Compliance

It is important to consider compliance through each stage of the reusing IT for Good process, whether you are undertaking processes in-house or with a partner. Think about what your end-to-end will look like, making sure you consider every step in the process. For example, will you need to securely store the devices? Do you have a secure area where you can limit who has access? How will you ensure secure data wiping and refurbishment processes?

Data wiping

Our research has shown that one of the biggest challenges is overcoming risk aversion in data and information security. If you decide to outsource the work of data wiping and refurbishment, this risk is transferred and will provide reassurance that your organisation is compliant and your reputation will be preserved. Make sure your partner has the necessary accreditations and software to undertake data wiping securely [link to partnerships page].

Wiping or replacing hard drives can be done in-house but you must ensure that you are compliant with government guidance: 

Products for undertaking the data wiping process can be free of charge, or may incur a cost. You should make sure that any such product meets the suitable standards, such as:

  • NIST standards: 800-88 Standard for Media Sanitisation
  • IEEE 2883-2022 – Standard for sanitising storage

ADISA undertake assessment of products suitable for data wiping, you can find a list of compliant products under ‘product certification/product assurance’.

Refurbishment

We recommend that you partner with an expert organisation to carry out refurbishment of devices. When selecting a partner, ensure that they comply with: 

Disposal

If you have any devices that, after assessment, are unsuitable for reuse and must be disposed of, you are most likely to engage a waste management organisation for this. Ensure that they comply with:

Reconome

“Everyone, regardless of where or to whom they were born, deserves the chance to live a healthy life, access education, pursue a career, and discover their passion. Reconome makes this possible by securely refurbishing and rehoming surplus tech with those who need it most. As the accredited tech partner to Good Things Foundation’s National Device Bank, we meet Ministry of Defence Infosec Enhanced standards and use NIST 800-88-compliant erasure. Certified to ISO 27001 and GDPR-aligned, our turnkey process delivers peace of mind, end-to-end traceability, and measurable ESG and social impact, fully aligned with the IT Reuse for Good Charter and a fairer, greener future.