ITAD data destruction checklist: three questions before servers are wiped

An ITAD data destruction checklist for a routine hardware refresh should confirm three things with the client's owner before any drive is wiped: whether the old device holds history that exists nowhere else, who owns that history, and whether it can still be exported. New hardware goes live on schedule; only destruction waits for sign-off.

Why an ITAD checklist needs three owner questions

A standard ITAD checklist proves that data was destroyed. It does not ask whether anything on the device should have been kept first. Add three questions, answered by the client's owner or an executive they name, before the destruction step: is there unique history here, who owns it, and can it still be exported?

In a routine refresh most data has already moved. The risk sits in what did not: a file server with project folders nobody migrated, the SQL box behind a retired job-costing app, an old on-premises mail server, or a backup appliance holding the only copy of a ticketing system the client stopped paying for. Once those drives are shredded, that history is gone for good.

This matters beyond compliance. Some companies license years of operational records to AI developers for a one-time payment, and deleted archives are on the list of red flags that end a data licensing review. A client can lose an option it never knew it had because a wipe ran a week early.

This checklist is for refreshes, lease returns and server consolidations at a business that keeps operating. If the client is closing, use the IT wind-down checklist, which covers custody, approvals and records for a shutdown.

The rule: deploy on schedule, destroy on sign-off

The refresh never waits for these answers. New servers, storage and laptops go live on the planned date. Only the last step, sanitizing or shredding the retired media, waits for the owner's written decision, and the media stay in locked, logged custody under your normal chain-of-custody process until then.

Your role stays narrow. You ask the questions and record the answers. You never copy, sample, upload or describe client records for licensing, and any retention copy happens only on the client's written instruction as ordinary IT work.

The checklist

Before the refresh is scheduled

  • Pull every data-bearing device from the RMM asset register: servers, NAS and SAN storage, backup appliances, tapes, phone-system storage and retired laptops still in the closet.
  • Note the oldest record date and main contents for each device.
  • Compare against migration logs and mark what moved to the new platform and was verified, and what did not.
  • Ask the client's leadership whether any legal hold, open dispute or audit request covers these records.
  • Put an owner sign-off step on the project plan between cutover and the ITAD pickup.

The three owner questions

  • Unique history: does this device hold records that exist nowhere else, such as unmigrated file shares, a legacy application database or the only backup of a retired system?
  • Ownership: did the client create these records, or do they belong to its customers, a former parent company, a vendor or a contractor?
  • Exportable: can the records still be opened and exported, with working admin credentials, encryption keys, application licenses and a readable format?

Ownership is the question most likely to need the client's lawyer. The US Copyright Office's circular on works made for hire explains that material an employee prepares within the scope of the job is generally owned by the employer, while work from contractors may not be unless it was assigned in a signed writing. Customer contracts can add their own limits. This is general information, not legal, tax or financial advice. The client should confirm ownership questions with its own counsel.

For clients that want to work through rights system by system, the ownership and permission questions for company system records go further.

Sign-off and custody

  • The owner records keep, assess or destroy for each device, in writing, in the client's own records as well as your PSA ticket.
  • Any retention copy has a named owner, a storage location and a review date set by the client.
  • Retired media stay in locked, logged custody until sign-off.
  • The certificate of destruction lists serial numbers that match the asset register.

Your role boundary

  • Nobody on your team has copied, sampled, uploaded or described client records for licensing.
  • Any introduction goes to the owner, and you have told them you may earn a referral reward.

How to use the results

Devices whose data was migrated and verified clear quickly. The table covers the ones that need a real decision.

ResultWhat it meansNext action
Everything migrated and verifiedNothing unique on the deviceDestroy on schedule and file the certificate
Unique history, client-owned, exportableAn archive worth a decisionOwner chooses retention; if the company fits the baseline, offer an introduction
Unique history, ownership unclearA rights question, not an IT questionOwner checks contracts with counsel before keeping or licensing anything
Unique history, cannot be exportedLocked in an expired app or behind lost credentialsOwner decides whether recovery is worth the cost; otherwise destroy
Legal hold or open disputeDestruction may not be allowedHold the media until counsel releases it
Owner says destroyDecision madeDestroy, document and close the ticket

Which refresh clients are worth a licensing conversation

The three questions are good hygiene for every client. The licensing conversation is for a narrower group: US companies with 50+ full-time employees at peak (contractors excluded), several years of documented operations, rights to license their records and an owner, CEO, CFO or authorized representative willing to explore it. The full baseline is on who qualifies.

Look first at long-tenured clients whose refresh roadmap you already review at QBRs, especially those that ran many systems over the years. The network opportunity finder helps you think through which clients to start with, and the guide to additional revenue streams for MSPs shows where introductions sit beside your other services. If clients are asking about AI projects, MSP AI services explains why data inventories often lead to these talks.

What to say to the owner

Ask during refresh planning, not on pickup day.

Red flags: destroy without a licensing conversation

When any of these apply, follow the client's retention decision and leave licensing out of it:

  • The records belong to the client's own customers, as at an agency or outsourcer, and they have not consented.
  • The device mainly holds consumer personal data or patient records with no licensing basis or de-identification.
  • The company never reached 50+ full-time employees at peak (contractors excluded).
  • The records were already licensed for AI training, or were generated with AI to sell them.
  • Nobody can open or export the data without rebuilding a dead system.
  • The owner rules out granting an exclusive AI-training license for a set period.

These are licensing red flags, not retention advice. The client may still need to keep records for legal, tax or contractual reasons.

How a referral reward works for an MSP

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 cumulative per referred company. Payment comes only after the buyer pays and SourceX receives its fee; a conversation, a qualified lead or a signed agreement alone does not trigger it, and no reward is guaranteed. The reward is a share of SourceX's fee, so it never reduces what your client receives. Check your MSA and any client policy on third-party introductions, and disclose the relationship up front.

Next step

Add the three owner questions and the sign-off step to your next refresh project template. When a client fits, register as a partner and make the introduction, or see the wider picture on referral opportunities for managed service providers.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does asking these questions delay the hardware refresh?

No. New hardware is deployed on the planned date. Only the final sanitization or shredding of the retired media waits for the owner's written decision, and the media stay in locked, logged custody until then. Most devices clear the questions quickly because their data was migrated and verified; only the few holding unique history need a real decision.

Should the MSP take a copy of an old server before wiping it, just in case?

Not on your own initiative. An unrequested copy is more client data to secure and may conflict with the client's retention policy. If the owner wants an archive, treat it as a written client instruction with a named owner, storage location and review date. You never copy, sample or share records for licensing purposes.

What if the old server only holds backups of data already in the cloud?

Check whether the cloud copy is complete before assuming the backup adds nothing. Backups sometimes hold history that was trimmed during migration, such as closed projects, departed users' mailboxes or prior-year accounting files. If the live system has the full history and the backup holds nothing extra, the device passes the unique-history question and can be destroyed on schedule.

Can a client whose old servers were already wiped still be introduced?

Possibly, if the history survives elsewhere. Many companies keep years of records in cloud email, chat, CRM, accounting and helpdesk systems that a hardware refresh never touched. What was destroyed cannot be recovered, and lost archives weaken a licensing review, so check which systems still hold several years of history before making any introduction.

Who at the client should answer the three questions?

The owner or an executive with authority over company records, such as the CEO, CFO or someone they name in writing. An office manager or internal IT lead can gather the facts, but the keep-or-destroy decision and any licensing conversation belong to an authorized sponsor, because only they can approve how company records are kept or used.

Does this checklist replace the ITAD vendor's certificate of destruction?

No. The certificate still proves that the media were sanitized or destroyed. The three questions sit before that step and record why destruction was approved. Keep both in the client's records: the owner's decision for each device and the certificate with serial numbers that match the asset register.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment