R2v3 stands for “Responsible Recycling (R2) Standard Version 3,” developed by Sustainable Electronics Recycling International, a non-profit organization with the mission to minimize the environmental and health risks posed by used and end-of-life electronics. The standard provides a comprehensive framework for electronics recyclers, refurbishers, and IT Asset Disposition (ITAD) companies handling end-of-life electronics. To maintain the integrity of the program, all R2-certified facilities are independently audited and certified by accredited certification bodies. In January 2024, the standard was updated with the release of Version 3.1. Its globally recognized program focuses on environmental protection, worker safety, and data security.
The R2v3 framework is organized into two sections:
Section 1: R2 Core Requirements
Section 2: R2 Process Requirements
Understanding the R2v3 Core Requirements
The R2v3 Core Requirements, defined in Section 1 of the R2v3 standard, establish the foundational obligations that all certified facilities must meet. For ITAD facilities handling end-of-life laptops, desktops, tablets, enterprise equipment, smartphones, and more, data security is a critical priority. Among the ten core elements of R2v3 certification, Element 7 “Data Security” sets the standard for how certified facilities must safeguard sensitive information throughout the recycling and disposition process.
What does R2v3 Data Security Requirement Cover?
R2v3 Core Requirement 7 establishes the standard for securing and sanitizing all data storage devices as appropriate to both the type of device and the sensitivity of the data it holds. To meet R2 compliance under this element, certified facilities must address four key areas:
A) Documentation
This aspect emphasizes the need for detailed documentation on the data sanitization plan and procedures. The documentation should comprise the following details:
- The physical security measures at the R2 Facility, such as restricted zones and access controls, that protect data throughout the sanitization process.
- List of all types of storage devices handled at the facility that may contain data.
- The categories of data that are required to be sanitized, along with a clear declaration of any general or non-sensitive information that is exempt from sanitization.
- Any network services that could automatically restore data onto a device after sanitization has been performed, and how that risk is addressed.
- Any written agreements with customers that prohibit sanitization of specific devices or data, and the process followed to honor those restrictions.
- All applicable legal, regulatory, and contractual obligations related to data sanitization, including privacy laws and data breach requirements, and where these are addressed in the facility's internal policies and procedures.
- The sanitization method to be applied to each type of storage device.
- The maximum timeframe within which sanitization must be completed after a device is received at the facility.
- All downstream vendors or contractors performing data sanitization on the facility's behalf, if not handled internally, including those whose services are provided in another country.
- Documented records that demonstrate the efficacy of data sanitization and verification methods.
- A pre-defined process by the facility for authorizing and monitoring access to equipment and components containing data, applicable to all employees, contractors, and visitors.
The R2 Facility must document and maintain a written data security policy that:
- Prohibits unauthorized individuals from accessing or handling any equipment that contains data.
- Requires appointment of a competent Data Protection Representative, holding overall responsibility and authority for the facility's data security and legal compliance.
- Requires that all known or suspected security and data breaches be reported to the Data Protection Representative without delay.
- Mandates authorized individuals to handle equipment containing data after completing the required training and signing a confidentiality agreement.
- Clearly identify the penalties for non-compliance, including the possibility of personal liability for individuals who violate it.
All workers must be trained regularly and confirmed to be competent in the facility's data security policies and procedures, in line with their assigned level of authorization.
B) Security
The R2 Facility must implement and maintain a security program that manages physical access to the facility and its electronic equipment. It should employ security measures appropriate for the electronic equipment it handles and the suppliers it serves in line with the following requirements:
- Must implement and maintain access control to all or parts of the facility, appropriate to the type of electronic equipment handled, the sensitivity of data on storage devices, the needs of suppliers served, and the risks of theft and unauthorized access.
- Security authorization levels must be developed to control access for employees, visitors, and contract workers based on equipment type, data sensitivity, and applicable legal or supplier requirements. All authorizations must be granted by the Data Protection Representative with supported evaluation documents permitted by law.
- All secured areas within the facility must be clearly marked with signage to warn against unauthorized access.
- A written acknowledgement must be maintained for every authorized individual, confirming their responsibility to prevent data disclosure, report any theft or data breaches, and disclose any circumstances that may affect their authorization status.
- An incident response procedure must be established to investigate potential data or security breaches and to notify affected suppliers, legal authorities, and other relevant parties as required by law.
C) Process
This aspect focuses on defining the processes followed for receiving and sanitizing data storage devices. All data must be sanitized unless the supplier contractually obligates the R2 facility not to sanitize the data.
Upon receiving any equipment or components that may contain data, the facility must provide a written confirmation acknowledging the receipt of equipment or components, the sanitization method that will be used, and whether sanitization will be performed internally or by a downstream vendor.
Once received, all equipment must be sanitized in a timely and effective manner using one of the following methods:
- Sanitize the data in accordance with Appendix B – Data Sanitization.
- Physically destroy the storage media in accordance with Appendix A NIST Guidelines for Media Sanitization SP 800-88 Rev. 1, and verify destruction through a defined process that demonstrates 100% effectiveness.
- Ship or transfer storage devices under a written contract to a verified downstream vendor, confirmed in accordance with Appendix A – Downstream Recycling Chain, with the capability to sanitize data from the type of equipment transferred using the method disclosed to the supplier.
Internal data security and sanitization audits must be conducted at least once a year by a competent and independent auditor. These audits must confirm that sanitization processes are effective and in conformance with the R2 Standard, applicable legal requirements, and the facility's data sanitization plan.
D) Notifications
The R2 Facility must have a documented notification process in place to keep suppliers informed upon request of the following:
- Any changes in downstream vendors responsible for processing the supplier's equipment and components containing data.
- Any breaches in security that may affect the supplier's data or equipment.
Conclusion!
For R2 certified ITADs, using a reliable data erasure solution is mandatory to comply with Appendix B Data Sanitization. Choosing the right tool that is certified by global bodies for its data wiping efficacy is an important consideration for building trust. The software must comply with NIST 800-88, IEEE 2883, and other data sanitization standards, along with supporting erasure of diverse storage devices. Software such as BitRaser performs secure data erasure across HDDs, SSDs, SEDs, SMR, NVMe, and other storage media. Upon completion, it generates audit reports and certificates of destruction that list the erasure method applied, verification results, and device-specific information for full traceability.
Be sure to review the Sanitization Software Examples list published by SERI.