The March 18, 2026 Omnibus I amendment to the CSRD reduces the number of companies that fall within its reporting scope. However, organizations that remain subject to the requirements still need to address sustainability reporting under the ESRS, including relevant Scope 3 emissions. This puts IT Asset Disposition (ITAD) and secure data erasure in a more important position within the technology lifecycle.

The EU Corporate Sustainability Reporting Directive (CSRD), amended through the Omnibus I Directive, came into force on March 18, 2026. The amendment narrowed the number of organizations required to report, with the revised scope generally covering undertakings and groups with more than 1,000 employees and more than €450 million in net annual turnover.
For organizations that remain within scope, sustainability reporting and limited assurance requirements continue to matter. The focus is not simply on whether a company has sustainability initiatives in place. Organizations increasingly need reliable and verifiable information about their environmental impact, including material Scope 3 emissions.
Scope 3 is particularly important because it extends beyond a company's direct operations and includes emissions throughout its wider value chain. For organizations with significant technology inventories, this can bring areas such as purchased capital goods and the treatment of operational waste into the conversation.
CSRD non-compliance penalties are determined under the applicable national rules of each EU Member State and are required to be effective, proportionate, and dissuasive. However, financial penalties are only part of the risk. A mismatch between an organization's sustainability claims and the evidence supporting those claims can also affect stakeholder confidence and corporate reputation.
This is where IT Asset Disposition (ITAD) becomes increasingly relevant.
For organizations managing large technology estates, ITAD can provide a structured way to manage retired devices while considering security, recovery, reuse, recycling, and end-of-life treatment. Secure data erasure is particularly important because it can determine whether a functional device can safely move toward another lifecycle—or whether physical destruction becomes the only practical option.
When an ITAD provider securely erases, verifies, tests, and prepares an asset for reuse, the device may be transferred to another organization instead of being immediately discarded or replaced with newly manufactured hardware.
That creates a connection between data security, asset recovery, circularity, and sustainability.
For organizations with substantial IT estates, two Scope 3 categories are especially relevant when considering the lifecycle of technology assets:
Category 5 covers emissions associated with the disposal and treatment of waste generated through an organization's operations. This can include solid waste such as electronic waste, as well as wastewater.
For IT-heavy organizations, the way retired computers, servers, storage devices, and other electronics are handled can therefore become an important part of the broader environmental impact discussion.
Category 2 covers upstream emissions associated with capital goods purchased or acquired during the reporting year.
Technology hardware can fall within this broader capital-goods conversation. The question then becomes how organizations can make better lifecycle decisions around technology rather than treating every retired device as a one-time purchase-and-disposal cycle.
The connection between these two areas is asset reuse. But before a device can be safely reused, one issue has to be addressed first: The data stored on that device must be securely removed.

Imagine two organizations: Company 1 and Company 2.
Company 1 is retiring a fleet of laptops and servers. Many of the devices are still fully functional and could potentially serve for several more years. However, those devices contain business information, user data, credentials, application data, and other sensitive information.
Simply deleting files or performing a standard factory reset may not provide the level of assurance required for secure disposition. Physical destruction removes the data-security concern, but it also removes the possibility of recovering the device for another useful lifecycle.
Secure data erasure provides another option.
An ITAD provider can use a solution such as D-Secure Drive Eraser to securely erase data from eligible storage devices, verify the erasure process, and generate detailed documentation. Hardware diagnostics can then help determine the condition of the device and whether it is suitable for reuse, refurbishment, recycling, or another disposition route.
The result is more than simply a wiped device. It creates an evidence trail showing how the asset was handled after retirement. For Company 1, that documented process can help demonstrate that suitable assets were evaluated for reuse instead of automatically being sent for destruction or waste treatment.
Where an asset is genuinely diverted from a waste-treatment pathway toward legitimate reuse, there may be an environmental benefit. However, any resulting emissions impact must be calculated according to the organization's applicable Scope 3 methodology and supported by appropriate evidence.
Now consider what happens to the device after Company 1's ITAD process.
A securely erased and tested laptop may be refurbished and subsequently acquired by Company 2. Instead of purchasing an entirely new device, Company 2 gains access to equipment that has already completed one useful lifecycle and has been prepared for another.
Extending the useful life of existing technology can help reduce the need for additional newly manufactured hardware. Manufacturing new electronic equipment involves raw materials, energy, transportation, and other upstream environmental impacts. This makes professionally refurbished and reused equipment relevant to organizations developing a circular procurement strategy.
Traditionally, ITAD was often viewed primarily as the final step in the technology lifecycle—something that happened after an organization had finished using its equipment. That role is changing.
An effective ITAD process can connect data security, asset recovery, reuse, recycling, compliance, and sustainability within a single lifecycle.
One ITAD transaction can potentially create value for two organizations:
This makes ITAD increasingly relevant to broader ESG and sustainability strategies. The process can also provide organizations with the documentation needed to understand what happened to individual assets after retirement.
Secure data erasure is the critical enabler because data-security concerns can otherwise make physical destruction the default choice for retired technology.
Together, these steps turn ITAD from a simple disposal activity into a more structured part of responsible technology lifecycle management.
As CSRD and ESRS reporting requirements continue to evolve, organizations need to look beyond simply retiring technology securely. They also need to understand what happens to those assets afterward. A documented, audit-ready sanitization process can help connect secure IT asset retirement with broader ESG and sustainability processes.
For organizations with large technology estates, this means being able to demonstrate:
D-Secure helps enterprises and ITAD providers build this evidence trail through secure data erasure, verification, asset-level reporting, and supporting capabilities for responsible IT asset disposition.
With D-Secure, enterprises and ITAD providers can securely erase sensitive information while maintaining detailed records of the sanitization process—helping create a stronger foundation for secure asset reuse and responsible disposition.
Explore the full D-Secure data security suite
Meeting NIST 800-88 and GDPR standards with full audit trails.
Scalable solutions for ITAD partners and large organizations.
Trusted by global enterprises for zero-leakage data sanitization.
Your email address will not be published. Providing an email is optional.
Send us an enquiry regarding: ITAD, Secure Data Erasure, and the Growing Importance of Scope 3 Reporting
No comments yet. Be the first to comment.