How to securely dispose of old devices and documents

Securely dispose of old laptops, phones, drives, copiers and paper records in 2026: verified backups, real wiping, destruction and a dated register.

Most Australian businesses retire laptops, phones and filing cabinets every year, and most of those devices leave the building still holding customer records, payroll data and email. Secure disposal is not an IT project — it is a seven-step routine any office manager can run in an afternoon: inventory, verified backup, account closure, real wiping, destruction where wiping is impossible, paper and copier handling, and a dated register.

Key takeaways

Who this is for

This is for owners, office managers and MSPs at Australian organisations with roughly 5 to 200 staff. You do not need an IT department: every step uses built-in device features, a shredder and a spreadsheet, and the whole routine fits inside an afternoon once a quarter.

Why this matters

The Australian Signals Directorate treats phones, tablets and laptops as core things to protect, and its device security guidance assumes a device will eventually be lost, stolen or retired. Disposal is the retirement case, and it is the one most businesses prepare for least.

The legal driver is quieter but firmer. Under the Privacy Act, organisations holding personal information must destroy or de-identify it once it is no longer needed. A laptop sold online with a working customer list is a breach waiting for the wrong buyer; a cross-cut shredded filing cabinet is not. And the reputational cost of a leaked client list travels faster than any fine.

Step 1: List what holds data

Walk the office — and ask remote staff about their homes — and list every device that ever held company information: laptops, desktops, phones, tablets, external drives, USB sticks, cameras, voice recorders, network gear with saved credentials, and the office copier. Include the devices in cupboards. The drawer of old iPhones is usually the largest single data store in a small business, and nobody has managed it since 2023.

Expected outcome: a written inventory with an owner and a planned date for each item.

Step 2: Back up, then verify

Before anything is wiped, confirm what needs to survive. Copy files to your approved backup location, then open a sample and check it. The ACSC's guidance on backing up files and devices treats the backup as the copy you restore from when data is lost — a backup you have never opened is a hope, not a backup. Only after verification does wiping begin.

Step 3: Close the accounts, not just the device

A device is more than its files. Remove it from your device management console, revoke its email and app sessions, deregister it from multi-factor authentication, and reassign any per-seat software licences attached to it. This is the same logic as offboarding a departing employee: access, not hardware, is the asset. If your offboarding checklist already covers accounts, reuse it here — the steps are identical.

Step 4: Wipe properly

For phones and tablets, the built-in factory reset on an encrypted device is adequate: modern iOS and Android devices encrypt everything, so the reset destroys the encryption key and the data with it.

For laptops and desktops:

Do not rely on deleting files or emptying the recycle bin. Standard deletion removes the index, not the data — the files sit on the drive until something overwrites them.

Step 5: Destroy what cannot be wiped

Drives that fail mid-wipe, drives from machines with unknown histories, and drives that held financial or health records should be destroyed rather than resold: professional destruction or degaussing, with a certificate. Reputable Australian e-waste recyclers issue destruction certificates — keep them with your register. An encrypted, fully wiped drive can be recycled safely; a half-wiped drive cannot be trusted at all.

Step 6: Handle paper and the machines that copy it

Step 7: Record it

Write one dated line per item: what it was, when it left, how it was wiped or destroyed, who approved it, and the certificate reference where one exists. When a cyber insurer, an auditor or a client's procurement team asks how you dispose of data-bearing devices in 2026, the register is the answer — and it takes minutes to maintain if you write it at the time instead of reconstructing it later.

What to avoid

FAQ

What is secure device disposal? A documented routine that backs up, wipes or destroys data-bearing devices and paper records before they leave your control, and records each action with a date and owner.

Can I just delete the files and sell the laptop? No. File deletion removes the index, not the data. Use the operating system's full erase function, or remove the drive and destroy it separately.

Do phones need special treatment? Just the built-in factory reset, on a device that is encrypted — which all recent iPhones and Android phones are. Sign out of work apps and remove them from your management console first.

What about devices that will not turn on? Treat the drive as unwipeable: pull it if you can, and send it for professional destruction with a certificate rather than reselling the machine.

Is a strip-cut shredder good enough? For junk mail, possibly. For anything with names, financials or client details, use a cross-cut shredder or a bonded shredding service.

How do we dispose of the office copier? Check the manufacturer's data sanitisation procedure before it is returned or sold — copier hard drives store every scanned and copied document. Some lease companies handle it; ask for the evidence.

What records should we keep? A dated register line per item plus destruction certificates where issued. Insurers and auditors increasingly ask for disposal evidence, and it costs minutes to maintain.

One last thing

The cheapest audit of your disposal routine costs nothing: look in the stationery cupboard. If retired phones and old drives sit in a drawer "just in case", they are the oldest and least-managed data store in the business — and step one of next quarter's routine.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.