Proudly Canadian flag Canadian

Solutions

Ready to optimize your mobile device strategy?

Speak with a mobility expert to find the right solution for your organization.

Contact us

Products

Ready to optimize your mobile device strategy?

Speak with a mobility expert to find the right solution for your organization.

Contact us

Industries

Ready to optimize your mobile device strategy?

Speak with a mobility expert to find the right solution for your organization.

Contact us

Company

What ITAD services actually include and how engagements work in Canada

A professional ITAD engagement covers far more than wiping hard drives and recycling hardware. It’s a documented chain of custody from the moment a device leaves a user’s hands to the moment you hold a certificate proving the data is gone and the asset is accounted for. Most organisations searching for ITAD services for the first time are surprised by the scope. This post walks through what’s included, how the logistics work in Canada, and what the process looks like from your side of the table.

The problem with retired devices sitting in storage

Picture a locked storage cage in a distribution centre. Three hundred retired Zebra TC72 scanners stacked on metal shelving, each one still containing Wi-Fi credentials, cached user logins, and application data from the last shift it was used on. Nobody has touched them in 18 months. Nobody has a plan.

This is the most common starting point for an ITAD conversation.

The devices aren’t actively causing problems, yet. They’re not taking up bandwidth or generating help desk tickets. But every one of them represents unresolved risk: data that should have been destroyed, assets that should have been reconciled, and compliance obligations that don’t expire just because the device is out of service.

Most organisations underestimate how much sensitive data remains on retired devices. A 2023 study by Blancco Technology Group found that 42% of used drives purchased on secondary markets still contained residual data (files, credentials, and personal information) that should have been erased before the device left organisational control. For an IT director in Canada, this means every retired device without certified erasure is a potential data breach sitting in a closet.

The environmental dimension compounds the problem. According to the Global E-waste Monitor 2024, global e-waste reached 62 million tonnes in 2022, with only 22.3% formally collected and recycled. Canadian organisations face increasing regulatory and reputational scrutiny over how they handle end-of-life electronics, as the response “we gave it to a recycler” no longer satisfies auditors or procurement teams asking for documentation.

When we onboard a new client for decommissioning, the first thing we do is a physical inventory of what’s actually in that storage cage—and it almost never matches what’s in their asset management system. Devices that were “returned” six months ago are missing. Devices that were supposed to be destroyed are sitting in a box labelled “keep.” The gap between what an organisation thinks it has and what it actually has is where risk lives.

Why a factory reset is not data erasure

A factory reset returns a device to its default software state. It does not overwrite the storage media.

On Android-based enterprise devices—Zebra scanners, Honeywell handhelds, Samsung rugged tablets—a factory reset may leave recoverable data in flash memory, cached credentials in secure storage partitions, and enterprise Wi-Fi certificates intact. The device looks clean. The screen shows a fresh setup wizard. But forensic tools can still extract what was there before.

The distinction matters because it’s a regulatory one, not just a technical one. NIST Special Publication 800-88 Rev. 1 defines three levels of media sanitisation—Clear, Purge, and Destroy—and specifies that a factory reset alone does not meet the “Purge” standard required for devices leaving organisational control. For Canadian organisations subject to PIPEDA or provincial privacy legislation, using factory reset as your decommissioning method means you cannot demonstrate regulatory compliance if challenged.

We’ve seen organisations that factory-reset 1,000 devices and then shipped them to a recycler without any documentation. When their auditor asked for proof of data erasure, they had nothing—because a factory reset doesn’t generate a per-device erasure certificate. The recycler certainly didn’t provide one. That gap is the difference between compliance and a reportable incident.

What certified data erasure actually means

NIST 800-88 establishes three sanitisation tiers. Clear uses logical techniques (overwriting) to protect against simple recovery methods—appropriate for devices staying within organisational control. Purge uses stronger techniques to make data infeasible to recover even with advanced forensic tools—the minimum standard for devices leaving your organisation. Destroy renders the device physically unusable through shredding, incineration, or degaussing.

The process itself matters less to your auditor than the certificate it generates. Certified data erasure produces a per-device record: serial number, sanitisation method, timestamp, and verification result. That certificate is the deliverable. Without it, erasure is unverifiable—and unverifiable erasure is the same as no erasure in a regulatory context.

What professional ITAD services include—scope of a typical engagement

A professional ITAD engagement in Canada typically covers six phases, each with its own deliverables and documentation. Understanding these phases is the fastest way to evaluate whether a provider is offering a complete service or cutting corners.

Phase What You Receive
Reverse Logistics Secure collection from distributed locations, tracked shipping, tamper-evident packaging
Inventory Reconciliation Serial number verification against your asset database, discrepancy reporting
Certified Data Erasure NIST 800-88 Purge-level sanitisation with per-device certificates
Physical Destruction Shredding or degaussing for devices requiring destruction, with witnessed documentation
Environmental Compliance Certified recycling or remarketing through licensed processors
Chain-of-Custody Documentation Complete audit package from pickup through final disposition

Each phase addresses a specific failure mode that organisations encounter when they try to handle ITAD internally or hand devices to an unqualified recycler.

Reverse logistics—getting devices from the field to the facility

For a national retailer with 400 locations, collecting retired scanners isn’t a shipping problem, it’s a project management problem. You need pre-labelled tamper-evident packaging at every site, a pickup schedule coordinated with store managers who have other priorities, and tracking from the moment a device leaves a store shelf to the moment it arrives at the processing facility.

Most IT teams don’t have the bandwidth to run that alongside their day jobs. The devices sit in back rooms, accumulating.

Professional ITAD providers handle the logistics infrastructure: packaging kits shipped to each location, carrier coordination across provinces, and real-time tracking that shows you exactly where every device is in transit. The goal is to remove every operational burden from your team except saying “yes, these devices are ready for pickup.”

Inventory reconciliation and asset verification

Every device received is logged against your asset database—serial numbers, model numbers, condition, accessories present. This is where the ITAD provider catches discrepancies.

We frequently find that 5–10% of devices in a decommissioning batch don’t match the client’s records. Sometimes a device was swapped in the field and never updated in the system. Sometimes a device that was reported as “lost” shows up in a box from a remote site. Sometimes accessories are missing, or a device arrives with undocumented damage that affects its residual value.

Reconciliation is where you clean up your asset database—and it’s a step that most organisations skip when they try to handle ITAD internally. They ship devices to a recycler and never confirm what actually arrived. Six months later, when someone asks about a specific serial number, there’s no record of what happened to it.

The documentation gap that starts here follows you into every subsequent audit.

The next question most IT directors ask is what happens after the devices are verified—specifically, how the data erasure process works and what documentation you’ll actually receive at the end.

Certified data erasure (NIST 800-88)

The erasure process itself is straightforward: software writes random data patterns across the entire storage media, then verifies the write was successful. For rugged enterprise devices—Zebra scanners, Honeywell handhelds, Samsung tablets—this typically takes 15–30 minutes per device depending on storage capacity.

What matters is what comes out the other end. Each device generates an individual certificate: serial number, make, model, sanitisation method applied, timestamp, and verification result. That certificate is timestamped and stored in a database you can query years later when an auditor asks what happened to a specific asset.

The certificate is the deliverable your compliance officer cares about. The erasure itself is invisible—you can’t watch electrons being overwritten. But the certificate is proof you can hand to an auditor, attach to an incident response file, or reference during a procurement review.

Physical destruction when required

Some devices can’t be software-erased. Damaged storage media, devices with hardware failures that prevent boot-up, or assets that handled classified government data may require physical destruction—shredding, crushing, or degaussing that renders the storage media physically unrecoverable.

Physical destruction generates its own documentation: a certificate of destruction noting the device serial number, destruction method, date, and often the name of the witness present. For government organisations handling Protected B data or higher, witnessed destruction with photographic documentation is sometimes a contractual requirement.

The decision between erasure and destruction is usually made during the inventory reconciliation phase. Devices that boot normally go to software erasure. Devices that don’t, or those that fall under stricter data handling requirements, go to destruction.

Environmental compliance and responsible recycling

After data is erased, the device still exists. What happens next depends on its condition and residual value.

Devices with market value—relatively recent models in good working condition—can be remarketed through certified resale channels. The proceeds either offset the ITAD service cost or return to the client, depending on the contract structure.

Devices without resale value go to certified e-waste recyclers. Canadian provincial regulations vary: Ontario’s Resource Recovery and Circular Economy Act, BC’s Recycling Regulation, Alberta’s Electronics Recycling Program. A professional ITAD provider handles compliance across jurisdictions, so you’re not tracking which provincial rules apply to which shipment.

The environmental documentation becomes part of your audit package—proof that devices were handled through licensed processors, not dumped in a landfill or shipped overseas to unregulated facilities. For organisations with sustainability reporting requirements or ESG commitments, this documentation matters beyond regulatory compliance. If you’re building a sustainable IT asset disposition strategy, the environmental trail is part of the story you tell stakeholders.

Chain-of-custody documentation and certificates

This is the deliverable that makes the entire engagement auditable.

A complete documentation package typically includes: manifest of all devices received (with serial numbers matched against your original shipment), per-device data erasure certificates, certificates of destruction (where applicable), environmental compliance records showing downstream handling, and a final asset disposition report summarising the entire engagement.

This package is what you hand to your auditor, your compliance officer, or your board when they ask how retired devices were handled. It closes the loop on assets that would otherwise exist in a documentation void—devices that left your control but have no record of what happened next.

How ITAD engagements actually work—the logistics from your side

Most IT directors expect ITAD to be a procurement headache—multiple vendors, complex contracts, weeks of coordination. In practice, a well-run engagement requires one scoping conversation, one logistics plan, and then the provider handles everything until you receive your documentation package.

The scoping conversation is where the engagement is won or lost. A good ITAD provider will ask you how many devices, what types, where they’re located, what data classification they carry, and what regulatory frameworks apply. They’ll want to know whether devices are centralised or scattered across dozens of locations, whether you have an accurate asset register or need reconciliation, and what your timeline looks like.

If a provider doesn’t ask about data classification or regulatory requirements in the first conversation, that tells you something about their process.

After scoping, the provider sends packaging materials to your locations, coordinates pickup schedules, and tracks devices through processing. You receive status updates as devices arrive at the facility, move through erasure or destruction, and generate documentation. The final deliverable is your audit package—and at that point, the devices are no longer your problem.

Pricing structures—what to expect

ITAD pricing in Canada typically follows one of three models, and the right one depends on your fleet size, device types, and how much residual value your hardware carries.

Per-device pricing charges a flat fee for each device processed—typically covering logistics, erasure, documentation, and recycling. This model is straightforward for budgeting but doesn’t account for the value recovery potential of newer devices.

Project-based pricing covers the entire engagement as a fixed cost, regardless of device count. This works well for one-time cleanouts where the scope is well-defined upfront.

Asset-recovery offset models apply the residual value of your devices against the service cost. Organisations with large fleets of relatively recent devices—say, Zebra TC52 scanners that are two years old—are often surprised to learn that the remarketing value can partially or fully offset the ITAD service cost.

Conversely, a batch of 10-year-old consumer-grade tablets with swollen batteries will cost more to process because there’s no recovery value and the environmental handling is more complex.

What happens when ITAD is handled poorly, or not at all

We’ve seen situations where healthcare organisations discovered that retired tablets containing patient scheduling data had been sold on secondary marketplaces without data erasure. The devices had been handed to a local recycler who promised to “take care of it.” There was no contract, no erasure certificate, and no chain of custody. The organisation was obligated to report the incident under PHIPA.

Scenarios like this aren’t rare. They’re the predictable outcome of treating device retirement as a disposal problem rather than a compliance obligation.

Under PIPEDA, the Office of the Privacy Commissioner can refer matters to the Federal Court, which can award damages—and organisations are required to report breaches that pose a “real risk of significant harm.” For an IT director, this means a missing erasure certificate on a single retired device could trigger a mandatory breach notification. The cost of that notification—legal review, communications, reputational damage—far exceeds the cost of professional ITAD.

How Canadian organisations are approaching device retirement

There’s no single “right” model for ITAD—but there is a clear maturity curve.

Organisations that manage a few dozen devices a year can often handle disposition internally with the right tools and documentation. Once you’re managing hundreds or thousands of devices across multiple locations, the logistics and compliance burden typically exceeds what an internal IT team can sustain alongside their other responsibilities.

Some organisations use local recyclers—convenient, but usually lacking certified erasure capabilities or chain-of-custody documentation. Some engage national ITAD providers for standalone decommissioning projects. And some bundle decommissioning into broader managed mobility services engagements, treating device retirement as the final phase of a continuous lifecycle rather than a separate procurement exercise.

What to look for in a Canadian ITAD company

Not every company that calls itself an ITAD provider delivers the same scope. Before you engage anyone, ask these five questions—the answers will tell you whether you’re working with a professional operation or a recycler with a website:

  1. Do they provide per-device certified data erasure to NIST 800-88 Purge standard?
  2. Do they offer full chain-of-custody documentation from pickup to final disposition?
  3. Are their facilities and operations in Canada? (Data leaving the country may become subject to foreign jurisdiction.)
  4. Can they handle reverse logistics across multiple provinces?
  5. Do they reconcile returned devices against your asset database and report discrepancies?

If the answer to any of these is vague, conditional, or “we work with a partner who handles that”, you’re not getting full-scope ITAD.

Where secure decommissioning fits within managed mobility

For organisations managing large mobile device fleets—rugged scanners, handhelds, and tablets deployed across warehouses, retail floors, and vehicles—device retirement isn’t a one-time project. It’s a recurring operational requirement that happens every time a device reaches end of life, gets damaged beyond repair, or is replaced during a fleet refresh.

That’s where the standalone ITAD model starts to show its limits. Running a separate procurement process, engaging a separate vendor, and managing a separate documentation trail every time you retire a batch of devices creates administrative overhead that compounds over time.

PiiComm’s Secure Decommissioning service covers the full scope described in this post: reverse logistics from distributed locations across Canada, inventory reconciliation, certified data erasure to NIST 800-88, physical destruction when required, environmental compliance, and chain-of-custody documentation—all executed in Canadian facilities by Canadian staff.

For organisations already managing devices through PiiComm’s lifecycle management services, decommissioning integrates into the existing asset record. Devices tracked in the AIM portal from deployment through retirement create a closed-loop audit trail—no documentation gaps, no orphaned serial numbers, no devices that “fell through the cracks.”

PiiComm has handled secure destruction of highly sensitive government devices with full chain-of-custody documentation and witnessed destruction protocols. For federal government and Quebec-based organisations, bilingual (English/French) service delivery and documentation is standard—not an add-on.

If you’re evaluating ITAD options and want to understand how decommissioning works as part of a managed lifecycle—rather than a standalone project—learn more about PiiComm’s approach to secure decommissioning.

For organisations ready to scope a specific decommissioning engagement, connect with a mobility specialist to discuss your device retirement requirements.

Frequently asked questions about ITAD services in Canada

What do ITAD services include?

A professional ITAD engagement covers six phases: reverse logistics, inventory reconciliation, certified data erasure, physical destruction (when required), environmental recycling or remarketing, and chain-of-custody documentation. The deliverable is an auditable record proving every device was accounted for and every byte of data was destroyed to NIST 800-88 standards.

Is a factory reset the same as certified data erasure?

No. A factory reset restores default software settings but does not overwrite storage media to NIST 800-88 standards. Recoverable data frequently remains on factory-reset devices—a 2023 Blancco study found residual data on 42% of used drives purchased on secondary markets.

What Canadian regulations apply to retiring devices that contain personal data?

PIPEDA requires organisations to report breaches involving personal information that create a “real risk of significant harm.” A retired device with unwiped personal data that leaves organisational control could constitute a reportable breach. Provincial laws like Ontario’s PHIPA and Quebec’s Law 25 add additional obligations for healthcare and private-sector organisations respectively.

How much do ITAD services cost in Canada?

Pricing typically follows one of three models: per-device fee, project-based pricing, or asset-recovery offset where the residual value of devices reduces the service cost. The right model depends on fleet size, device types, data sensitivity, and geographic distribution. Devices with market value can partially or fully offset service costs.

How do I know if my organisation needs professional ITAD?

If you’re managing more than a few dozen devices, if devices are distributed across multiple locations, if devices contain personal or regulated data, or if you cannot produce a per-device erasure certificate for every retired device—you likely need professional ITAD. The tipping point is usually when an auditor asks for documentation you don’t have.

What’s the difference between an ITAD company and an e-waste recycler?

An e-waste recycler handles the environmental processing of electronics. A professional ITAD company handles the entire disposition process—including data erasure, chain-of-custody documentation, asset reconciliation, and regulatory compliance—before any recycling or remarketing occurs. Not all recyclers provide certified data erasure or auditable documentation.

Can ITAD services handle rugged enterprise devices like barcode scanners and handheld computers?

Yes, but not all providers have experience with rugged enterprise mobility devices. Zebra scanners, Honeywell handhelds, and vehicle-mounted computers have different storage architectures and erasure requirements than consumer laptops. Choose a provider with demonstrated experience in enterprise mobility hardware, not just traditional IT assets.

The devices sitting in your storage cage aren’t going to dispose of themselves. Every month they sit there, your asset register drifts further from reality, your compliance exposure grows, and the residual value of those devices declines. The question isn’t whether you need an ITAD process—it’s whether the one you have (or don’t have) can survive scrutiny when someone asks for documentation you should have generated months ago.