During data center decommissioning, data-bearing assets like hard drives and servers move through multiple hands. From rack removal to staging, loading, transporting, processing, and final destruction – every step creates a potential gap in accountability.
Before we learn about where the chain-of-custody can break down, we’ll help you understand the key terms. Then we’ll further explore the asset journey to identify the key risks, required controls, and documentation at each stage.
What is Chain of Custody and Data Center Decommissioning
Data center decommissioning is the process of securely retiring a data center (or a part of it). It usually involves removing servers, hard drives, networking equipment, and other IT assets.
Chain of custody is a documented record of an equipment journey, right from the owner to another point and ultimately to destruction (or any other form of disposal). It records every movement, including who handled the asset, when and where it changed hands, and what happened to it. The purpose of the chain-of-custody proof is to keep assets traceable and accountable until they reach their final disposition.
A data center may be secure while equipment is inside the rack. But that security can weaken when assets leave it. According to research, 48% of breaches involved a third party, while 62% involved a non-malicious human element. At the same time, IBM’s 2026 Cost of a Data Breach Report estimates the global average cost of a data breach at $4.99 million, which ultimately highlights the importance of maintaining a secure chain-of-custody throughout the decommissioning process.
Where Data Security Can Break Down
Data center decommissioning service providers follow six key steps, and each stage presents potential risks to data security. Let’s take a look at how it goes on:
1. Rack
Servers, hard drives, storage devices, and other equipment are identified against the decommissioning inventory. Then, the IT assets are disconnected and removed from their racks.
What information goes in the chain of custody?
- Asset ID and serial number
- Equipment type and description
- Original rack/location
- Removal date and time
- Person or team performing the removal
- Initial custody status
Where may data security break down?
An IT asset may be incorrectly identified, overlooked, or removed without being tagged in records. In case a data-bearing device is removed from its documented inventory without being listed at this stage, it would be difficult to identify where it went, who handled it, or whether it was destroyed.
This may lead to data disclosure incidents, like 149 incidents reported by Verizon involving lost or stolen IT assets, with 122 involving confirmed data disclosure.
2. Staging
After removal, the IT equipment is moved to a designated staging area. Here, equipment is held temporarily and then sorted, counted, and prepared for its next destination. Assets are grouped according to their processing requirements. For example, devices that are intended for reuse will be separated from devices requiring data destruction.
What information goes in the chain of custody?
- Staging-area location
- Arrival date and time
- Person or team receiving the asset
- Asset count and inventory verification
- Current asset status
- Any discrepancies identified during reconciliation
Where may data security break down?
Staging often involves manual handling, sorting, and inventory reconciliation, which makes human error a potential risk.
3. Loading
Once assets are identified, sorted, and prepared for removal from the facility, they are loaded into the designated vehicle or container. Before departure, the assets are checked against the shipment inventory to confirm that the correct assets are being transferred.
What information goes in the chain of custody?
- Assets included in the shipment
- Shipment/container ID
- Loading date and time
- Origin and destination
- Person releasing custody
- Person or carrier accepting custody
- Final pre-departure inventory check
Where may data security break down?
An asset may be left behind or loaded onto the wrong container. A mismatch between the physical shipment and the inventory records can create a gap in accountability.

Photo Credit: iStockPhoto/sefa ozel
4. Transport
The assets now leave the data center and travel to the designated processing or ITAD facility, or another authorized location if the data center is being relocated. At this stage, physical custody shifts from the data center operator to a transportation provider or another authorized party.
What information goes in the chain of custody?
- Carrier or transportation provider
- Custody transfer date and time
- Shipment or tracking number
- Origin and destination
- Authorized person releasing the shipment
- Authorized person/carrier accepting custody
- Delivery confirmation
Where may data security break down?
Assets during transit may be lost, stolen, damaged, or accessed without authorization. That’s because the organization no longer controls the equipment physically, so it needs documented evidence showing who has responsibility for it and where it is supposed to be.
5. Processing
When the shipment reaches the receiving or ITAD facility, or the new location where the data center will be assembled, the assets are received and reconciled against the shipment records. Each item is routed according to its assigned processing path.
What information goes in the chain of custody?
- Date and time of receipt
- Receiving facility
- Person accepting the asset
- Asset verification against shipment records
- Processing status
- Assigned disposition or destruction method
- Any discrepancies or exceptions
Where may data security break down?
At this stage, the biggest risk is losing traceability between the physical asset and its required outcome. If the received asset is not properly identified or routed, the organization may fail to verify whether the required data destruction or disposition was completed.
6. Destruction/Disposition
This is the final stage that determines what happens to the asset. Data-bearing devices undergo secure data destruction, like hard drive destruction or an approved data-erasure process. Equipment suitable for continued use may be refurbished, resold, or go for value recovery, while other assets may be recycled or otherwise processed for final disposition.
What information goes in the chain of custody?
- Final disposition or destruction status
- Date and time completed
- Destruction method, where applicable
- Responsible party
- Asset ID/serial number confirmation
- Certificate of destruction or other supporting evidence
- Final disposition record
Where may data security break down?
The issue is that organizations cannot prove that the decided outcome actually occurred. A device marked for destruction but not destroyed may leave sensitive data exposed. This is not just a theoretical risk; instead, Australia’s OAIC reported an insecure-disposal breach that impacted 150 people in the second half of 2024.
Required Controls From Their Teams and ITAD Providers
The asset journey for data center decommissioning above highlights where control can break down. To fill those gaps, organizations should establish clear requirements for both internal teams and ITAD providers before decommissioning begins.
Require Proven Data Destruction Standards
Organizations should define the acceptable method for each data-bearing asset based on its intended outcome. Providers should adhere to recognized standards such as NIST SP 800-88 and submit evidence that the required sanitization or hard drive destruction actually occurred.
Create Exception and Escalation Protocols
Missing assets, failed sanitization, inventory discrepancies, or incomplete documentation should trigger a defined investigation process. Do not mark the asset as complete when a required control fails.
Set Ground Rules for Third-Party Partners
If an ITAD provider is involved, security requirements should be set before assets depart the facility. Contracts should mention expectations for access, transportation, data destruction, documentation, incident reporting, and final disposition.
Confirm The Final Outcome
Every IT asset should have a documented final disposition, whether it is reused, resold, recycled, or sent for secure data destruction. This way, organizations gain confidence that their data center asset disposal process ended with the outcome they intended.
Evidence IT/Compliance Teams Should Retain
After decommissioning is complete, IT and compliance teams should retain enough evidence to verify how each asset was handled and where it ended up.
Key records should include:
- Final asset inventory with asset IDs and serial numbers
- Chain-of-custody and handoff records
- Transportation and delivery records
- Data sanitization or destruction records
- Certificates of Destruction
- Final disposition records
- Exception and incident reports
- ITAD provider reports and supporting documentation
Learn more: IT Compliance and E-Waste Regulations
7 Common Mistakes During Data Center Decommissioning
Common mistakes include assuming removed assets are secure, destroying every asset by default, tracking batches instead of individual assets, overlooking human error, relying too heavily on ITAD providers, and more. Let’s explore key issues that can occur during data decommissioning:
1. Treating ‘Removed’ As ‘Secured’
An asset leaving the rack doesn’t mean it is free from security risks. Instead, organizations need controls that continue until the asset reaches its verified final disposition.
2. Skipping Asset Inventory
If an asset is missing and no one knows about it, it may not receive the security protection it needs, which can increase the risk of a data breach. Recent industry findings reveal that only 48% of people were confident that their organization had a complete and updated list of all its hardware, software, and data. This means organizations may overlook data-bearing devices and struggle to reconcile equipment with its disposition.
3. Destroying Every Asset by Default
Although physical destruction or wiping seems like the easiest and safest option, it is not always the appropriate one. Why? Because Blancco’s research reported that up to 47% of data center assets were still operational when they were decommissioned.
4. Tracking Assets in Batches Instead of Individually
A record showing that “250 drives were sent for destruction” does not provide the same level of accountability as linking each drive to its serial number and final outcome. This is important when even one device goes missing or fails sanitization.
5. Trusting Local Data Destruction Partners
Hiring unverified data destruction service providers can leave sensitive information exposed even after equipment has been retired. This illustrates the importance of carefully vetting decommissioning providers and trusting a qualified team like Hummingbird International for offsite or onsite destruction.
Learn More: On-Site vs. Off-Site Data Destruction: Which Pickup Option Works Best?
6. Overlooking Human Error
Decommissioning should never rely solely on employees remembering every step. 84% of surveyed security and IT professionals in 2024 considered accidental data leaks by employees a high-risk area.
7. Failing to Address Operational Dependencies
Shutting down a system without checking what other applications or services depend on it can cause unexpected problems. McCraw Law Group’s 2026 data center decommissioning case study shows how this can be done successfully. The company mapped system dependencies and migrated services in the right order to avoid unexpected outages during decommissioning.
Read More: Data Center Decommissioning Risk Assessment: 12 Things IT Teams Should Verify Before Removing Equipment
Finally
When sensitive equipment leaves a data center, trusting the right partner can make the difference. Hummingbird’s track record reflects its experience in Data Center Decommissioning and IT Asset Disposal. The company reports more than 1,200 pickups, while its ITAD service holds a 4.7-star rating on Gartner Peer Insights.
Frequently Asked Questions
Have doubts? Check the FAQs below to resolve your queries:
What happens if a data-holding device is not properly decommissioned?
If a data-holding device is not properly decommissioned, sensitive data can remain exposed to unauthorized access and breaches. Organizations in healthcare, finance, and government can also face fines for failing to meet data protection requirements. For example, CVS Pharmacy paid $2.25 million to settle a case involving the improper disposal of patient information.
Which devices can be decommissioned?
Most IT and data center equipment can be decommissioned, including servers, storage devices, hard drives, networking equipment, and other data-bearing assets.
Can decommissioned IT equipment be reused?
Yes, decommissioned IT equipment can be reused if it is still functional and meets business requirements. It can be redeployed, refurbished, or resold after secure data sanitization. Equipment that cannot be reused should be sent for secure destruction or certified recycling.
What happens to equipment that cannot be reused or resold?
Equipment that cannot be reused or resold is usually sent for responsible recycling or final disposition. Through ITAD, organizations can ensure data-bearing components undergo data sanitization or physical destruction, helping protect sensitive information and support responsible recycling.
Leave a Reply