Patient data is special category data under UK GDPR. That raises the standard of evidence you need when a device leaves the building — and lowers your tolerance for a supplier who cannot produce it.
Health data is classified as special category data under UK GDPR, which means processing it carries additional conditions and a breach carries heavier consequences. A retired workstation from a clinical area may hold patient identifiable data in cached files, local profiles, imaging exports or a database client that was never supposed to store anything locally.
The practical implication is simple: for healthcare organisations, the deliverable is not the recycling. It is the evidence. Being able to state, eighteen months later, exactly what happened to a specific asset tag is the thing that protects you.
NHS organisations and suppliers handling NHS data complete the Data Security and Protection Toolkit annually, and asset disposal sits squarely inside it. Assertions around asset management and data destruction typically require you to show that hardware is disposed of securely, that records exist, and that your supplier is competent to do the work.
We support that with documentation designed to be handed straight to an assessor:
A note on honesty in procurement: we are working toward ISO certification rather than claiming it. Our ISO 9001 and ISO 14001 audits are booked and we are awaiting the site visit; ISO 27001 follows once those are complete. A supplier who overstates their accreditation on a healthcare tender is a risk to your assurance process, not an asset to it. What we do hold today is listed in the footer and can be checked on the EA and ICO public registers in under a minute.
Desktops and laptops are handled as a matter of course. The items that routinely get missed in healthcare estates are the ones nobody thinks of as computers:
Tell us what you have, including anything you are unsure about. We are IT WEEE specialists rather than a general waste contractor, so if something falls outside what we can lawfully take we will say so plainly rather than quietly accepting it.
Healthcare sites are not offices. Collections have to work around clinical activity, infection control requirements, restricted access areas and, frequently, a lift shared with patient transfers. Practical things that help:
Smaller healthcare providers face the same data obligations as a large trust with a fraction of the resource. A practice retiring a dozen machines is still handling special category data, and still needs to evidence destruction — but rarely has anyone whose job it is to organise it.
There is no minimum collection size in our local area, and for most loads with recoverable value there is no charge. If you are a practice manager who has inherited a cupboard of old machines nobody dared throw away, that is a very normal starting point.
Tell us what you are retiring and we will give you a straight answer on cost, timing and documentation.
Book a Collection →NIST 800-88 Purge wiping, degaussing and shredding, with a certificate per device.
Learn more →Serialised audit trails and environmental data your ESG and audit teams can use.
Learn more →Unmarked, GPS-tracked vehicles collecting from offices, schools and restricted sites.
Learn more →Safeguarding and SEN data on retired kit, and a summer window that fills fast.
View →Multi-site refreshes, asset register reconciliation and ESG reporting that stands up.
View →Defensible audit trails, framework compliance and social value evidence.
View →Rack decommissioning, serial-level control and white-label work for providers.
View →Shop-floor terminals, machine control PCs and legacy drive interfaces.
View →Network hardware holding live configuration, credentials and topology.
View →Handheld fleets, vehicle-mount terminals and warehouse systems.
View →White-label capacity and licensed processing for other providers.
View →