Arc ITAD

Arc ITAD Secure IT asset disposition, data destruction, and electronics recovery for businesses, schools, healthcare, and public sector organizations.

Most companies treat retired IT as a disposal cost. Often that is backwards.When laptops, servers, phones, or drives com...
08/17/2026

Most companies treat retired IT as a disposal cost. Often that is backwards.

When laptops, servers, phones, or drives come out of service, that hardware can carry recoverable value and unmanaged data risk at the same time. E-waste recycling only handles one side of it. It gets equipment out the door and meets environmental rules. It doesn't prove the data was destroyed, and it doesn't recover what a device is still worth.

That is the line between recycling and ITAD.

A rough guide to where the value sits, by age:

- Under 3 years. Strong resale value with modern hardware holding real secondary-market prices
- 3 to 5 years. Still worth recovering, usually the sweet spot.
- 5 to 10 years. May carry enough value to offset the cost of secure removal, but often nets toward zero.
- Over 10 years. Little to no resale value and handled as compliant recycling.

Not every retired asset has resale value. The problem is that most organizations never check before it leaves the building.

Before a refresh, an office move, or a data center decommission, two questions are worth asking. What is this equipment still worth, and can we prove the data on it was destroyed.

arcITAD handles both. Secure sanitization to NIST SP 800-88, documented chain of custody, and value recovery on whatever still has a market.

Every engagement we close ends with a page like this.It is the companion summary that sits on top of the full closeout w...
08/04/2026

Every engagement we close ends with a page like this.

It is the companion summary that sits on top of the full closeout workbook. One reconciled view of the lot: assets received, data-bearing count, assets sanitized and passed, drives destroyed, exceptions logged. Beneath it is the line-by-line record, every unit by model and serial or IMEI, available on request.

The settlement sits on the same page. Value recovered, fees, and the net payment of record, reconciled against the same asset count shown above it. It is one count and one reconciliation, and both sides of the page tie out.

That's what a closeout summary is for. A year from now, when an auditor or an insurer asks, the proof is one page, already assembled.

The figures shown here are illustrative, the format is what we send.

Mergers, acquisitions, and divestitures are data disposition events.When two companies combine, duplicate systems get re...
07/31/2026

Mergers, acquisitions, and divestitures are data disposition events.

When two companies combine, duplicate systems get retired quickly. Two email platforms become one. Two data centers consolidate. The losing side of each decision becomes hardware that still holds records.

In both cases the org chart changes faster than the hardware does. A laptop that had a clear owner on Friday can belong to a merged entity, a carve-out, or no one in particular by Monday. The data on it didn't move, but the accountability for it certainly did.

Transitional service agreements cover a lot of this on paper. What they often leave vague is who sanitizes the retired fleet, to what standard, and who keeps the record that it happened.

The clean version is boring. Before the deal closes, name the disposition owner for the retired and duplicated assets, set the sanitization standard, and file the documentation with the transaction records. It's a small line item against the size of the deal, and it's the one the other side's counsel can ask about later.

Ask a healthcare team where their device disposal rules live and most point to the BAA. The BAA assigns responsibility. ...
07/28/2026

Ask a healthcare team where their device disposal rules live and most point to the BAA. The BAA assigns responsibility. The specifics are in the HIPAA Security Rule.

The Device and Media Controls standard (45 CFR 164.310(d)) names four disposal specifications. Two are required: procedures for the final disposition of ePHI media, and removing ePHI before a device is reused. Two are addressable: a record of where the hardware moved and who was responsible, and a retrievable backup before equipment moves.

Addressable does not mean optional. It means implement it, use an equivalent, or document why not. Most programs cover the required two and skip the rest. The addressable two are where an auditor finds the gap.

Government IT retires devices on a refresh cycle. Government records come off a different clock.Every state sets a recor...
07/24/2026

Government IT retires devices on a refresh cycle. Government records come off a different clock.

Every state sets a records retention schedule, and it applies to records in any form, including the ones on a retired laptop. It sets the earliest a record may be destroyed. Destroying it outside that schedule can be a violation, and in some states a criminal one.

A device pulled from service can still hold records the agency is required to keep, and records it is required to destroy on a documented date. Wiping the drive does not settle either one.

Disposition for a public agency has to answer to both clocks.

Chain of custody is a sequence of handoffs. Every handoff is a place the record can break.Between pickup and the moment ...
07/21/2026

Chain of custody is a sequence of handoffs. Every handoff is a place the record can break.

Between pickup and the moment the data is destroyed, a retired asset changes hands several times. It is counted and loaded at pickup, held by one custodian in transit, checked in on arrival, and logged into processing. Each one is a transfer of custody, and each one needs a signature and a timestamp.

When a handoff has neither, the chain has a gap. A gap means you can no longer say where the devices were the whole time.

At any moment between pickup and destruction, someone should be able to say who had the assets, and prove it.

A state audit of a Washington school district found that a physical inventory could not account for 986 of its 6,714 Chr...
07/16/2026

A state audit of a Washington school district found that a physical inventory could not account for 986 of its 6,714 Chromebooks. Auditors then asked staff to produce 20 specific devices. Nine were found.

A device nobody can locate never reaches a processing facility, which means it is never sanitized and never appears on a certificate. The device is still somewhere, and so is the student data on it.

Reconciliation is a data-security control, and it belongs at the start of a refresh.

You can't sanitize what you can't find.

Source: Washington State Auditor's Office, 2026.

Most security controls have evidence behind them. Access logs, patch reports, MFA enrollment, backup tests. Disposal is ...
07/14/2026

Most security controls have evidence behind them. Access logs, patch reports, MFA enrollment, backup tests. Disposal is usually the exception.

Five questions worth being able to answer about a fleet you have already retired:

Where the devices physically went?
Who held custody in between?
What standard the data was removed to?
Which downstream vendors received them?
Could produce that record today?

arcITAD builds that record as part of disposition.

Retired devices usually get boxed and stacked in a closet until there is time to deal with them. Their recoverable value...
06/25/2026

Retired devices usually get boxed and stacked in a closet until there is time to deal with them. Their recoverable value does not wait. A current laptop or Chromebook has a real resale market the month it comes off the floor. Six months later it is closer to obsolete and worth less, and a year later there may be little left to recover.

The timing of disposition is a financial decision. The value that offsets the cost of compliant handling is highest right after retirement. A structured program captures it while it still exists.

The compliance work is the same whenever the devices leave. The recoverable value depends on when that is.

Most equipment in disposition now is encrypted by default. A modern laptop, phone, or tablet stores everything as cipher...
06/17/2026

Most equipment in disposition now is encrypted by default. A modern laptop, phone, or tablet stores everything as ciphertext, scrambled by a key in the hardware. Sanitizing it does not always mean overwriting the data block by block. Destroy the key the device used, and the contents become permanently unreadable. NIST SP 800-88 recognizes this as cryptographic erase. The catch is verification: it only holds if the device was encrypting from first use and the key destruction can be confirmed. Modern device tooling like Phonecheck, with its MacCheck, WinCheck, and Chromecheck modules, runs this kind of erase at the device level and logs the result.

Address

Warminster, PA
18974

Alerts

Be the first to know and let us send you an email when Arc ITAD posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share