
Schools and universities are sitting on more retired technology than most people realize. Chromebooks from a pandemic-era 1:1 program. Laptops that aged out of a lease cycle. Servers that got replaced during a network upgrade two years ago. The devices pile up fast, and the disposal question gets pushed to the back of the queue until something forces it forward.
Equip Recycling works with educational institutions at both the K-12 and higher education levels to handle this process correctly, from chain-of-custody documentation through R2v3-certified downstream processing.
Call (866) 966-4574
The people dealing with this problem are usually district technology directors, university IT managers, and procurement or compliance officers who realize a storage room full of old devices represents both a liability and a missed budget opportunity. According to the Consortium for School Networking (CoSN), the average K-12 district refreshes student devices every three to four years. (Source: CoSN Annual EdTech Leadership Survey, cosn.org) For a mid-sized district deploying 5,000 devices, that means thousands of end-of-life units entering the disposition stream every cycle.
At the university level, the volume is higher and the data sensitivity is often greater. Research institutions handle data governed by FERPA, HIPAA, and in some cases federal research security requirements. The stakes are meaningfully different from a typical corporate device refresh.
At Equip Recycling, the institutions we work with most often are mid-to-large school districts, community colleges, and research universities managing recurring refresh cycles. Technology directors tend to initiate the process, but compliance officers and CFOs are usually involved by the time the project gets approved, especially when FERPA documentation is part of the requirement.
FERPA is the starting point. The Family Educational Rights and Privacy Act requires that schools protect personally identifiable student information and ensure it is destroyed in a way that prevents unauthorized recovery. That requirement does not expire when a device is powered off and put in a closet.
Any data-bearing device that passed through a student or staff member’s hands carries potential exposure: Chromebooks with cached login credentials, tablets with locally stored assignments, laptops with administrative files. Deleting files and reimaging devices is not sufficient on its own. Without NIST 800-88 Rev. 1-compliant sanitization, data can still be forensically recovered from storage media.
Community colleges and universities that conduct federally funded research face additional requirements under the Cybersecurity Maturity Model Certification (CMMC) framework if they handle Controlled Unclassified Information (CUI). For those institutions, the method of data sanitization is not optional. It is auditable.
“We have walked into university decommissioning projects where nobody could tell us which hard drives had been wiped and which ones had not. That is a FERPA problem waiting to happen. Serialized reporting at the asset level is the only way to close that gap.”
— Equip Recycling, ITAD Sustainability Specialists
Call (866) 966-4574
These two terms get used interchangeably, and that creates real confusion when schools are trying to plan a device retirement.
IT Asset Disposition (ITAD) is a broader process. It includes evaluating devices for residual resale value, refurbishing usable units, recovering materials, and handling end-of-life equipment. When a district retires a batch of three-year-old Chromebooks, some of those devices may still carry resale value on the secondary market. An ITAD provider identifies that, processes the devices, and can return value recovery proceeds to offset disposal costs or fund new equipment.
End-of-life recycling handles what is left: devices with no market value, broken units, obsolete hardware. R2v3-certified recycling ensures those materials are processed through vetted downstream vendors rather than shipped to jurisdictions with weak environmental enforcement.
The practical implication for schools is this: using a certified ITAD provider can return funds to a constrained budget. Using a generic recycler does not, and may still leave you without the data destruction documentation you need for a FERPA audit.
This depends on the device type, and getting it wrong creates liability.
For most functional laptops and Chromebooks, software-based overwriting to NIST 800-88 Rev. 1 Clear or Purge standards is appropriate. The key word is functional. A device with a failed operating system, locked bootloader, or inaccessible storage media cannot be software-wiped. Physical destruction of the storage component is the only defensible method for those units.
Some institutions still reference DoD 5220.22-M as their internal standard. That is a legacy document. While it is not wrong to reference, NIST 800-88 Rev. 1 is the current federal guideline and should be the baseline your ITAD Provider provider is working from.
For tablets and smartphones issued to students, the same logic applies. If the device is accessible and functional, NIST-compliant wiping is appropriate. If it is not, it gets physically destroyed. Either way, you need a Certificate of Destruction (CoD) tied to the individual device serial number or IMEI, not a blanket batch certificate. Batch certificates do not protect you in a compliance review.
Here is what a properly managed disposition project looks like from intake to final documentation.
Not all recyclers can support the documentation requirements that FERPA and institutional audits demand. Here is what matters.
| Certification | What It Covers |
|---|---|
| R2v3 | Responsible Recycling standard; governs downstream vendor accountability |
| NAID AAA | Data destruction operations; covers on-site and off-site destruction workflows |
| ISO 14001 | Environmental management systems; verifies operational environmental compliance |
| e-Stewards | Alternative to R2v3; similar downstream accountability framework |
A vendor who hands you a Certificate of Recycling and calls it done has not provided data destruction documentation. Those are two separate records with two different compliance functions. Make sure your vendor knows the difference and can produce both.
Yes, and this is the part most school technology directors do not think to ask about.
Devices retired at the three-year mark often retain secondary market value, especially if they were commercial-grade or have components in demand. Chromebooks in certain configurations, in particular, maintain resale value. The proceeds from remarketing refurbished units can offset the cost of new device procurement, reduce net refresh costs, or be reinvested in other IT infrastructure.
This is the ITAD component. It is distinct from recycling, and it only works if your provider has the refurbishment capacity and secondary market relationships to realize that value on your behalf.
Equip Recycling provides ITAD services and certified e-waste recycling for educational institutions, including K-12 districts and higher education campuses. The process covers serialized asset intake, NIST 800-88-compliant data sanitization, individual Certificates of Destruction, R2v3-certified materials processing, and full documentation for FERPA compliance and institutional audits.
If your district or university has a device retirement project coming up, or if you are managing a storage room full of devices that have not been touched in two years, call (866) 966-4574 to talk through what your situation requires.
Schedule a Pickup today!
Ready to close your ESG documentation gap?