Key Takeaway

A significant percentage of the devices employees returned during the remote-work exodus were never properly wiped before the next step in their lifecycle.

Between 2020 and 2023, millions of employees went remote. Companies shipped laptops, phones, and accessories to home addresses across the country, and around the world. Then the layoffs started. Then the return-to-office mandates. Then the office closures.

What followed was a hardware return wave that enterprise IT departments were almost universally unprepared to handle securely at scale.

Devices came back via FedEx in padded envelopes. They were dropped at office lobbies with no chain-of-custody documentation. They were mailed in by former employees weeks after separation. They were collected during facility shutdowns and stacked in storage rooms with no record of what was on them.

The Data That Stayed Behind

A returned laptop from a departed employee is not a blank slate. It likely contains:

Under HIPAA, GDPR, and CCPA, that data was always the organization’s problem. The question regulators and plaintiffs ask isn’t whether you had a policy. It’s whether you can prove the data was handled properly — device by device, step by step, through the entire chain of custody.

Most companies cannot prove that. Not for bulk returns. Not for remote collections. Not for the hundreds of devices that moved through informal processes during a chaotic two-year period.

Why “We Have a Policy” Is Not a Defense

IT security policies are not self-executing. A written standard that says all returned devices must be wiped within 30 days provides no legal protection if the operational reality was a stack of laptops in a closet waiting for someone to get to them.

The documentation gap between what companies say they do and what they can actually demonstrate is one of the most exploitable vulnerabilities in enterprise data governance — and the remote work era created one of historic scale.

What a Defensible Program Looks Like

The standard for defensibility isn’t high-tech. It’s documentary. Regulators and courts want a clear, unbroken record answering four questions for every device: What was on it? Who had it? What was done to it? How do you know?

A program that answers those questions at scale has three components:

Most organizations have pieces of this. Very few have all three working consistently at the volume a remote workforce generates.

If You Have Unresolved Returns, Act Now

The instinct when you know there are documentation gaps is to leave them alone. The risk of disturbing the process feels greater than the risk of the gap. That calculation is almost always wrong.

A proactive remediation — inventorying outstanding devices, certifying destruction where hardware is still available, documenting the process going forward — creates a defensible record. Doing nothing leaves a gap a regulator or plaintiff can fill with their own narrative.

The organizations most exposed aren’t the ones with bad policies. They’re the ones with reasonable policies, executed imperfectly under pressure, who never went back to close the loop.

DRM Worldwide — ITAD Intelligence Series

The Broader Lesson

The remote work era revealed that end-of-life disposition was universally treated as an afterthought. The companies best positioned going forward build programs that are audit-ready by design — treating device return with the same governance applied to procurement, requiring serialized CODs, and choosing ITAD partners who can prove their downstream chain of custody.

The exposure gap created by the remote work hardware wave is still unresolved for most enterprises. It doesn’t close itself.

Ready to close the gap on your returned device backlog?
DRM Worldwide specializes in secure device collection, certified data destruction, and chain-of-custody disposition — including remediation for organizations with unresolved return backlogs. We help enterprises build the documentary record needed to demonstrate compliance and recover value from idle hardware.

Get in Touch