Explore the latest Remote Work and IT Trends & Insights with GroWrk's Blog

Corporate Device Recovery in India: 2026 Guide

Written by GroWrk Team | Aug 7, 2026, 7:41:34 AM

Corporate device recovery in India is the process of securely collecting company-owned laptops and IT equipment from departing employees, maintaining chain of custody in transit, reconciling the returned asset against the record, sanitising the data, and routing the device to its next lifecycle state. Two things changed the operating picture recently. India’s four labour codes took effect on 21 November 2025, and Section 17(2) of the Code on Wages now requires wages due on resignation or termination to be paid within two working days of the last working day — which removes the delayed final settlement many companies quietly relied on as recovery leverage. And NIST withdrew SP 800-88 Revision 1 in September 2025, replacing it with Revision 2 and a different approach to what counts as proof of sanitisation. Recovery now has to start earlier and produce better evidence, which makes it part of equipment retrieval workflows rather than a courier booking.

Question What IT leaders should know
Which providers recover devices from employees in India? Global lifecycle platforms such as GroWrk, Firstbase, Workwize, and allwhere; India-focused reverse-logistics providers such as Bombax; national couriers; and registered ITAD firms. Compare lifecycle depth, not pickup availability.
When should recovery begin? At notice, not the last working day. The two-working-day settlement rule means the exit is financially closed before a late retrieval has started.
Is remote wipe enough? No. A wipe is a data action, not an asset action — and an unverified wipe command is not evidence that anything happened.
What must chain of custody include? Device identity, employee handoff proof, tracked movement, delivery proof, facility receipt, serial reconciliation, sanitisation evidence, and final disposition.
What is the most common mistake? Marking an asset recovered when the courier scans the parcel, rather than when the record is reconciled and closed.

What corporate device recovery actually includes

Booking a courier is not recovering a device. A complete IT device retrieval workflow runs from the offboarding event through to a closed asset record:

  1. Receive the offboarding or termination event from HR.
  2. Identify every item assigned to the employee, by serial number.
  3. Revoke access and decide whether to lock, wipe, or preserve the device.
  4. Confirm the employee’s current address and phone number.
  5. Contact the employee with instructions and a return deadline inside the notice period.
  6. Provide packaging or a printerless return option, and schedule a home pickup.
  7. Track the shipment and follow up on missed collections or non-response.
  8. Confirm receipt at a controlled facility and reconcile the serial number.
  9. Inspect condition, sanitise to policy, and record the evidence.
  10. Route the device to repair, storage, redeployment, resale, or certified disposal.

The asset is not recovered when the courier scans the package. It is recovered when the company holds the correct equipment, the record has been reconciled, and the next action is known. Every stage should answer the same question: where is the device, who is responsible for it, and what happens next?

Start recovery at the offboarding event, not the final day

HR knows someone is leaving before IT does, and IT knows before logistics does. That makes the HR event the natural trigger, and an HRIS integration that opens the retrieval workflow on notice is worth more than any escalation script written afterwards. Where that connection is missing, IT typically discovers the outstanding device days or weeks after the exit — by which point contact details are stale, the employee has no reason to respond, and nobody clearly owns the case.

In India this is now a compliance matter as much as an operational one. For years the informal recovery mechanism was the final settlement: hold full and final payment for 30 to 60 days, and the laptop usually came back before the money went out. Under Section 17(2) of the Code on Wages, wages payable on resignation, removal, dismissal, retrenchment, or closure must be paid within two working days of exit. Section 18 permits deductions only in specified categories, caps them at 50 percent of wages in a wage period, and a deduction for loss or damage needs a documented basis in the terms the employee accepted at hiring — not a policy applied after they resign.

The practical consequence: treat an unreturned device as a separate recoverable rather than a gate on settlement, and get the return in motion during the notice period, while the employee is still on payroll and still responsive. This is general information rather than legal advice; confirm the position with your employment counsel.

Different departures need different workflows

Departure type Access action Recovery approach
Standard resignation Revoke per final-day policy Scheduled retrieval initiated at notice
Immediate termination Revoke immediately Priority outreach and expedited pickup
High-risk or security exit Lock access and device per policy Accelerated retrieval with close monitoring
Legal hold or investigation Preserve required information Do not wipe until Legal authorises sanitisation
Internal transfer Modify access Device may stay assigned or be exchanged
Contractor end date Revoke at agreed time Retrieve according to the ownership terms in the contract

Security, HR, Legal, and IT should agree these rules before a difficult exit forces the question.

Know exactly what has to come back

Recovery gets hard when a company cannot confidently identify its own equipment. Asking someone to “return your laptop” invites the wrong device, a personal machine, or a laptop without its charger. For anything of value, the request should name the serial number.

Field Why it matters
Employee name and ID Removes ambiguity between similar records
Current address and phone Determines pickup location — confirm at retrieval, not from the hiring record
Device type, make, model Lets the employee verify what is being asked for
Serial number and asset tag Definitive identity, and the key everything else attaches to
Ownership Company-owned, leased, or rented changes the return path
Accessories issued Charger, dock, token, headset, bag — the items most often missing
MDM and encryption status Determines which security actions are actually available
Return deadline and destination Creates accountability and tells logistics where it goes

Serial-level IT asset management is what prevents the recurring failures here: two devices assigned but one recovered, equipment arriving with no way to link it to a person, and disputes about whether a machine was company-owned at all.

Remote wipe, sanitisation, and the data obligations

A remote wipe is a data-security action. Recovery is an asset action. They solve different problems and companies usually need both — wiping a managed laptop does not return a device worth Rs 100,000 or more to inventory, and recovering the hardware does not by itself mean the data was removed safely.

Do not assume the wipe succeeded

A remote command only works if the device stays enrolled in MDM, connects to the internet, receives the instruction, and completes it. Any of those can fail silently. Keep evidence of the command and its result rather than treating the button press as closure, and reconcile that evidence against the device when it physically arrives. Encryption enforced at deployment is what makes the fallback work: on encrypted hardware, cryptographic erase destroys the key and renders the remaining data unreadable, which is why zero-touch deployment with BitLocker or FileVault enforcement is a recovery decision as much as a security one.

The standard changed in September 2025

NIST published SP 800-88 Revision 2 on 26 September 2025 and withdrew Revision 1, which had stood since 2014. The shift matters for how you write policy and contracts. Revision 2 is organised around establishing a media sanitisation programme rather than picking a method from a table; apart from cryptographic erase, it replaces technique-level detail with a requirement to comply with IEEE 2883, NSA specifications, or an organisationally approved standard; it separates verification from validation; and it expects digital audit trails supporting traceability. It also confirms that a single overwrite pass is sufficient on modern hard drives, retiring the three- and seven-pass folklore.

Reformatting remains inadequate on an SSD, where wear levelling can leave data in blocks the operating system no longer references. If your provider contract still references Revision 1, it is citing a withdrawn document.

Legal holds must stop the wipe

If a departing employee is subject to litigation, investigation, audit, or regulatory inquiry, a routine offboarding wipe can destroy information you are required to preserve. The workflow needs a flag that halts automated sanitisation and routes the device into a preservation path before any destructive command is issued.

What Indian law expects

The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 and phase in over roughly 18 months, with the security-safeguard and breach-notification obligations landing in the final phase. The framework requires notification to the Data Protection Board without delay on becoming aware of a personal data breach, a detailed report within 72 hours, and communication to affected individuals; the Act’s schedule provides penalties of up to Rs 250 crore for failures of reasonable security safeguards. Separately and already in force, the CERT-In directions of 2022 require specified cyber incidents to be reported within six hours of noticing them.

The retrieval process also handles personal data of its own — employee name, home address, personal phone number, availability. Establish what your provider receives, who can access it, which subcontractors see it, how long it is retained, and when it is deleted. A device that was encrypted and is documented as cryptographically erased is a materially different conversation from one that simply disappeared. This section is informational rather than legal advice.

Chain of custody and the employee experience

Chain of custody answers who held the device, when responsibility transferred, where it travelled, and who has it now. Tracking numbers do not do that on their own.

Stage Evidence
Asset identified Serial number and asset tag matched to the assignment record
Employee notified Communication record with date and deadline
Handoff completed OTP, signature, scan, or photographed confirmation
Shipment accepted Carrier scan and tracking reference linked to the serial
Delivery completed Proof of delivery at a named facility
Facility receipt Warehouse or technician acknowledgement
Device verified Serial reconciliation against the expected asset
Condition assessed Inspection record, damage or clearance report
Data sanitised Erasure evidence tied to the serial number
Asset closed Final disposition recorded: stored, redeployed, resold, or recycled

Recovery rates also depend on how little the process asks of the departing employee. They should not have to choose a courier, pay for shipping, find a box, print documentation, or coordinate between HR, IT, and a logistics vendor. One set of instructions, packaging provided, a pickup slot they choose, visible tracking, and a confirmation that their obligation is closed.

Non-response needs a defined cadence rather than an indefinite “awaiting employee” status — for example initial request at day zero, reminder at day two, second attempt at day five, escalation to HR or the reporting manager at day seven, with thresholds beyond that set by policy and asset value. Adjust the timings to your notice periods, but keep the principle: every aging case has an owner and a next action.

India on the ground: logistics, reuse, and end of life

India is one country and several logistics scenarios. Collecting a MacBook in Bengaluru, Hyderabad, Pune, Mumbai, Chennai, or Delhi NCR is routine. Tier-2 and tier-3 cities, the North East, and remote areas need longer windows, verified serviceability, and more careful address confirmation — particularly for employees who relocate to a hometown during their notice period, which is one of the most common reasons a pickup fails. Ask a provider which postcodes are serviceable, whether pickup SLAs differ by location, who schedules the employee, whether high-value shipments can be insured above standard carrier liability, and how carrier exceptions get escalated. “Do you operate in India?” is the wrong question. “Can you execute our workflow in the locations where our people actually live?” is the right one.

Recovered devices should move quickly into their next state, and in India the case for redeployment is stronger than in most markets. Importing a replacement laptop involves an Importer Exporter Code, BIS requirements, and duty, while a device already in the country can reach the next hire in days. Exporting a used laptop out of India creates an export event and a fresh import wherever it lands, usually costing more than the device is worth. For most distributed companies the right default is to hold Indian stock in India and redeploy it there, which turns retrieval into the supply line for domestic IT procurement rather than a cost centre. That only works if procurement can see recovered inventory — specification, condition, age, warranty, location — before it raises a new order.

For devices past useful life, the E-Waste (Management) Rules, 2022 have applied since 1 April 2023. A bulk consumer — an entity that has used at least 1,000 units of listed equipment at any point in a financial year — must hand e-waste only to a registered producer, refurbisher, or recycler. Ask which registered entity actually receives the device and what documentation comes back: serial number, final disposition, sanitisation record, refurbishment or recycling evidence, and date of processing. No retired corporate laptop should disappear into an informal disposal channel, and no serial should end its life with a status of simply “disposed”.

Choosing a provider

Provider type Examples Best suited for
Global device lifecycle platform GroWrk, Firstbase, Workwize, allwhere Distributed companies wanting retrieval connected to asset records, storage, redeployment, and the same process in other countries
India logistics and IT asset movement Bombax and similar domestic providers Companies that mainly need domestic collection and reverse logistics
National courier Regional and national carriers Teams prepared to own employee communication, escalation, receipt, and reconciliation themselves
Registered ITAD provider Refurbishment and recycling specialists Equipment already recovered and ready for retirement
Internal IT team Company-managed workflow Businesses with enough local staff and storage to run retrieval directly

Score candidates rather than compare pickup prices. The weights below load toward chain of custody and security because those are the areas where failure is expensive and cannot be corrected after the fact.

Capability Weight What good looks like
Chain of custody 15% Documented handoff from employee through facility receipt, tied to serials
Security and sanitisation 15% Access controls, incident process, erasure evidence aligned to SP 800-88r2
India pickup coverage 10% Stated serviceability and timelines across your actual employee locations
Employee communication 10% Provider owns outreach, scheduling, reminders, and status
Packaging and logistics 10% Packaging supplied, printerless options, tracked home pickup
Asset reconciliation 10% Serial-level verification feeding your asset record
Escalation management 10% Named owner and thresholds for missed pickups and non-response
Lifecycle services 10% Storage, repair, redeployment, resale, and registered-channel retirement
Integrations 5% HR, ITSM, identity, and MDM events triggering physical workflows
Reporting 5% Recovery aging, performance, and final outcomes per serial

Ten questions worth asking:

  1. Which Indian cities and postcodes can you actually service, and do SLAs differ?
  2. Who contacts the departing employee, and how soon after notice?
  3. Do you verify the assigned equipment and serial before pickup?
  4. How do you prove employee handoff?
  5. What happens after a failed pickup, and how is non-response escalated?
  6. What is your documented recovery rate, and over what window?
  7. How do you reconcile serial numbers on receipt, and what evidence do we get?
  8. Which sanitisation standard do you work to, and how is the certificate issued?
  9. Where are recovered devices stored, who can access them, and which subcontractors participate?
  10. Can you store and redeploy inside India, and which registered entity handles end of life?

Be cautious of any provider that defines recovery as a label generated, marks an asset recovered at courier pickup, cannot track serial numbers, expects your IT team to chase employees, has no process for missed collections, cannot explain its subcontractors, treats remote wipe as guaranteed, cannot support legal-hold exceptions, stores devices without inventory visibility, or uses disposal channels it will not name. A provider’s exception workflow tells you more than its standard one.

Who GroWrk is best suited for

GroWrk is a device lifecycle platform for distributed companies that want recovery in India to run as part of one global operation covering procurement, deployment, retrieval, storage, redeployment, and retirement. It fits teams with engineering or support staff across several Indian cities, companies where offboarding has become a recurring source of asset loss, and IT organisations that need the same workflow and serial-level record in India as everywhere else they hire.

A domestic courier is enough if you need one laptop collected in one city and your team will handle everything before and after the shipment. GroWrk also does not replace an MDM platform or your legal and privacy functions. The case for a lifecycle partner starts when devices, systems, borders, and exceptions have to be handled together. GroWrk supports the physical device lifecycle in India and across more than 150 countries.

Frequently asked questions

Which providers can recover company devices from employees in India after offboarding?

Global device lifecycle platforms including GroWrk, Firstbase, Workwize, and allwhere manage recovery in India as part of a wider lifecycle service. India-focused reverse-logistics providers such as Bombax handle pickup, movement, and chain-of-custody documentation, and registered ITAD firms handle end-of-life processing. The services are not equivalent: a courier gives you transportation and a tracking number, while a lifecycle provider should give you employee outreach during the notice period, printerless return options, home pickup across metro and tier-2 locations, chain-of-custody proof tied to serial numbers, sanitisation evidence, domestic storage and redeployment, and a closed asset record. Ask any provider for a documented recovery rate and the window over which it is measured.

Can an Indian employer withhold full and final settlement until the laptop is returned?

Not as a general practice. Since the labour codes took effect on 21 November 2025, Section 17(2) of the Code on Wages requires wages payable on resignation, removal, dismissal, retrenchment, or closure to be paid within two working days of the last working day. Deductions are limited to the categories the Code specifies, cannot exceed 50 percent of wages in a wage period, and any deduction for loss or damage needs a documented basis in the terms the employee accepted at hiring rather than a policy applied after they resign. The workable approach is to complete retrieval inside the notice period and treat an unreturned device as a separate recoverable rather than a gate on settlement. Confirm the position with your employment counsel before relying on any deduction.

Should we remote wipe a laptop before it is collected?

Usually yes for a standard exit, with two important caveats. If the employee is subject to a legal hold, audit, or investigation, suspend wipe commands and preserve the device. And never assume the wipe worked: the command only completes if the device remains enrolled, comes online, receives the instruction, and finishes the action, so keep evidence of the result and reconcile it when the hardware arrives. On encrypted devices, cryptographic erase destroys the key and renders the remaining data unreadable, which is faster and more defensible than an overwrite. Reformatting an SSD is not sanitisation, because wear levelling can leave data in unreferenced blocks.

Which data sanitisation standard should we require in 2026?

NIST SP 800-88 Revision 2, published on 26 September 2025, which superseded and withdrew Revision 1. Revision 2 is built around running a media sanitisation programme rather than selecting a technique from a table: other than cryptographic erase, it points to IEEE 2883, NSA specifications, or an organisationally approved standard, separates verification from validation, and expects digital audit trails for traceability. It also confirms single-pass overwrite is adequate on modern hard drives. If a provider contract or internal policy still cites Revision 1, it references a withdrawn document and should be updated.

What should happen to a recovered laptop at end of life in India?

Inspect it, sanitise it with evidence tied to the serial number, then redeploy, resell, refurbish, or hand it to a registered recycler. Under the E-Waste (Management) Rules, 2022, in force since 1 April 2023, a bulk consumer — an entity using at least 1,000 units of listed equipment at any point in a financial year — must channel e-waste only to registered producers, refurbishers, or recyclers. Ask which registered entity receives the device and what documentation returns to you. Given duty, BIS requirements, and the Importer Exporter Code on replacement hardware, redeploying a serviceable device inside India is usually the better commercial outcome than retiring it.

Can an MDM platform recover a company laptop?

No. MDM secures and manages the endpoint — policies, configuration, applications, and remote lock or wipe on a device that is enrolled and reachable. It cannot collect the laptop from the employee, transport it, inspect it, reconcile a serial number, store it, repair it, or redeploy it. The two layers are complementary, and the dependency runs in one direction worth noting: an unenrolled or offline device is beyond MDM’s reach entirely, which is exactly when physical recovery becomes the only remaining control.

Device recovery in India is no longer a payroll negotiation with a courier attached. The two-day settlement rule moved the leverage, the DPDP framework raised the evidentiary bar, SP 800-88r2 changed what counts as proof, and the e-waste regime made disposition something you must document. The companies that recover reliably start during the notice period, make returning effortless, and can show what happened to every serial number afterwards.

Book a demo