong with in-house data sanitisation, the organisation carries that exposure directly, with no certificate, no audit trail, and no one else in the chain of accountability.
How big is the data-breach risk from device disposal specifically?
It’s not a hypothetical. The Office of the Australian Information Commissioner recorded 1,205 notifiable data breaches in the 2025 calendar year — the highest total since the scheme began in 2018, and an 8% increase on 2024’s already-elevated 1,112. The majority were attributable to malicious or criminal activity, but human error and process gaps — including inadequate data sanitisation — remain a recurring, documented cause category in OAIC reporting. A retired laptop or phone that leaves the building without verified erasure is exactly the kind of gap that shows up in these figures after the fact, when it’s too late to fix.
This is precisely the exposure that Australian Privacy Principle 11 is designed to close — entities holding personal information must take reasonable steps to destroy or de-identify it once it’s no longer needed, and “we assumed IT handled it” is not a defensible position if a device surfaces later with recoverable data. See Security & Compliance for how a certified, documented process addresses that obligation directly.
What does “reasonable steps” actually require that in-house processes often miss?
Three things separate a defensible disposal process from an informal one: software-based erasure certified against recognised standards (not just a factory reset, which doesn’t guarantee unrecoverable data on every device type), a signed, auditable certificate per device rather than a batch assumption, and a documented chain of custody from the point a device leaves a desk to the point it’s confirmed wiped. In-house teams can technically do all three, but in practice it competes for time against core IT work and is the first thing that slips when priorities are tight — which is exactly when the risk crystallises.
What’s the actual cost comparison between in-house and outsourced?
Outsourced disposal through a certified ITAD partner is often structured so the resale value of graded devices offsets or fully covers the service — CirculaTech’s model, for example, is built so clients receive no invoice across a three-year exclusivity term, funded entirely by device resale value rather than billed as a cost. Compare that to the in-house path: no resale value captured (devices are typically written down to zero rather than graded for resale), ongoing IT staff time, and full liability retained if erasure isn’t provably compliant. On a like-for-like basis, outsourcing frequently comes out ahead on cost as well as risk — it isn’t a trade-off between “cheaper but riskier” and “safer but pricier.”
What should IT and procurement leaders actually ask before deciding?
Before defaulting to “we’ll just handle it internally,” it’s worth quantifying three things: current IT staff hours spent on device disposal per year, what devices are currently doing at end of life (landfill, generic recycler, storage cupboard, or genuine resale), and whether the organisation could produce a certificate of erasure for a specific device if asked during an audit or after an incident. If any of those answers is uncomfortable, that’s the signal to evaluate an outsourced, certified alternative rather than assume the in-house path is the safe default. Choosing an ITAD Provider in Australia covers exactly what to evaluate once that conversation starts.
Frequently Asked Questions
Is in-house device disposal actually against Privacy Act requirements?
Not automatically — but Australian Privacy Principle 11 requires “reasonable steps” to destroy or de-identify personal information, and an informal in-house process without certified erasure, audit trail, or documented chain of custody is difficult to defend as reasonable if a breach or audit occurs.
Is a factory reset enough to make a device safe to dispose of?
Not reliably across all device and storage types. Certified erasure software follows recognised standards (such as those Blancco is certified against, including NIST 800-88) and produces a verifiable, device-level certificate — a factory reset does neither.
Does outsourcing device disposal cost more than doing it in-house?
Often less overall once resale value, staff time and risk are accounted for. Many outsourced models — including CirculaTech’s — are structured so recovered resale value offsets the service rather than being billed as a straight cost.
What happens to devices that are outsourced instead of handled in-house?
Each device is graded, certified-erased with a signed certificate, and routed to its highest-value next life — redeployment, resale, or recycling only if neither applies — rather than defaulting straight to disposal.
How do we know an outsourced provider is actually compliant, not just claiming to be?
Ask for the specific standards their erasure software is certified against, whether you receive a certificate per device (not a batch summary), and how chain of custody is documented from collection to completion.