Contract an NAID AAA–certified data destruction provider that also holds R2v3 or e-Stewards environmental certification and follows NIST SP 800-88 sanitization methods. That combination covers both the data security audit trail and California’s environmental disposal requirements in a single vendor relationship.
Before you call anyone, have three things ready:
- Ask first: Confirm the vendor’s NAID AAA scope (plant-based vs. mobile), the sanitization level they’ll apply (clear, purge, or destroy), and how chain-of-custody is documented from pickup to final disposition.
- Have ready: A serialized asset manifest listing every device by serial number and data sensitivity classification.
- Next step: Request a site quote or on-campus pickup through Usedcartridge, and immediately ask for proof of insurance, a Certificate of Destruction template, and their downstream vendor disclosure.
Pro Tip: Demand a device-level Certificate of Destruction, not a batch-level one. A single CoD covering 200 drives gives you nothing useful in an audit.
Key Takeaways
Certified e-waste disposal for UCLA organizations requires NAID AAA data destruction, NIST SP 800-88 sanitization documentation, and CalRecycle-compliant environmental handling from a single, insured vendor.
| Point | Details |
|---|---|
| Lead with certifications | Require current NAID AAA and R2v3 certificates before any asset leaves campus. |
| Match method to media | SSDs and embedded NVM need cryptographic erase or physical destruction, not overwrite. |
| Demand device-level CoDs | Batch certificates don’t satisfy UC or HIPAA audit requirements. |
| California law applies | Covered devices must go through CalRecycle-approved collectors; verify Basel PIC compliance for any offshore routing. |
| Usedcartridge next step | Request an IT asset recovery disposition quote and attach a serialized asset manifest to start. |
Table of Contents
- What UCLA e-waste compliance actually requires from your department
- How to engage with UCLA-approved or preferred vendors
- Steps and paperwork required for on-campus pickup or drop-off
- How California e-waste law affects UCLA organizations
- The case for combining NAID AAA and R2v3 on every campus engagement
- Usedcartridge delivers audit-ready e-waste and data destruction services
- Sources
What UCLA e-waste compliance actually requires from your department
UCLA organizations disposing of electronic equipment operate under overlapping obligations: UC systemwide policy on data security, California’s Electronic Waste Recycling Act (CalRecycle), and federal frameworks like HIPAA or FERPA depending on the data involved. The UC system requires that devices storing institutional data be sanitized before disposal, with documented verification. That means a vendor receipt is not enough. You need a serialized record showing which device was sanitized, by what method, and when.
For devices containing Protected Health Information or sensitive PII, the sanitization standard rises to purge or destroy under NIST SP 800-88. SSDs and embedded NVM storage require cryptographic erase or physical destruction because overwrite methods that work on HDDs often leave recoverable data on flash media.
How to engage with UCLA-approved or preferred vendors
UCLA Procurement Services maintains a vendor approval process that typically requires proof of current certifications, insurance minimums, and compliance with UC data security standards. When evaluating vendors, ITAD is distinct from general recycling: a recycler focuses on material recovery, while a true ITAD provider manages audit documentation, chain-of-custody, and data liability. Treating a recycler as an ITAD vendor creates real compliance exposure.
Require vendors to supply current R2v3 or e-Stewards certificates, NAID AAA verification, errors and omissions insurance, and a named downstream vendor list before any assets leave campus.
Steps and paperwork required for on-campus pickup or drop-off
- Generate a serialized asset manifest (device type, serial number, data classification, assigned department).
- Get departmental IT security sign-off confirming data classification and required sanitization level.
- Confirm vendor’s scheduled pickup window and on-site equipment requirements (shredder truck access, loading dock clearance).
- At pickup, verify tamper-evident seals are applied and chain-of-custody documentation is signed by both parties.
- Retain the signed manifest, Certificate of Destruction, and vendor insurance certificate for a minimum of three years per UC records retention guidelines.
How California e-waste law affects UCLA organizations
California’s Electronic Waste Recycling Act requires that covered electronic devices (monitors, TVs, laptops, and similar equipment) be recycled through CalRecycle-approved collectors. UCLA departments cannot legally place these devices in standard waste streams. Vendors must be registered with CalRecycle, and the Basel Convention amendment effective January 1, 2025 now requires Prior Informed Consent for most cross-border e-waste shipments, which affects any vendor routing assets to international processing facilities. Confirm your vendor processes domestically or has documented PIC compliance for any offshore movement.
The case for combining NAID AAA and R2v3 on every campus engagement
Most campus IT teams treat certification as a checkbox. It isn’t. NAID AAA and R2v3 solve different problems, and you need both.

NAID AAA covers operational data destruction: unannounced audits, personnel background screening, CCTV requirements, and documented chain-of-custody. R2v3 covers what happens to the hardware after data is gone: downstream vendor controls, environmental handling, and material traceability. A vendor with only one of these certifications leaves a gap that shows up fast in a UC audit or a HIPAA breach investigation.
On-site destruction makes sense for classified data, high-risk PHI, or any device that cannot leave the building under your data governance policy. Off-site facility processing works well for bulk asset recovery where reuse or remarketing is the goal and sanitization can be verified at the facility before resale.

For reuse decisions, NIST SP 800-88 recommends purge over destroy when the device will be remarketed, because purge preserves hardware value while meeting the sanitization threshold for most data classifications. Cryptographic erase on self-encrypting drives is the fastest purge method for SSDs and is fully NIST-compliant.
Pro Tip: When a vendor says “NIST-compliant,” ask which tier (clear, purge, or destroy) and for which specific media type. Vague answers mean they’re applying the same method to every device regardless of media, which is a red flag.
For a campus lab refresh or dorm equipment turnover, the practical checklist looks like this: confirm asset tags are intact, get IT security sign-off on classification, schedule pickup with at least five business days’ lead time, and require the CoD within 10 business days of pickup. Usedcartridge handles on-site destruction and pickup logistics for Southern California locations, with certification documentation provided as part of the service.
Usedcartridge delivers audit-ready e-waste and data destruction services
Certified e-waste recycling and secure data destruction don’t have to mean two separate vendor relationships, two sets of paperwork, and two audit trails.

Usedcartridge provides on-site and off-site data destruction, IT asset recovery with direct payout, and compliant e-waste recycling for organizations across Southern California. Every engagement includes a Certificate of Destruction, serialized chain-of-custody documentation, CCTV-monitored processing, background-screened personnel, and liability and E&O insurance coverage. Asset recovery payouts offset disposal costs, and the service maps directly to the audit evidence UCLA procurement requires.
| Service | Sanitization method | Certificate provided | Asset recovery | Typical timeline |
|---|---|---|---|---|
| On-site destruction | Purge / destroy | Device-level CoD | No (destroyed) | Same day |
| Off-site facility processing | Clear / purge / cryptographic erase | Device-level CoD | Yes, with payout | 3–5 business days |
| IT asset recovery | Purge / cryptographic erase | CoD + audit report | Yes, direct payment | 5–10 business days |
To start, request an IT asset recovery disposition quote and attach your serialized asset manifest. Have your lease or contract clauses ready if any devices are under a return obligation.
Sources
Bookmark these standards when writing vendor RFPs or preparing audit responses:
- SP 800-88 Rev. 2, Guidelines for Media Sanitization | CSRC
- IT Asset Disposition: The Compliance Guide for Mid-Market IT Teams – Disposition Compliance
- What Is IT Asset Disposition (ITAD)? Enterprise Guide
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.