Operations

Data Centre Decommissioning: A Step-by-Step Planning Checklist

ReCircle Tech7 min read

Why Decommissioning Projects Go Wrong

Data centre decommissioning is the kind of project that looks simpler than it is. The technical work — pulling cables, racking down servers — is straightforward. The complexity lives in sequencing, stakeholder alignment, and the compliance obligations that sit on top of every asset.

Common failure modes include: business units discovering dependencies late, finance discovering fully-depreciated assets with residual market value after they've been destroyed, and compliance teams finding that data destruction wasn't completed before the site lease ended.

A structured checklist doesn't prevent all of these problems, but it surfaces them early enough to manage.

Phase 1: Discovery and Planning (Weeks 1–4)

Asset Inventory

  • [ ] Conduct a full physical audit of the facility — every rack, every shelf, every cable run
  • [ ] Cross-reference physical audit against CMDB (expect discrepancies — plan for them)
  • [ ] Identify all storage media: servers, NAS, SAN, backup tapes, embedded storage in networking hardware
  • [ ] Flag devices outside standard hardware lifecycle for special handling

Dependency Mapping

  • [ ] Work with application owners to map all workloads to physical infrastructure
  • [ ] Identify workloads with no current migration plan — these become blockers
  • [ ] Confirm migration targets and timelines are validated, not assumed
  • [ ] Document third-party access dependencies (co-location tenants, managed service providers)

Data Classification

  • [ ] Classify data on each storage asset by sensitivity (personal data, confidential, public)
  • [ ] Involve your Data Protection Officer early — they need sign-off on the destruction plan
  • [ ] Confirm which assets require GDPR-compliant destruction certificates
  • [ ] Identify assets subject to legal hold or regulatory retention requirements

Phase 2: Procurement and Logistics (Weeks 3–6)

ITAD Partner Selection

  • [ ] Confirm ITAD partner holds ISO 27001 and ISO 14001 certifications
  • [ ] Review partner's data destruction methodology against NIST 800-88 requirements
  • [ ] Request sample certificates of destruction to confirm serial-level reporting
  • [ ] Confirm liability transfer terms in the contract — data liability should pass on collection
  • [ ] Agree on SLA for certificate delivery (we recommend 5 business days post-processing)

Site Logistics

  • [ ] Book loading dock access and confirm vehicle access restrictions
  • [ ] Plan for secure transport — tamper-evident sealing, GPS tracking, single-custody transport
  • [ ] Confirm site security requirements for the ITAD team (visitor management, escorted access)
  • [ ] Notify building management of decommissioning timeline

Phase 3: Decommissioning Execution (Variable)

Sequencing

Work backwards from your facility exit date. The order matters:

  1. Migrate workloads before touching infrastructure
  2. Sanitise in-place for any assets that cannot be transported (some regulated environments require on-site destruction)
  3. Disconnect and label equipment before removal — unlabelled kit creates inventory problems downstream
  4. Remove in rack order from top to bottom; cable management before power disconnection

Documentation at Each Step

  • [ ] Photograph each rack before and after removal
  • [ ] Log serial numbers against your inventory at point of disconnection
  • [ ] Issue a collection manifest to the ITAD partner; request a signed receipt
  • [ ] Record any discrepancies between physical assets and the CMDB

Phase 4: Closeout and Compliance (Weeks post-completion)

Certificate Collection

  • [ ] Collect individual certificates of data destruction for every storage asset
  • [ ] Reconcile certificates against collection manifest — chase missing items
  • [ ] File certificates in your GDPR records of processing activities
  • [ ] Archive with a minimum 3-year retention (longer if any data was subject to extended retention requirements)

Financial Closeout

  • [ ] Reconcile asset recovery credits against original project budget
  • [ ] Update Fixed Asset Register to reflect disposed assets
  • [ ] Confirm any lease or finance agreement closeout for leased equipment

Lessons Learned

  • [ ] Document any CMDB discrepancies for infrastructure team review
  • [ ] Record any compliance issues encountered for future planning
  • [ ] Capture timeline variances for future project estimating

Working With ReCircle

We've managed decommissioning projects from single server rooms to multi-site data centre closures. Our project management team handles logistics, chain-of-custody documentation, and compliance reporting — so your internal team can focus on the migration, not the disposal.

Contact us to discuss your upcoming decommissioning project.

Speak With Our Team

Questions about your ITAD programme? Our compliance specialists are available for a confidential consultation.

Get in Touch

Category

Operations
All Insights