Resource Recycling
  • The Latest
  • Analysis
    • All
    • Certification Scorecard
    • Industry Announcements
    • Opinion
    EPR fees are a market signal. Here’s what they’re telling you.

    EPR fees are a market signal. Here’s what they’re telling you.

    Wolframite ore, the primary ore of tungsten from Altai, Russia

    Tungsten scrap export controls draw industry attention

    Certification Scorecard — Week of April 6, 2026

    Closed Loop Partners acquires Sutter Metals, connecting electronics disposition to metals recovery

    Certification Scorecard — Week of March 30, 2026

    Industry announcements for January 2026

    Industry announcements for April 2026

    Certification scorecard – Week of March 23, 2026

    Certification Scorecard – Week of March 16, 2026

    Groups identify recovered plastics users in the Northeast

    Bale pricing for recycled plastics diverges

  • Conferences
  • Publications

    Other Topics

    Textiles
    Organics
    Packaging
    Glass
    Brand Owners

    Metals
    Technology
    Research
    Markets
    Grant Watch

    All Topics

Subscribe
No Result
View All Result
Resource Recycling
  • The Latest
  • Analysis
    • All
    • Certification Scorecard
    • Industry Announcements
    • Opinion
    EPR fees are a market signal. Here’s what they’re telling you.

    EPR fees are a market signal. Here’s what they’re telling you.

    Wolframite ore, the primary ore of tungsten from Altai, Russia

    Tungsten scrap export controls draw industry attention

    Certification Scorecard — Week of April 6, 2026

    Closed Loop Partners acquires Sutter Metals, connecting electronics disposition to metals recovery

    Certification Scorecard — Week of March 30, 2026

    Industry announcements for January 2026

    Industry announcements for April 2026

    Certification scorecard – Week of March 23, 2026

    Certification Scorecard – Week of March 16, 2026

    Groups identify recovered plastics users in the Northeast

    Bale pricing for recycled plastics diverges

  • Conferences
  • Publications

    Other Topics

    Textiles
    Organics
    Packaging
    Glass
    Brand Owners

    Metals
    Technology
    Research
    Markets
    Grant Watch

    All Topics

Subscribe
No Result
View All Result
Resource Recycling
No Result
View All Result
Home E-Scrap

ITAD firms can help avoid compliance risks

Antoinette SmithbyAntoinette Smith
November 7, 2024
in E-Scrap
ITAD firms can help avoid compliance risks

High-profile data breaches have highlighted the perils of ITAD, and until multiple companies are “put in the penalty box,” it will keep happening, industry experts said during a panel at the 2024 E-Scrap Conference. 

However, ITAD firms can take steps to help avoid risk and educate clients, the panelists said during the conference, which was held by Resource Recycling in Orlando from Sept. 30 to Oct. 2. 

In one notorious example, years of ITAD errors cost banking giant Morgan Stanley more than $163 million in penalties and fees. The legal issues stemmed from IT asset decommissioning and refresh projects the company undertook between 2016 and 2019. 

Morgan Stanley hired a moving company with no data destruction experience to decommission two U.S. data centers in 2016, and devices holding unencrypted customer data were eventually sold online. In 2019, Morgan Stanley simply lost track of dozens of devices containing customer data during an IT refresh project.

“I don’t think we’ve actually studied it as an industry and learned the lessons yet,” said Kyle Marks, founder and CEO of Retire-IT, adding that millions of dollars in fines and penalties is small change to a corporate behemoth. “Morgan Stanley eats that for breakfast.”

In the latter incident, the vendor was Arrow Electronics, “one of the most credentialed, secure powerhouses in the industry at the time,” Marks said. The incident “ran down the list of everything you could do wrong.” 

However, those failings were on the part of the client, not on the part of the ITAD, he said. “Very often ITADs or any vendor is more compliant than their client is. From any perspective, this becomes a poster child for why a client should pick you as a service provider,” he said. Morgan Stanley had chosen a vendor based on reduced costs, “and it’s coming back to bite them. That’s obviously a good message for you if you’re an ITAD.” 

Panelist Bob Johnson, principal advocate at Privata Vox, agreed: “Cheaper is not always better, in fact cheaper is probably not better. You need to be careful in the selection process.” 

The incidents were a great example of why ITAD isn’t just disposing of garbage and must be taken more seriously, Johnson said. “The client always pays for the consequences of the vendor’s mistake,” he said.

In announcing its findings, the SEC called the Morgan Stanley breaches “astonishing.” Marks said, “The only thing astonishing is that the FCC found it astonishing. Anybody who has been in this industry for any period of time understands that most clients are wildly noncompliant.” 

“When the company buys the assets and deploys them, they’re already losing track of 2-3% of assets upon deployment,” he said. “And life cycle management is a series of check-ins and check-outs, and ITAD is what I call the final checkout. Companies are lucky if they know where 85% of their assets are, but magically at the end of life, 100% of assets are accounted for.”

Certification helps avoid risks

Morgan Stanley failed to conduct the risk analysis associated with hiring third-party vendors, said panelist Jennie Gift, vice president of member services at i-SIGMA. Using a certified company would have helped with their verification process, she said, and the company is required to do a risk assessment based on working with certain vendors. Had Morgan Stanley looked at its subcontractors involved in the project beforehand, “they would have been able to see some red flags before the incident happened.”

Using certified vendors also would have avoided the miscommunications that led to the breach, including one firm assuming the downstream firm would wipe the data, and the downstream firm assuming the upstream firm had done so. “They would have had processes that they would have gone through to track all of that,” she said.

Panelist Eric Capps, director of global compliance at Iron Mountain, concurred, saying that by using proper policy and strategy, “we’re making sure that we’re not releasing control of any data-bearing device without 100% certainty that it’s safe.”

“Never assume a hard drive doesn’t have data,” he said. “We should never take anybody’s word for it.”

Johnson added that processors’ written policies and procedures are among the most overlooked areas of vulnerability. 

Top-down education

Avoiding disastrous breaches starts with education, the panelists agreed. 

“We need to educate our customers and help them understand the process of how to manage these assets and how to retire them properly,” said Gift. 

She added that having only one person at an organization understand the risks is insufficient, and client-facing staff must know the reasons behind best practices. “They’re your stewards, they’re out there talking to your customers,” and this extends the education even further.

Capps agreed, saying front-line workers have procedures to follow but aren’t always told why to follow them. Beyond that, shareholders and investors need to understand as well, he said. 

The people ITAD professionals speak to often are not very high on the decision-making ladder, added Johnson. Lower- and mid-level employees would “just as soon not be bothered with incidents, whereas someone higher in the org would understand that we can’t just let this stuff go,” he said. 

ITAD firms have to elevate the discussion up the organizational chain so chief risk officers and boards of directors understand what’s going on, “and we as an industry are not abetting this noncompliance simply by being the rug under which these missing IT assets are swept,” Johnson said. 

Companies may not understand the significance of a seemingly small issue, he added. “A missing IT asset can have more information than an entire warehouse, so if Iron Mountain couldn’t find one of those buildings, it would be a pretty big deal.” 

As a result of new SEC rules implemented at the end of 2023, entities must account for all assets even if they might not contain data, Marks said. 

Tags: Data SecurityElectronicsPolicy Now
TweetShare
Antoinette Smith

Antoinette Smith

Antoinette Smith has been at Resource Recycling Inc., since June 2024, after several years of covering commodity plastics and supply chains, with a special focus on economic impacts. She can be contacted at [email protected].

Related Posts

Oregon’s battery EPR bill officially charged for implementation

byStefanie Valentic
April 10, 2026

Oregon Governor Tina Kotek signed HB 4144 into law on April 7, setting into motion the mechanics for an extended...

AF&PA states disappointment over Oregon EPR decision

byStefanie Valentic
April 8, 2026

The American Forest & Paper Association is responding after a federal judge blocked the trade group's bid to intervene in...

MRF equipment firm Machinex wins patent fight with rival

Judge blocks four groups from joining Oregon Recycling Act injunction

byStefanie Valentic
April 7, 2026

A judge has shut the door on four industry groups seeking to join NAW's Oregon EPR injunction and clarified who's...

UBC stakeholders report on recycling progress

Trump’s Section 232 tariff overhaul provides mixed results for recycling industry

byStefanie Valentic
April 7, 2026

A sweeping overhaul of the Section 232 steel and aluminum derivatives tariff program took effect April 6, slashing duty rates...

Paladin adds ICT in Ireland, deepening Europe ITAD push

byScott Snowden
April 7, 2026

Paladin has acquired Ireland-based ICT, adding on-site shredding and expanding its European ITAD footprint as it builds out secure in-region...

Oregon’s Recycling Modernization Act faces injunction

Why EPR’s biggest obstacle might not be legislation

byStefanie Valentic
April 6, 2026

A miscommunication around the Oregon injunction has some of the industry operating on bad information, and it's raising bigger questions...

Load More
Next Post
Blancco’s software flags possible data security loophole

Blancco's software flags possible data security loophole

More Posts

Wineries help create model for film recycling

Wineries help create model for film recycling

April 7, 2026
With RPET in crisis, focus turns to solutions

With RPET in crisis, focus turns to solutions

April 2, 2026

Trafigura signs $1.1b deal for recycled battery metals

April 8, 2026
End markets, policy key to RPET viability

End markets, policy key to RPET viability

April 8, 2026
EPR fees are a market signal. Here’s what they’re telling you.

EPR fees are a market signal. Here’s what they’re telling you.

April 10, 2026
Wolframite ore, the primary ore of tungsten from Altai, Russia

Tungsten scrap export controls draw industry attention

April 9, 2026
Oregon’s Recycling Modernization Act faces injunction

Why EPR’s biggest obstacle might not be legislation

April 6, 2026
PCA closing Richmond plant

PCA closing Richmond plant

April 2, 2026

Apparel retailer organization challenges SB 707 textile PRO selection

April 2, 2026

Independents complement primary PRO in state EPR

April 6, 2026
Load More

About & Publications

About Us

Staff

Archive

Magazine

Work With Us

Advertise
Jobs
Contact
Terms and Privacy

Newsletter

Get the latest recycling news and analysis delivered to your inbox every week. Stay ahead on industry trends, policy updates, and insights from programs, processors, and innovators.

Subscribe

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • The Latest
  • Analysis
  • Recycling
  • E-Scrap
  • Plastics
  • Policy Now
  • Conferences
    • E-Scrap Conference
    • Plastics Recycling Conference
    • Resource Recycling Conference
    • Textiles Recovery Summit
  • Magazine
  • About Us
  • Advertise
  • Archive
  • Jobs
  • Staff
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.