Traceability is one of those words that survives a meeting without being defined. A regulator, a corporate client and a certification auditor will each ask a refurbishment operation whether it has it, and each will be satisfied by something different. Building a record that answers only one of the three is the common and expensive mistake, because the three demands arrive at different moments and the data cannot be reconstructed afterwards.
The regulator wants a destination, per device
European waste law is built on a distinction that is decided on the shop floor: equipment prepared for reuse leaves the waste stream, equipment sent for recycling does not. WEEE reporting depends on it, and the two outcomes are counted separately.
That makes the disposition decision a reportable fact rather than an internal one. An operation that records tonnage by category can report; an operation that also records which devices left as working products can substantiate the reuse side of that report.
The direction of travel tightens it further. The ESPR framework attaches a machine-readable Digital Product Passport to products, carrying composition, repair and compliance information across the product life, with the EU central registry live since 19 July 2026 and electronics addressed through delegated acts. The relevant point for an operation today is not the deadline but the data: repair history per device is becoming a deliverable, and history that was never captured cannot be produced later.
The corporate buyer wants a discharge of liability
A company handing over retired equipment is transferring a data-protection problem. What it needs back is evidence that the problem was disposed of, unit by unit, in a form it can hand to its own auditors.
That means a certificate attached to an identifier, not a statement about a batch. It also means the negative cases: a drive that failed sanitisation and went to physical destruction is a result that has to be documented, not an absence in the record. An inventory where forty devices were received and thirty-nine certificates exist raises exactly the question nobody wants to answer a year later.
The identifier matters more than it looks. A serial number answers manufacturer, warranty and part-compatibility questions; an IMEI is what a network operator and a stolen-device blocklist recognise. Phones need both on the same record, captured at intake, because checking a handset against a blocklist after repair means the effort is already spent.
The auditor wants to sample and follow
A certification auditor does not read your whole record. They pick a small number of items, follow them end to end, and judge the system by whether the trail holds.
What they are testing is not completeness of data but control of the process: that a record exists, that it is dated, that the person who made the entry was competent to make it, that the procedure in force at the time is identifiable, and that nothing can have been altered afterwards without a trace.
This is why an audit trail is a different object from a log. It has to be complete enough that the absence of an entry means nothing happened, and tamper-evident enough that a later alteration is detectable - commonly by chaining entries so each carries a fingerprint of the previous one. Segregation of duties sits alongside it: a trail showing one person raised, approved and closed an action is honest, and still a finding.
Why lot-level tracking fails all three
Tracking by pallet or by lot is cheaper and covers ordinary operations. It fails in the same way for each of the three parties, and the failure is always retrospective.
The regulator asks how many devices were reused rather than recycled, and a lot-level record can only estimate. The buyer asks for the certificate for one specific asset tag, and the lot record cannot isolate it. The auditor samples one device, and the trail stops at the pallet.
The cost is not the migration to per-device tracking. It is that the first months or years of history are simply gone, and those are usually the months a client, a certification body or a business case needs.
What a record has to carry
Reduced to essentials, one device record that satisfies all three parties holds: the identifiers - serial number and IMEI where it exists, plus the client asset tag; the origin, meaning which client and which arrival; the state at intake as assessed, not as declared; the data outcome, with the certificate or the documented destruction; the work done, with parts consumed and the procedure version applied; the grade, against written criteria; the disposition - resold, dismantled, recycled; and the trail of who did what and when.
None of those is exotic. What makes them hard is that they have to be captured at the moment the work happens, by people whose job is repairing devices rather than maintaining records - which is a system design problem more than a discipline problem.
The practical test is the one an auditor will apply anyway. Pick a serial number at random and produce its full history, evidence included, while the person asking is still in the room.