ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 5. ISO 27001 Annex A - 8 ...
  5. ISO 27001 Annex A 8.10 Information deletion

ISO 27001 Annex A 8.10 Information deletion

What is ISO 27001 Annex A 8.10 – Information Deletion?

ISO 27001 Annex A 8.10 focuses on ensuring that information is deleted when it is no longer required, in accordance with the organization’s information-retention requirements and applicable obligations.

Information can exist in many places, including:

  • Production databases
  • File storage
  • Cloud storage
  • SaaS applications
  • Email
  • Backups
  • Logs
  • Endpoints
  • Mobile devices
  • Source-code repositories
  • Collaboration platforms
  • Customer environments
  • Paper records
  • Removable media

Information deletion is therefore more than simply pressing Delete on a computer.

The organization should understand:

  • What information it holds
  • Why it is retaining the information
  • How long it should be retained
  • When it should be deleted
  • Where copies may exist
  • Who can authorize deletion
  • How deletion is performed
  • How deletion is verified where appropriate

Simple Explanation

Do not keep information forever without a reason. When information is no longer required, delete it appropriately and securely.


Why is Information Deletion Important?

Organizations continuously accumulate information.

For example, a SaaS startup may collect:

  • Customer account information
  • Employee records
  • Contracts
  • Support tickets
  • Application logs
  • Security logs
  • Marketing data
  • Financial records
  • Backup data
  • Development data
  • Test data

If information is retained indefinitely, the organization may create unnecessary:

  • Privacy risk
  • Security risk
  • Storage costs
  • Compliance obligations
  • Data-breach exposure
  • Legal and contractual risk

Example

A former customer closed its account two years ago.

If unnecessary customer information remains in:

Production Database
        +
Analytics Database
        +
File Storage
        +
Support Platform
        +
Development Environment
        +
Old Export
        +
Backups

the organization may still be holding information that it no longer needs.

Simple Principle

If you do not need the information, there should be a reason for keeping it.


What Does Annex A 8.10 Require?

The organization should establish appropriate processes for deleting information when it is no longer required.

Deletion should consider:

  • Business requirements
  • Information classification
  • Retention requirements
  • Legal obligations
  • Regulatory requirements
  • Contractual requirements
  • Customer commitments
  • Privacy requirements
  • Security requirements
  • Backup arrangements
  • Technical limitations

The organization should determine what needs to be deleted, when, how, and from which systems.

ISO 27001 does not require every piece of information to be deleted immediately.

Some information may need to be retained because of:

  • Legal requirements
  • Tax requirements
  • Financial reporting
  • Contracts
  • Regulatory requirements
  • Audit requirements
  • Business needs
  • Litigation or legal holds

Therefore:

Deletion should be controlled by the organization’s retention and information-management requirements.


Information Deletion vs Data Retention

These controls work together.

Data Retention

Defines:

How long should information be kept?

Information Deletion

Defines:

What happens when the retention period ends?

Example:

Customer Account Closed
        ↓
Retention Period
        ↓
Retention Period Ends
        ↓
Deletion Eligibility
        ↓
Delete Information
        ↓
Verify / Record

What Information Should Be Deleted?

Potential examples include:

Customer Information

  • Inactive customer accounts
  • Customer contact information
  • Customer support information
  • Customer-provided files

Employee Information

  • Information that is no longer required
  • Temporary HR records
  • Old recruitment information

Subject to applicable retention obligations.

Technical Information

  • Temporary files
  • Old exports
  • Test data
  • Temporary development databases
  • Unnecessary logs

Marketing Information

  • Unnecessary campaign data
  • Old prospect information
  • Duplicate records

Application Data

  • Deleted user records
  • Temporary application data
  • Expired sessions
  • Temporary processing data

Important: Deletion Is Not the Same as Hiding Information

Deleting information from the user interface does not necessarily mean it has been deleted from the underlying systems.

For example:

User Deletes Account
        ↓
Record Removed From Application
        ↓
But...
        ↓
Database Backup
        +
Analytics Platform
        +
Support Platform
        +
Logs
        +
Exports

The organization should understand where relevant copies exist and how deletion applies to those environments.


Activities Required to Implement Annex A 8.10

1. Identify the Information You Hold

Start with information inventory and data mapping.

Identify:

  • Customer data
  • Employee data
  • Financial information
  • Business records
  • Security information
  • Source code
  • Logs
  • Backups
  • Development data
  • Test data
  • Documents
  • Emails

This connects closely with:

A.5.9 – Inventory of Information and Other Associated Assets


2. Identify Where Information Exists

Information may be distributed across many systems.

For example:

InformationPossible Location
Customer DataProduction Database
Customer DocumentsCloud Storage
Support DataTicketing System
Employee DataHR Platform
Financial RecordsAccounting System
Source CodeGit Repository
LogsLogging Platform
BackupsBackup Storage
EmailsEmail Platform

Deletion processes should take these locations into account.


3. Define Retention Requirements

Before deleting information, determine how long it should be retained.

A retention schedule may look like:

InformationRetentionDisposal Trigger
Customer Account DataDefined by business/legal requirementEnd of retention period
Support RecordsDefined periodRetention expiry
Marketing LeadsDefined periodRetention expiry
Financial RecordsApplicable legal requirementLegal retention expiry
Temporary Test DataShort periodTesting completed
Application LogsDefined operational/security periodRetention expiry

These are examples only.

Actual retention periods should be determined according to applicable business, legal, regulatory, contractual, and privacy requirements.


4. Identify Deletion Triggers

Deletion can be triggered by:

  • Retention period expiry
  • Customer request where applicable
  • Contract termination
  • Employee lifecycle
  • Project completion
  • End of business purpose
  • Data becoming obsolete
  • Duplicate information
  • Disposal of an information-processing asset

Not every trigger automatically means immediate deletion.

Legal or contractual requirements may require information to be retained.


5. Define Deletion Methods

Deletion methods depend on the type of information and storage technology.

Examples include:

Database

  • Delete records
  • Apply approved data-retention jobs
  • Remove associated records where appropriate

Cloud Storage

  • Delete files
  • Delete objects
  • Apply lifecycle policies

SaaS Applications

  • Use platform deletion functionality
  • Configure retention settings
  • Request deletion from the provider where required

Endpoints

  • Securely delete information
  • Follow media sanitization requirements

Paper

  • Secure destruction/shredding

6. Consider Backups

Backups require special attention.

A customer record may be deleted from production while historical backups continue to contain the information for a defined period.

Organizations should define how backup retention interacts with deletion.

For example:

Production Data Deleted
        ↓
Backup Still Exists
        ↓
Backup Retention Period
        ↓
Backup Expires / Is Overwritten
        ↓
Information No Longer Retained

Organizations should not necessarily restore deleted production data simply because it exists in an old backup.

The approach should be documented and consistent with applicable requirements.


7. Consider Replicated Data

Modern systems frequently replicate information.

Examples include:

  • Primary database
  • Read replicas
  • Disaster-recovery environments
  • Analytics platforms
  • Search indexes
  • Caches
  • Data warehouses

The deletion process should consider relevant copies.


8. Consider Development and Test Environments

One common problem is production data being copied into development environments.

For example:

Production Customer Database
             ↓
       Data Export
             ↓
      Development DB
             ↓
       Old Copy Remains

Where production data is used for testing, organizations should consider:

  • Whether it is necessary
  • Access restrictions
  • Data minimization
  • Masking/anonymization
  • Retention
  • Deletion

This is especially important when the information contains sensitive or personal information.


9. Automate Deletion Where Appropriate

Automation can reduce human error.

Examples:

  • Database retention jobs
  • Cloud storage lifecycle policies
  • Automated account deletion workflows
  • Log-retention policies
  • SaaS retention settings
  • Automated cleanup jobs

For example:

Retention Period Reached
        ↓
Automated Eligibility Check
        ↓
Deletion Job
        ↓
Execution Log
        ↓
Monitoring

Automation should be tested and monitored appropriately.


10. Control Manual Deletion

Some information may require manual deletion.

Manual deletion should have appropriate:

  • Authorization
  • Process
  • Validation
  • Recordkeeping

For example:

Request → Approval → Deletion → Verification → Record


11. Protect Information During Deletion

Deletion activities themselves should be secure.

Organizations should prevent:

  • Unauthorized deletion
  • Accidental deletion
  • Deletion of records that must be retained
  • Manipulation of deletion records

Appropriate access controls and approvals should be applied to sensitive deletion activities.


12. Handle Legal Holds and Exceptions

Information should not be deleted simply because a retention period has expired if there is a valid reason to preserve it.

Examples:

  • Litigation hold
  • Regulatory investigation
  • Legal requirement
  • Audit requirement
  • Contractual requirement

The organization should have an exception or legal-hold process where relevant.


Startup Example

Example: 40-Person SaaS Company

The company uses:

  • AWS
  • PostgreSQL
  • Google Workspace
  • Slack
  • CRM
  • Support platform
  • GitHub
  • Cloud backups
  • Analytics platform

A customer closes its account.

Poor Approach

The company disables the account but retains customer data indefinitely across multiple systems.

Better Approach

Customer Account Closed
        ↓
Identify Relevant Data
        ↓
Check Retention Requirements
        ↓
Identify Systems Holding Data
        ↓
Delete Eligible Data
        ↓
Apply Backup Retention Rules
        ↓
Verify Deletion Where Appropriate
        ↓
Record Completion

This creates a controlled deletion lifecycle.


Information Deletion Register

A startup can maintain a simple register:

IDInformationSystemTriggerRetentionActionStatus
DEL-001Customer DataProduction DBAccount closureDefined periodDeleteCompleted
DEL-002Support DataTicketingRetention expiryDefined periodDeletePending
DEL-003Test DataDev DBTest completionShort periodDeleteCompleted
DEL-004Marketing DataCRMRetention expiryDefined periodDeleteScheduled

Example Data Retention and Deletion Matrix

Data CategoryBusiness PurposeRetention BasisDeletion TriggerOwner
Customer Account DataService deliveryBusiness/contractual requirementsRetention expiryProduct/IT
Support RecordsCustomer supportBusiness/contractual requirementsRetention expirySupport
Employee RecordsHRLegal/business requirementsRetention expiryHR
Financial RecordsAccountingLegal requirementsLegal retention expiryFinance
Application LogsSecurity/operationsSecurity/operational requirementsRetention expirySecurity/IT
Test DataTestingTesting purposeTest completionEngineering

Actual retention periods should be determined for the organization rather than copied from generic examples.


Audit Evidence for Annex A 8.10

An auditor may request:

Policies

  • Information Retention Policy
  • Information Deletion Policy
  • Data Lifecycle Management Procedure
  • Data Disposal Procedure

Data Mapping

  • Information inventory
  • Data-flow diagrams
  • Data-location inventory
  • Application inventory

Retention

  • Retention schedule
  • Data-retention matrix
  • Business/legal retention requirements

Deletion

  • Deletion procedures
  • Automated deletion configurations
  • Deletion logs
  • Deletion records
  • Customer-account deletion records
  • Secure disposal records

Technical Evidence

  • Database retention jobs
  • Cloud lifecycle rules
  • SaaS retention settings
  • Log-retention configuration
  • Backup retention configuration

Exception Evidence

  • Legal holds
  • Deletion exceptions
  • Approved retention extensions

ISO 27001 Annex A 8.10 Audit Checklist

QuestionYes/NoEvidence
Is information retention defined?Retention schedule
Is information mapped to systems?Data inventory
Are deletion requirements defined?Procedure
Are deletion triggers identified?Retention matrix
Are obsolete/expired records deleted?Deletion records
Are automated deletion mechanisms used where appropriate?System configuration
Are backups considered?Backup policy
Are replicated copies considered?Data-flow documentation
Is development/test data addressed?Dev/test procedure
Is deletion access restricted?Access controls
Are legal holds considered?Legal-hold process
Are deletion exceptions documented?Exception register
Can deletion activities be demonstrated?Logs/records
Is the deletion process periodically reviewed?Review evidence

Common Mistakes

1. “Delete” Means Deleted Everywhere

Removing a record from an application does not necessarily remove all copies.


2. Keeping Everything Forever

Organizations sometimes retain data simply because storage is inexpensive.

Cheap storage does not eliminate security and compliance risks.


3. No Retention Schedule

Without defined retention requirements, deletion becomes inconsistent.


4. Ignoring Backups

Production deletion and backup retention should be considered together.


5. Ignoring Development Environments

Copies of production data may remain in:

  • Test databases
  • Developer machines
  • Data exports
  • Analytics environments

6. No Deletion Evidence

An organization may have a deletion process but be unable to demonstrate that it actually operates.


7. Deleting Information That Must Be Retained

Deletion must consider:

  • Legal requirements
  • Regulatory requirements
  • Contracts
  • Audits
  • Legal holds

8. Manual Deletion Without Controls

Uncontrolled manual deletion can result in:

  • Accidental deletion
  • Unauthorized deletion
  • Incomplete deletion
  • Lack of evidence

9. Ignoring SaaS Providers

Information may exist in third-party systems.

Organizations should understand the deletion and retention capabilities of relevant suppliers.


Information Deletion for Startups

A startup does not need a complicated enterprise data-destruction system.

Start with five questions:

1. What information do we hold?

Create a practical data inventory.

2. Where is it stored?

Identify databases, SaaS platforms, cloud storage, backups and other relevant locations.

3. Why are we keeping it?

Document the business, legal, contractual, regulatory, or operational reason.

4. When should it be deleted?

Define appropriate retention requirements.

5. How do we delete it?

Document the appropriate technical or physical method.


Practical Startup Implementation Model

A simple lifecycle is:

Identify → Classify → Retain → Trigger → Delete → Verify → Record → Review

Identify

Know what information you have.

Classify

Understand its sensitivity and importance.

Retain

Define how long it needs to be kept.

Trigger

Identify when deletion becomes applicable.

Delete

Use an appropriate deletion method.

Verify

Confirm deletion where appropriate.

Record

Maintain evidence of important deletion activities.

Review

Periodically review retention and deletion requirements.


Policy vs. Process vs. Evidence

TypeExample
PolicyInformation shall be retained and deleted according to defined requirements
ProcessEligible information is identified and deleted after the retention period
StandardCustomer information is subject to defined retention requirements
Technical ControlAutomated database deletion job
ConfigurationCloud storage lifecycle rule
EvidenceDeletion log
RecordDeletion register
ExceptionApproved legal hold

The important audit trail is:

Retention Requirement → Deletion Trigger → Deletion Action → Verification/Evidence


A.8.10 vs A.7.14 – Secure Disposal or Re-use of Equipment

These controls can look similar but address different things.

ControlFocus
A.8.10Deletion of information
A.7.14Secure disposal or re-use of equipment

Example

Deleting customer information from a database:

A.8.10

Securely wiping a laptop before giving it to another employee:

A.7.14

Both may apply when information exists on physical equipment.


A.8.10 vs A.7.10 – Storage Media

ControlFocus
A.7.10Managing storage media
A.8.10Deleting information

For example:

Protecting a USB drive containing confidential information:

A.7.10

Deleting information when it is no longer required:

A.8.10


A.8.10 vs A.5.33 – Protection of Records

ControlFocus
A.5.33Protecting records
A.8.10Deleting information when no longer required

Records that must legally or contractually be retained should not be deleted simply because they are old.


A.8.10 vs A.5.34 – Privacy and Protection of PII

Where personal information is involved, deletion should also consider applicable privacy requirements and commitments.

For example:

Personal Information
       ↓
Purpose / Requirement
       ↓
Retention Period
       ↓
Deletion Eligibility
       ↓
Secure Deletion

Privacy requirements may establish specific deletion or retention obligations depending on the applicable jurisdiction and circumstances.


Questions an Auditor May Ask

1. How do you determine what information should be deleted?

Show the retention/deletion process.

2. How do you know where information exists?

Show data inventories and system mapping.

3. What happens when a customer leaves?

Demonstrate the customer-data lifecycle.

4. How do you handle backups?

Show backup retention and deletion arrangements.

5. How do you handle replicated information?

Show relevant data flows and system processes.

6. How do you handle test data?

Show development/test-data controls.

7. How do you prevent unauthorized deletion?

Show access controls and authorization.

8. How do you handle legal holds?

Show the exception/legal-hold process.

9. How do you demonstrate that information was deleted?

Show logs, deletion records, automated jobs, or other appropriate evidence.

10. Who owns information retention and deletion?

Show defined responsibilities.


Useful Resources

Organizations implementing Annex A 8.10 may maintain:

  1. Information Retention and Deletion Policy – [Insert Draft Document Link]
  2. Information Deletion Procedure – [Insert Draft Document Link]
  3. Data Retention Schedule – [Insert Draft Document Link]
  4. Data Retention and Deletion Matrix – [Insert Draft Document Link]
  5. Information/Data Inventory – [Insert Draft Document Link]
  6. Data Flow Diagram – [Insert Draft Document Link]
  7. Deletion Request Form – [Insert Draft Document Link]
  8. Deletion Register – [Insert Draft Document Link]
  9. Data Deletion Verification Checklist – [Insert Draft Document Link]
  10. Backup Retention Procedure – [Insert Draft Document Link]
  11. Data Deletion Exception Form – [Insert Draft Document Link]
  12. Information Deletion Audit Checklist – [Insert Draft Document Link]

Startup-Focused Quick Summary

A startup can implement A.8.10 using a straightforward lifecycle:

1. Identify
Know what information you hold.

2. Map
Know where it is stored and replicated.

3. Define Retention
Determine how long it needs to be kept.

4. Identify Triggers
Know when deletion becomes applicable.

5. Delete
Use an appropriate deletion method.

6. Consider Backups
Define how backup retention interacts with deletion.

7. Verify
Confirm important deletion activities where appropriate.

8. Document
Maintain sufficient evidence.


Startup-Focused Final Takeaway

ISO 27001 Annex A 8.10 is about preventing organizations from becoming permanent warehouses for information they no longer need.

A practical startup should be able to answer:

What information do we have?

Where is it stored?

Why are we keeping it?

How long should we keep it?

What triggers deletion?

How do we delete it?

How do we handle backups and copies?

The objective is not to delete information blindly.

It is to establish a controlled information lifecycle:

Create → Use → Retain → Review → Delete

For a cloud-native SaaS company, effective implementation can combine data inventories, retention schedules, automated lifecycle policies, database deletion processes, SaaS retention controls, backup policies, and appropriate deletion evidence.

One-Line Summary

ISO 27001 Annex A 8.10 ensures that information is retained only as long as necessary and is appropriately deleted when it is no longer required, while considering legal, regulatory, contractual, business, privacy, and security requirements.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *