BG Beter Geregeld ICT
Security zonder IT-afdeling · 5 min leestijd · 21 July 2026

Trading in or passing on an old work phone: what should you wipe first?

An old device tends to leave the building faster than expected — passed to a colleague, traded in, or simply forgotten in a drawer. Here are the steps you really want to take before you let it go.

Summer is a classic time for a clear-out. Most businesses have a drawer full of old devices somewhere: the phone of a colleague who left last year, the spare handset that's quietly become a collection, or your own previous work phone that you "just wanted to hold on to for a bit". Some end up traded in, some go to family, and some find their way to the second-hand marketplace.

That's all fine. But those devices usually hold a lot more than people realise. And "just doing a factory reset" isn't always enough. Below is a practical sequence you can follow yourself.

What's actually on that device

Don't just think about photos and contacts. A phone used for work typically also contains:

  • Your email account, including its history
  • WhatsApp Business with client conversations
  • Authenticator apps with codes for your bank, accounting software, Microsoft 365, and possibly ten other services
  • Saved passwords in the browser
  • Access to shared folders (OneDrive, Google Drive, Dropbox)
  • Saved Wi-Fi networks, including those at client sites
  • Photos of receipts, contracts, and sometimes copies of passports

If you simply reset the device without signing out first, some accounts can remain actively linked — particularly with Apple and Google accounts, that can cause problems down the line.

The sequence to follow

1. Make a backup first — even if you think you don't need anything

Back up to iCloud, Google, or your computer. Not because you want to keep everything, but because you're guaranteed to remember something was on there a week later. A backup takes five minutes; regret takes an afternoon.

2. Move your authenticator app first

This is the step that gets skipped most often. If you use Google Authenticator or Microsoft Authenticator and you wipe your phone, you instantly lose all your 2FA codes for everything stored in it. You'll then spend hours on the phone with helpdesks trying to get back into your own accounts.

So migrate the authenticator to your new device first — or switch to a solution that syncs. Then check, service by service (bank, accounting software, Microsoft 365), that the new phone works before you wipe the old one.

3. Actively sign out of accounts

Go through your main accounts and manually deregister the device:

  • Apple ID (on iPhone: Settings → your name → Sign Out)
  • Google account (on Android: Settings → Accounts)
  • WhatsApp (Settings → Account → Delete My Account, if you're no longer using the number on this device)
  • Microsoft 365 / work account
  • Your password manager

The first one in particular matters: a reset device that's still linked to an Apple ID or Google account is unusable for the next owner. They'll come straight back asking you to fix it.

4. Remove the SIM card and memory card

Sounds obvious, yet it's regularly forgotten. The microSD card in Android devices in particular can have been sitting in the slot for years.

5. Only now: perform a factory reset

On modern devices, storage is wiped with encryption. This has been standard on iPhones for a long time, and on recent Android devices too. On older Android devices (say version 6 or earlier), it's worth filling the device with dummy data after the reset and resetting it again — or simply not reselling it at all.

6. Remove the device from your management environment

Do you use Microsoft 365 with Intune, or Apple Business Manager? The device will still be registered there. Remove it from the list, otherwise you'll keep counting licences for devices that are long gone.

Special case: a device belonging to a former employee

If the phone belonged to someone else, additional rules apply. It may contain private communications. You are not simply allowed to scroll through the photos or messages "to see what's on there". GDPR applies to devices once they're back in your possession too.

The safe approach: wipe the device completely without looking through it first. If you need to retain certain business data (emails, documents), retrieve it from the underlying cloud account — not from the device itself. This is part of a proper access check when someone leaves.

What if the device no longer works?

A broken phone might seem safer, but it isn't necessarily. The storage chip can still be read in a lab. For a typical SMB context, that's not something to lose sleep over — but it does mean: don't just toss a broken device into the nearest collection bin. Ask for a certificate of destruction when handing it in, or handle it through your supplier.

Quick summary

  1. Make a backup
  2. Move and test the authenticator
  3. Sign out of major accounts
  4. Remove the SIM and SD card
  5. Perform a factory reset
  6. Remove the device from your management environment

Fifteen minutes of work, in the right order. Undoing mistakes afterwards takes many times longer.

Want to have this kind of process properly sorted for phones, laptops, and accounts of former employees? Take a look at our access check. It ensures no "forgotten" devices or accounts are left floating around.

Onderwerpen

#security #offboarding #2Fa #Mobiel #Data Wissen

Volledige gids: Security for SMBs without an IT department: what should you do this quarter?

Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →