IT disposal is a form of waste electrical and electronic equipment (WEEE) and while most financial services firms have an IT disposal arrangement, not all teams consider whether they meet all compliance needs before signing a contract. That’s because there are actually two regulators to satisfy when removing WEEE from a site
The Information Commissioner’s Office (ICO) governs how client and transaction data is protected under UK’s data protection regulations, known as UK GDPR. The FCA (Financial Conduct Authority) governs the systems and controls a regulated firm has in place to manage information security risk. Both regulators care about what happens to a device once it is considered waste and it leaves the company building. Most disposal arrangements satisfy one set of regulations, usually the ICO, but not both. The organisations contracting a waste provider often don’t check whether the arrangement holds up against the other. The gap between the two goes unnoticed until someone is looking for evidence of proper removal.
Article 5(1)(f) of UK GDPR requires personal data to be processed with appropriate security, including protection against loss, destruction or damage, using appropriate technical and organisational measures. Article 5(2) goes further saying that the firm must be able to demonstrate that it has met this standard, not just assert it.
For a financial services firm, "appropriate security" is especially important. A firm holding client account details, transaction histories, or financial profiles is processing more sensitive personal data than the average business, and the security measures applied to it, including at end of life, are judged against that higher bar. The ICO's own guidance makes it clear what counts as appropriate scales with the sensitivity of the data involved.
The ICO does not name a specific destruction standard. What it requires is evidence that data was destroyed to a level appropriate to the risk. That means device-level destruction certificates referencing a recognised sanitisation framework, not a generic confirmation that "IT equipment was disposed of."
The FCA Systems and Controls (SYSC) Handbook requires firms to establish and maintain appropriate systems and controls to manage operational and information security risks. For most regulated financial services firms the relevant chapters are SYSC 4.1 (general organisational requirements) and SYSC 7.1 (risk control). Insurers fall under SYSC 13.7, which addresses the same principles in an insurance-specific context. This sits within the FCA's broader operational risk framework, and it applies whether the risk in question is a live system or a laptop sitting in a cupboard waiting to be collected.
Neither SYSC 4.1 nor SYSC 7.1 mentions IT asset disposal, destruction certificates, or sanitisation standards by name. What they require is a control framework that manages information security risk end to end, and the ability to demonstrate to a supervisor that those controls work. An IT disposal arrangement that can't produce auditable, device-level evidence of what happened to the data on a specific machine is a gap in the information security controls these chapters are designed to catch, whether or not the firm has ever been asked to prove it.
Most financial services firms have a WEEE-compliant collection route in place, and most have some form of data wiping or destruction as part of it. Where arrangements usually fall short is the paper trail that needs to accompany the physical product.
A batch confirmation that "all devices were wiped" is not satisfactory for either of the regulators. The ICO wants evidence proportionate to the sensitivity of the data. The FCA wants paperwork that is fully auditable. Both of those depend on documentation that ties a specific destruction event to a specific device, using a method that references a recognised standard, such as HMG Infosec Standard 5 Enhanced or NIST SP 800-88 Rev 2, the two frameworks that are widely used by UK data destruction providers for sanitising storage media before reuse or disposal. Neither the ICO nor the FCA mandates either standard specifically. They're the practical evidence a firm points to when asked how it meets the security obligations both regulators do specify.
WEEE compliance sits alongside all of this as a separate, simultaneous obligation. A firm still needs a waste transfer note confirming devices were collected and processed through a licensed route under the WEEE Regulations 2013. Satisfying the data destruction requirement doesn't satisfy the WEEE duty of care, and vice versa. A compliant arrangement needs to evidence both.
For a financial services firm, that means four things coming out of every disposal run: a destruction certificate for each individual device, referencing a recognised sanitisation standard; a waste transfer note confirming the WEEE route was followed; documentation specific enough to satisfy an ICO enquiry into a particular device if one ever arises; and a record that can be handed to an FCA supervisor as evidence of a working information security control, not just a description of one.
None of this needs to mean juggling multiple suppliers. A single IT disposal partner, working with a trusted provider for the destruction element, can produce documentation for both the WEEE and data destruction sides of the process from one collection.
The compliance risk in financial services IT disposal most often comes from the documentation. Most firms are already collecting devices through a licensed route and destroying the data on them but not all firms are supplying adequately detailed documents that will stand up to an audit test from two different regulators that are asking two different sets of questions.
Talk to GAP about IT asset disposal with data destruction that produces the documentation your FCA and ICO obligations both require.