ADISA ICT Asset Recovery Standard 8.0 — the ICO-approved certification for IT asset disposal
When a disposal contractor says it is “ICO-certified”, this is usually what is meant: certification by ADISA Certification Ltd against criteria the ICO has approved under Article 42(5) UK GDPR for processors and sub-processors that sanitise and dispose of IT hardware.
- Published by
- ADISA Certification Ltd, Harpenden — scheme owner and UKAS-accredited certification body (accreditation 23831); criteria approved by the ICO.
- Type
- UK GDPR certification scheme criteria (Art. 42(5)).
- Versions and language
- Standard 8.0 v4.0, Part 1 and Part 2 Criteria (ICO-CSC/003:2 and ICO-CSC/004:3), approved 18 March 2026 to reflect the Data (Use and Access) Act 2025. The earlier v3.1/v3.2 documents (ICO-CSC/003:1 and ICO-CSC/004:2), approved 19 July 2021, remain valid until all certified organisations have transitioned to v4.0. English.
- Jurisdiction
- United Kingdom.
- Primary audience
- IT asset disposal providers; DPOs and procurement choosing a disposal processor.
- Topic tags
- data sanitisation · IT asset disposal · Art. 28 processors · Art. 32 · storage limitation
- Availability
- Criteria PDFs are free on the ICO register; certification is paid.
Why it matters
Disposal is an Article 28 relationship like any other, and this is the one place in UK GDPR where a sector has an ICO-approved yardstick for the processor’s controls. The Part 2 criteria are what the certification body audits; the ICO register also links ADISA’s register of certified companies, which is the check to run before relying on a contractor’s claim.
The March 2026 update matters for two reasons. It is, as at 15 September 2026, the only entry on the ICO’s certification register carrying criteria rewritten for the Data (Use and Access) Act 2025 (we read all five register entries); and the register makes the transition explicit — the 2021 criteria stay valid only until certified organisations have moved to v4.0, so a certificate should say which version it was issued against, and that is a fair question to put to a contractor.
For what “sanitised” means technically, NIST SP 800-88 Rev. 2 is the reference most policies cite, and ISO/IEC 21964 (DIN 66399) is the physical-destruction standard behind shredding levels — both in Standards & Frameworks. UK-only: ICO approval carries no status in the EU. The register entry also carries the ICO’s own notice that approvals on the register remain valid but are under review and may be subject to change following the Data (Use and Access) Act 2025.
