Why Decommissioning Projects Go Wrong
Data centre decommissioning is the kind of project that looks simpler than it is. The technical work — pulling cables, racking down servers — is straightforward. The complexity lives in sequencing, stakeholder alignment, and the compliance obligations that sit on top of every asset.
Common failure modes include: business units discovering dependencies late, finance discovering fully-depreciated assets with residual market value after they've been destroyed, and compliance teams finding that data destruction wasn't completed before the site lease ended.
A structured checklist doesn't prevent all of these problems, but it surfaces them early enough to manage.
Phase 1: Discovery and Planning (Weeks 1–4)
Asset Inventory
- [ ] Conduct a full physical audit of the facility — every rack, every shelf, every cable run
- [ ] Cross-reference physical audit against CMDB (expect discrepancies — plan for them)
- [ ] Identify all storage media: servers, NAS, SAN, backup tapes, embedded storage in networking hardware
- [ ] Flag devices outside standard hardware lifecycle for special handling
Dependency Mapping
- [ ] Work with application owners to map all workloads to physical infrastructure
- [ ] Identify workloads with no current migration plan — these become blockers
- [ ] Confirm migration targets and timelines are validated, not assumed
- [ ] Document third-party access dependencies (co-location tenants, managed service providers)
Data Classification
- [ ] Classify data on each storage asset by sensitivity (personal data, confidential, public)
- [ ] Involve your Data Protection Officer early — they need sign-off on the destruction plan
- [ ] Confirm which assets require GDPR-compliant destruction certificates
- [ ] Identify assets subject to legal hold or regulatory retention requirements
Phase 2: Procurement and Logistics (Weeks 3–6)
ITAD Partner Selection
- [ ] Confirm ITAD partner holds ISO 27001 and ISO 14001 certifications
- [ ] Review partner's data destruction methodology against NIST 800-88 requirements
- [ ] Request sample certificates of destruction to confirm serial-level reporting
- [ ] Confirm liability transfer terms in the contract — data liability should pass on collection
- [ ] Agree on SLA for certificate delivery (we recommend 5 business days post-processing)
Site Logistics
- [ ] Book loading dock access and confirm vehicle access restrictions
- [ ] Plan for secure transport — tamper-evident sealing, GPS tracking, single-custody transport
- [ ] Confirm site security requirements for the ITAD team (visitor management, escorted access)
- [ ] Notify building management of decommissioning timeline
Phase 3: Decommissioning Execution (Variable)
Sequencing
Work backwards from your facility exit date. The order matters:
- Migrate workloads before touching infrastructure
- Sanitise in-place for any assets that cannot be transported (some regulated environments require on-site destruction)
- Disconnect and label equipment before removal — unlabelled kit creates inventory problems downstream
- Remove in rack order from top to bottom; cable management before power disconnection
Documentation at Each Step
- [ ] Photograph each rack before and after removal
- [ ] Log serial numbers against your inventory at point of disconnection
- [ ] Issue a collection manifest to the ITAD partner; request a signed receipt
- [ ] Record any discrepancies between physical assets and the CMDB
Phase 4: Closeout and Compliance (Weeks post-completion)
Certificate Collection
- [ ] Collect individual certificates of data destruction for every storage asset
- [ ] Reconcile certificates against collection manifest — chase missing items
- [ ] File certificates in your GDPR records of processing activities
- [ ] Archive with a minimum 3-year retention (longer if any data was subject to extended retention requirements)
Financial Closeout
- [ ] Reconcile asset recovery credits against original project budget
- [ ] Update Fixed Asset Register to reflect disposed assets
- [ ] Confirm any lease or finance agreement closeout for leased equipment
Lessons Learned
- [ ] Document any CMDB discrepancies for infrastructure team review
- [ ] Record any compliance issues encountered for future planning
- [ ] Capture timeline variances for future project estimating
Working With ReCircle
We've managed decommissioning projects from single server rooms to multi-site data centre closures. Our project management team handles logistics, chain-of-custody documentation, and compliance reporting — so your internal team can focus on the migration, not the disposal.
Contact us to discuss your upcoming decommissioning project.