Orlando Office Relocations

When an Orlando business relocates offices, downsizes, or consolidates space, the checklist usually covers the obvious things: movers, IT cutover, updating the address with vendors and clients. What gets missed more often than it should is what happens to the data sitting on the equipment that isn't making the move.


Old desktops, decommissioned servers, retired laptops, and even office copiers and multifunction printers routinely get shuffled into a storage closet, donated, sold secondhand, or left behind for the new tenant to deal with. Every one of those devices can still hold data: employee records, client files, financial information, scanned documents. A relocation is exactly the kind of trigger event that creates a compliance blind spot, because the move itself becomes the priority and data destruction gets treated as an afterthought.


Why Office Moves Are a Higher-Risk Moment

During a normal operating year, IT asset disposal tends to happen in small batches, one or two machines at a time, as equipment is individually retired. A relocation compresses that into a single event: dozens of devices going into boxes at once, often handled by movers or staff who aren't thinking about what's stored on the drives inside them.


That compression is what raises the risk. A hard drive that gets tossed in a dumpster, sold at a surplus auction without being wiped, or simply left in a filing cabinet in the old space isn't a hypothetical, it's one of the more common ways sensitive business data ends up exposed. Several federal and state rules treat "we didn't get around to it during the move" as exactly the kind of negligence they were written to prevent, and none of them pause their requirements just because a business is mid-relocation.


What the Law Actually Requires

This isn't optional best practice, it's regulation with specific disposal requirements attached, and which rules apply depends on what kind of business you run.


If your business uses consumer reports (background checks on employees or tenants, credit checks, insurance applications), the FTC's Disposal Rule under the Fair and Accurate Credit Transactions Act (FACTA) applies. It requires "reasonable measures" to dispose of that information, which the FTC defines specifically as burning, pulverizing, or shredding paper records, and destroying or erasing electronic files and media so the information can't be read or reconstructed. The rule's reach is broader than most businesses assume: it explicitly covers landlords, employers, debt collectors, and attorneys who pull background checks, not just banks and lenders (FTC, Disposing of Consumer Report Information).


If your business qualifies as a "financial institution" under the FTC Safeguards Rule, a category that includes mortgage brokers, finance companies, tax preparers, collection agencies, and credit counselors, not just banks, you're required to securely dispose of customer information no later than two years after you last used it, with limited exceptions (FTC Safeguards Rule).


Every business in Florida falls under the Florida Information Protection Act, Florida Statute 501.171, which requires "reasonable measures" to dispose of customer records containing personal information by shredding, erasing, or otherwise modifying it so it can't be read. The same statute requires notifying the state within 30 days of discovering a breach, which is exactly the exposure a business is carrying if data walks out the door during a move and later surfaces somewhere it shouldn't (Florida Statute 501.171).


An office relocation, in other words, isn't just a logistics project. It's a moment where a business's disposal obligations under all of the above become concentrated into a few weeks.


It also tends to fall into a gap between departments. Facilities or operations usually owns the move itself, IT owns the equipment, and neither one is always the party thinking about regulatory disposal requirements. Assigning data destruction to a specific person, on a specific date, before the move begins, closes that gap. Leaving it as "someone will handle the old computers eventually" is how equipment ends up in a storage unit for six months, or worse, in a surplus sale.


What Proper Data Destruction Looks Like During a Move

The benchmark most organizations get measured against, formally or informally, is NIST Special Publication 800-88, the federal guideline for media sanitization. It breaks sanitization into three tiers: clearing (software-level overwriting), purging (methods like degaussing that go further), and destruction (physically disintegrating the media so recovery isn't possible). NIST finalized Revision 2 of the standard in September 2025, replacing the 2014 version many vendors still reference (NIST SP 800-88 Rev. 2).


In practice, for a relocating office, this comes down to a few concrete steps:


  • Inventory every data-bearing device before the move, not just computers and servers. Copiers, scanners, and multifunction printers almost always have internal hard drives that store scanned documents, and they're the easiest thing to overlook in a relocation.
  • Decide what gets destroyed versus sanitized for resale. Equipment with resale value can go through an IT asset recovery process, wiped and tested rather than shredded outright, so it isn't a pure loss.
  • Schedule destruction or pickup ahead of the move date, not after. Once boxes are in a truck or a storage unit, tracking what happened to which drive gets much harder.
  • Get documentation for every device, tied to serial numbers, not a generic disposal receipt. That documentation is what a business would actually need to produce if a regulator or a client asked how a specific piece of equipment was handled.


How OCM Recycle Handles This

OCM Recycle has been processing electronics recycling and data destruction out of its Oldsmar facility since 2004, and the process is built around the steps above rather than a generic recycling drop-off.


For a relocation specifically, the on-site recycling service means a team packs, tags, and transports equipment directly from the old location, so devices aren't sitting in a storage unit between the move and destruction. Data destruction is handled through DOD wiping, Active KillDisk software erasure, and physical hard drive shredding, with the facility able to process up to 45 hard drives at once, every device tracked by serial number, and a final disposition report provided for the compliance file.


For equipment that still has resale value, the IT asset recovery program tests and sorts retired equipment, destroys the drives regardless of resale status, and issues a Certificate of Recycling along with payment for anything worth reselling, typically within 30 days.


The company operates under ISO 9001:2015 (quality management) and ISO 14001:2015 (environmental management) certification, and Orlando is one of twelve Florida markets listed on its service area page, alongside Tampa, Miami, and Jacksonville.


None of this replaces legal advice on what a specific business's compliance obligations are, that depends on industry and what data is involved. But whatever those obligations turn out to be, the disposal side of them needs to get handled during the move, not worked around after the fact.


Frequently Asked Questions

Do we need to destroy hard drives if we're just moving offices, not going out of business? Yes. The rules above don't carve out an exception for "still operating." They apply any time data-bearing devices are being retired, sold, donated, or left behind, which is exactly what happens during a relocation even when the business itself continues uninterrupted.


What about the hard drive inside our office copier? It's one of the most commonly missed devices in a relocation. Most networked copiers and multifunction printers from the last 15 years store scanned document images on an internal drive, and it should go through the same destruction process as a computer hard drive, not get left behind for the new tenant or a leasing company to deal with.


Can we sell our old computers instead of destroying them? Yes. Through an IT asset recovery process, drives get wiped or destroyed first, then the sanitized hardware is tested and resold, so a business isn't choosing between compliance and recovering some value from retired equipment.


Who should own this internally, IT or facilities? Either can run it, but it should be one named person with a deadline, not a shared responsibility that falls to whoever remembers first. In practice this usually means IT identifies and inventories the data-bearing devices, while whoever is coordinating the move (facilities, an office manager, or an outside relocation coordinator) confirms destruction or pickup is scheduled before the move date, not left as a loose end for after.


Before You Book the Movers

If a relocation is on the calendar, the data destruction plan should be too, ideally scheduled before the moving company shows up, not squeezed in afterward. Businesses relocating in or around Orlando can contact OCM Recycle to schedule on-site pickup or destruction ahead of a move date, and have the documentation in hand before the old office is empty.