Call Us Now: 888.945.2611
Call Us Now: 888.945.2611
Sep 15, 2026
Much of the guidance on retiring school technology is written for U.S. institutions and focuses on laws such as FERPA. Canadian schools, colleges and universities operate under different privacy and cybersecurity requirements, which can also vary by province and institution type.
In Ontario, for example, school boards are subject to the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), while colleges, universities and provincial institutions generally fall under the Freedom of Information and Protection of Privacy Act (FIPPA). Newer provincial cybersecurity requirements add another layer to how public-sector organizations protect digital information and manage technology.
That matters when evaluating ITAD services for schools and other educational institutions. Retired laptops, desktops, servers and other devices may still contain student, employee or administrative information, so secure data destruction, chain of custody and final reporting need to align with the institution’s privacy and security obligations.
This guide looks at the regulatory context, what it means for device retirement, and how schools, colleges and universities can plan an IT refresh around security, reporting and budget requirements.
The privacy rules that apply to retired IT equipment depend on the institution, province and type of information involved.
| Institution type | Primary privacy framework |
|---|---|
| Ontario district school boards | MFIPPA, along with applicable requirements under Ontario’s Enhancing Digital Security and Trust Act, 2024 |
| Ontario provincial and demonstration schools | FIPPA, along with applicable provincial cybersecurity requirements |
| Ontario public colleges and universities | FIPPA, along with applicable provincial cybersecurity requirements |
| British Columbia public schools and other public bodies | B.C. Freedom of Information and Protection of Privacy Act |
| Alberta public schools and other public bodies | Alberta Protection of Privacy Act |
| Quebec public-sector institutions | Act respecting Access to documents held by public bodies and the Protection of personal information |
| Private educational institutions and service providers | PIPEDA or applicable provincial private-sector privacy legislation, depending on the organization and jurisdiction |
Although the legislation differs, the practical concern is similar: institutions must protect personal information in their custody or control against unauthorized access, use or disclosure. If a retired laptop still contains recoverable student, employee or administrative records, disposing of the hardware does not remove the institution’s responsibility to protect the information stored on it.
Ontario has also added new cybersecurity requirements for public-sector organizations. Bill 194, the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, enacted the Enhancing Digital Security and Trust Act, 2024 and amended Ontario’s public-sector privacy framework. Regulations under the EDSTA took effect on July 1, 2026 and introduced cybersecurity requirements for covered public-sector organizations, along with additional transparency requirements concerning children’s digital information at school boards.
The regulatory framework has several practical implications for how schools, colleges and universities retire IT equipment.
The institution remains accountable for the information. Using an ITAD provider does not remove the institution’s responsibility to protect personal information in its custody or control. That makes a documented, centrally managed disposition process easier to govern than relying on individual schools, departments or campuses to handle retired devices independently.
Asset-level reporting strengthens the audit trail. If a laptop, desktop or storage device can’t be accounted for during the disposition process, the institution needs enough detail to investigate what happened. Serial-number-level tracking provides a clearer record than a summary certificate that only states the total number of devices processed.
Vendor due diligence matters. Institutions should understand how an ITAD provider protects data, maintains chain of custody and manages downstream processors. Certifications and documented controls can help procurement and privacy teams assess whether a provider has appropriate processes in place. Our certifications page lists the standards and certifications that apply to eCycle Solutions facilities.
One-to-one device programs can create a very different ITAD workload from routine equipment retirement. School boards often replace student devices on a planned multi-year cycle, which can mean hundreds or thousands of similar laptops or Chromebooks reaching retirement at the same time.
That creates several jobs that need to be coordinated. Returned devices must be reconciled against the board’s asset records, any missing equipment needs to be investigated, data must be securely removed and documented, and equipment with remaining market value needs to be identified quickly enough to support the board’s refresh budget.
Reconciliation can be especially time-consuming because it depends on accurate records as well as the physical devices. Planning the return and inventory process before the end-of-year rush can make the later ITAD stages much easier to manage.
For school boards planning a summer device refresh, the collection and ITAD schedule should be worked out well before the end of the school year. A typical planning sequence might look like this:
The earlier this process is scheduled, the easier it is to coordinate collections, transportation and processing during the busy summer refresh period. Booking ITAD services in the spring also gives the board and provider more time to resolve inventory questions before large volumes of equipment begin moving.
Resale can help offset the cost of a device refresh, but the amount recovered varies widely. Age matters, but so do specifications, condition, market demand and the amount of manufacturer support remaining. Rather than building a fixed recovery figure into the budget, institutions should ask for an early valuation based on the actual devices being retired.
Chromebooks need particular attention because their Auto Update Expiration date affects how long they continue receiving ChromeOS software and security updates. Devices approaching or past that date may have less resale potential, so it is worth checking the model-specific support window when planning a refresh.
Where an institution prefers not to receive resale proceeds directly, eCycle Solutions can also arrange for the value of eligible assets to be donated to a charity. Our resale and refurbishment service explains how testing, valuation, refurbishment and remarketing work.
An education ITAD project may involve pickups from multiple schools or campuses, documented chain of custody, secure sanitization of data-bearing devices, asset-level tracking, testing and grading, resale of equipment with remaining value, and material recovery for devices that cannot be reused.
The final reporting should give the institution a clear record of what was received, how data was handled and what ultimately happened to each asset.
Our ITAD service covers the full disposition process, while our government and public sector services provide additional information for public-sector organizations managing secure IT retirement and reporting requirements.
If your immediate need is electronics recycling rather than the disposition of data-bearing IT assets, our guide to secure electronics recycling for schools is a better starting point.
Look at the provider’s current certifications, data destruction procedures, chain-of-custody controls, asset-level reporting and downstream recycling practices. For a school board or multi-campus institution, also confirm that the provider can coordinate collections across all required locations. Ask for a sample reporting package during procurement so your IT, privacy and compliance teams can confirm that it contains the level of detail they need.
Data-bearing devices should be securely sanitized or physically destroyed before they are released for reuse or recycling. The appropriate method depends on the type and condition of the media, and the results should be documented at the asset level. The final reporting package should provide evidence of how the devices and their data were handled.
FERPA is a U.S. federal student privacy law and generally does not govern Canadian schools, colleges or universities. Canadian educational institutions are instead subject to applicable federal or provincial privacy legislation. In Ontario, for example, school boards fall under MFIPPA, while public colleges and universities generally fall under FIPPA. Ontario school boards, colleges and universities are also subject to applicable cybersecurity requirements under the Enhancing Digital Security and Trust Act, 2024.
For a summer refresh, planning should begin well before devices are collected at the end of the school year. Confirm the expected device count, reconcile the asset register and schedule the ITAD provider in the spring where possible.
Recovery value depends on the device type, specifications, age, condition, market demand and remaining manufacturer support. Ask for a valuation based on the actual devices being retired before including expected resale proceeds in a budget.
Yes, provided the ITAD provider has the geographic coverage and logistics capacity required for the project. Managing multiple school locations through one engagement can simplify pickup coordination, chain-of-custody documentation, asset reconciliation and final reporting compared with managing separate disposition processes at each site.