HomeKnowledge HubCodes & Schemes › ADISA ICT Asset Recovery Certification 8.0

UK GDPR certification scheme (Art. 42) · Codes & Schemes

ADISA ICT Asset Recovery Standard 8.0 — the ICO-approved certification for IT asset disposal

ICO-approved 19 July 2021DUAA-updated criteria approved 18 March 2026UKAS 23831

When a disposal contractor says it is “ICO-certified”, this is usually what is meant: certification by ADISA Certification Ltd against criteria the ICO has approved under Article 42(5) UK GDPR for processors and sub-processors that sanitise and dispose of IT hardware.

Published by
ADISA Certification Ltd, Harpenden — scheme owner and UKAS-accredited certification body (accreditation 23831); criteria approved by the ICO.
Type
UK GDPR certification scheme criteria (Art. 42(5)).
Versions and language
Standard 8.0 v4.0, Part 1 and Part 2 Criteria (ICO-CSC/003:2 and ICO-CSC/004:3), approved 18 March 2026 to reflect the Data (Use and Access) Act 2025. The earlier v3.1/v3.2 documents (ICO-CSC/003:1 and ICO-CSC/004:2), approved 19 July 2021, remain valid until all certified organisations have transitioned to v4.0. English.
Jurisdiction
United Kingdom.
Primary audience
IT asset disposal providers; DPOs and procurement choosing a disposal processor.
Topic tags
data sanitisation · IT asset disposal · Art. 28 processors · Art. 32 · storage limitation
Availability
Criteria PDFs are free on the ICO register; certification is paid.

Why it matters

Disposal is an Article 28 relationship like any other, and this is the one place in UK GDPR where a sector has an ICO-approved yardstick for the processor’s controls. The Part 2 criteria are what the certification body audits; the ICO register also links ADISA’s register of certified companies, which is the check to run before relying on a contractor’s claim.

The March 2026 update matters for two reasons. It is, as at 15 September 2026, the only entry on the ICO’s certification register carrying criteria rewritten for the Data (Use and Access) Act 2025 (we read all five register entries); and the register makes the transition explicit — the 2021 criteria stay valid only until certified organisations have moved to v4.0, so a certificate should say which version it was issued against, and that is a fair question to put to a contractor.

For what “sanitised” means technically, NIST SP 800-88 Rev. 2 is the reference most policies cite, and ISO/IEC 21964 (DIN 66399) is the physical-destruction standard behind shredding levels — both in Standards & Frameworks. UK-only: ICO approval carries no status in the EU. The register entry also carries the ICO’s own notice that approvals on the register remain valid but are under review and may be subject to change following the Data (Use and Access) Act 2025.

A curated reference entry maintained by VulaPri. We summarise and link to the original; we do not reproduce or host it. Listed since 5 July 2026 · last verified 15 September 2026 — facts verified against the ICO certification schemes register (entry dated 13 July 2026, read 11 September 2026; the other four register entries read 11–15 September 2026). Suggest a correction.