What is ISO 27001 Annex A 8.10 – Information Deletion?
ISO 27001 Annex A 8.10 focuses on ensuring that information is deleted when it is no longer required, in accordance with the organization’s information-retention requirements and applicable obligations.
Information can exist in many places, including:
- Production databases
- File storage
- Cloud storage
- SaaS applications
- Backups
- Logs
- Endpoints
- Mobile devices
- Source-code repositories
- Collaboration platforms
- Customer environments
- Paper records
- Removable media
Information deletion is therefore more than simply pressing Delete on a computer.
The organization should understand:
- What information it holds
- Why it is retaining the information
- How long it should be retained
- When it should be deleted
- Where copies may exist
- Who can authorize deletion
- How deletion is performed
- How deletion is verified where appropriate
Simple Explanation
Do not keep information forever without a reason. When information is no longer required, delete it appropriately and securely.
Why is Information Deletion Important?
Organizations continuously accumulate information.
For example, a SaaS startup may collect:
- Customer account information
- Employee records
- Contracts
- Support tickets
- Application logs
- Security logs
- Marketing data
- Financial records
- Backup data
- Development data
- Test data
If information is retained indefinitely, the organization may create unnecessary:
- Privacy risk
- Security risk
- Storage costs
- Compliance obligations
- Data-breach exposure
- Legal and contractual risk
Example
A former customer closed its account two years ago.
If unnecessary customer information remains in:
Production Database
+
Analytics Database
+
File Storage
+
Support Platform
+
Development Environment
+
Old Export
+
Backups
the organization may still be holding information that it no longer needs.
Simple Principle
If you do not need the information, there should be a reason for keeping it.
What Does Annex A 8.10 Require?
The organization should establish appropriate processes for deleting information when it is no longer required.
Deletion should consider:
- Business requirements
- Information classification
- Retention requirements
- Legal obligations
- Regulatory requirements
- Contractual requirements
- Customer commitments
- Privacy requirements
- Security requirements
- Backup arrangements
- Technical limitations
The organization should determine what needs to be deleted, when, how, and from which systems.
ISO 27001 does not require every piece of information to be deleted immediately.
Some information may need to be retained because of:
- Legal requirements
- Tax requirements
- Financial reporting
- Contracts
- Regulatory requirements
- Audit requirements
- Business needs
- Litigation or legal holds
Therefore:
Deletion should be controlled by the organization’s retention and information-management requirements.
Information Deletion vs Data Retention
These controls work together.
Data Retention
Defines:
How long should information be kept?
Information Deletion
Defines:
What happens when the retention period ends?
Example:
Customer Account Closed
↓
Retention Period
↓
Retention Period Ends
↓
Deletion Eligibility
↓
Delete Information
↓
Verify / Record
What Information Should Be Deleted?
Potential examples include:
Customer Information
- Inactive customer accounts
- Customer contact information
- Customer support information
- Customer-provided files
Employee Information
- Information that is no longer required
- Temporary HR records
- Old recruitment information
Subject to applicable retention obligations.
Technical Information
- Temporary files
- Old exports
- Test data
- Temporary development databases
- Unnecessary logs
Marketing Information
- Unnecessary campaign data
- Old prospect information
- Duplicate records
Application Data
- Deleted user records
- Temporary application data
- Expired sessions
- Temporary processing data
Important: Deletion Is Not the Same as Hiding Information
Deleting information from the user interface does not necessarily mean it has been deleted from the underlying systems.
For example:
User Deletes Account
↓
Record Removed From Application
↓
But...
↓
Database Backup
+
Analytics Platform
+
Support Platform
+
Logs
+
Exports
The organization should understand where relevant copies exist and how deletion applies to those environments.
Activities Required to Implement Annex A 8.10
1. Identify the Information You Hold
Start with information inventory and data mapping.
Identify:
- Customer data
- Employee data
- Financial information
- Business records
- Security information
- Source code
- Logs
- Backups
- Development data
- Test data
- Documents
- Emails
This connects closely with:
A.5.9 – Inventory of Information and Other Associated Assets
2. Identify Where Information Exists
Information may be distributed across many systems.
For example:
| Information | Possible Location |
|---|---|
| Customer Data | Production Database |
| Customer Documents | Cloud Storage |
| Support Data | Ticketing System |
| Employee Data | HR Platform |
| Financial Records | Accounting System |
| Source Code | Git Repository |
| Logs | Logging Platform |
| Backups | Backup Storage |
| Emails | Email Platform |
Deletion processes should take these locations into account.
3. Define Retention Requirements
Before deleting information, determine how long it should be retained.
A retention schedule may look like:
| Information | Retention | Disposal Trigger |
|---|---|---|
| Customer Account Data | Defined by business/legal requirement | End of retention period |
| Support Records | Defined period | Retention expiry |
| Marketing Leads | Defined period | Retention expiry |
| Financial Records | Applicable legal requirement | Legal retention expiry |
| Temporary Test Data | Short period | Testing completed |
| Application Logs | Defined operational/security period | Retention expiry |
These are examples only.
Actual retention periods should be determined according to applicable business, legal, regulatory, contractual, and privacy requirements.
4. Identify Deletion Triggers
Deletion can be triggered by:
- Retention period expiry
- Customer request where applicable
- Contract termination
- Employee lifecycle
- Project completion
- End of business purpose
- Data becoming obsolete
- Duplicate information
- Disposal of an information-processing asset
Not every trigger automatically means immediate deletion.
Legal or contractual requirements may require information to be retained.
5. Define Deletion Methods
Deletion methods depend on the type of information and storage technology.
Examples include:
Database
- Delete records
- Apply approved data-retention jobs
- Remove associated records where appropriate
Cloud Storage
- Delete files
- Delete objects
- Apply lifecycle policies
SaaS Applications
- Use platform deletion functionality
- Configure retention settings
- Request deletion from the provider where required
Endpoints
- Securely delete information
- Follow media sanitization requirements
Paper
- Secure destruction/shredding
6. Consider Backups
Backups require special attention.
A customer record may be deleted from production while historical backups continue to contain the information for a defined period.
Organizations should define how backup retention interacts with deletion.
For example:
Production Data Deleted
↓
Backup Still Exists
↓
Backup Retention Period
↓
Backup Expires / Is Overwritten
↓
Information No Longer Retained
Organizations should not necessarily restore deleted production data simply because it exists in an old backup.
The approach should be documented and consistent with applicable requirements.
7. Consider Replicated Data
Modern systems frequently replicate information.
Examples include:
- Primary database
- Read replicas
- Disaster-recovery environments
- Analytics platforms
- Search indexes
- Caches
- Data warehouses
The deletion process should consider relevant copies.
8. Consider Development and Test Environments
One common problem is production data being copied into development environments.
For example:
Production Customer Database
↓
Data Export
↓
Development DB
↓
Old Copy Remains
Where production data is used for testing, organizations should consider:
- Whether it is necessary
- Access restrictions
- Data minimization
- Masking/anonymization
- Retention
- Deletion
This is especially important when the information contains sensitive or personal information.
9. Automate Deletion Where Appropriate
Automation can reduce human error.
Examples:
- Database retention jobs
- Cloud storage lifecycle policies
- Automated account deletion workflows
- Log-retention policies
- SaaS retention settings
- Automated cleanup jobs
For example:
Retention Period Reached
↓
Automated Eligibility Check
↓
Deletion Job
↓
Execution Log
↓
Monitoring
Automation should be tested and monitored appropriately.
10. Control Manual Deletion
Some information may require manual deletion.
Manual deletion should have appropriate:
- Authorization
- Process
- Validation
- Recordkeeping
For example:
Request → Approval → Deletion → Verification → Record
11. Protect Information During Deletion
Deletion activities themselves should be secure.
Organizations should prevent:
- Unauthorized deletion
- Accidental deletion
- Deletion of records that must be retained
- Manipulation of deletion records
Appropriate access controls and approvals should be applied to sensitive deletion activities.
12. Handle Legal Holds and Exceptions
Information should not be deleted simply because a retention period has expired if there is a valid reason to preserve it.
Examples:
- Litigation hold
- Regulatory investigation
- Legal requirement
- Audit requirement
- Contractual requirement
The organization should have an exception or legal-hold process where relevant.
Startup Example
Example: 40-Person SaaS Company
The company uses:
- AWS
- PostgreSQL
- Google Workspace
- Slack
- CRM
- Support platform
- GitHub
- Cloud backups
- Analytics platform
A customer closes its account.
Poor Approach
The company disables the account but retains customer data indefinitely across multiple systems.
Better Approach
Customer Account Closed
↓
Identify Relevant Data
↓
Check Retention Requirements
↓
Identify Systems Holding Data
↓
Delete Eligible Data
↓
Apply Backup Retention Rules
↓
Verify Deletion Where Appropriate
↓
Record Completion
This creates a controlled deletion lifecycle.
Information Deletion Register
A startup can maintain a simple register:
| ID | Information | System | Trigger | Retention | Action | Status |
|---|---|---|---|---|---|---|
| DEL-001 | Customer Data | Production DB | Account closure | Defined period | Delete | Completed |
| DEL-002 | Support Data | Ticketing | Retention expiry | Defined period | Delete | Pending |
| DEL-003 | Test Data | Dev DB | Test completion | Short period | Delete | Completed |
| DEL-004 | Marketing Data | CRM | Retention expiry | Defined period | Delete | Scheduled |
Example Data Retention and Deletion Matrix
| Data Category | Business Purpose | Retention Basis | Deletion Trigger | Owner |
|---|---|---|---|---|
| Customer Account Data | Service delivery | Business/contractual requirements | Retention expiry | Product/IT |
| Support Records | Customer support | Business/contractual requirements | Retention expiry | Support |
| Employee Records | HR | Legal/business requirements | Retention expiry | HR |
| Financial Records | Accounting | Legal requirements | Legal retention expiry | Finance |
| Application Logs | Security/operations | Security/operational requirements | Retention expiry | Security/IT |
| Test Data | Testing | Testing purpose | Test completion | Engineering |
Actual retention periods should be determined for the organization rather than copied from generic examples.
Audit Evidence for Annex A 8.10
An auditor may request:
Policies
- Information Retention Policy
- Information Deletion Policy
- Data Lifecycle Management Procedure
- Data Disposal Procedure
Data Mapping
- Information inventory
- Data-flow diagrams
- Data-location inventory
- Application inventory
Retention
- Retention schedule
- Data-retention matrix
- Business/legal retention requirements
Deletion
- Deletion procedures
- Automated deletion configurations
- Deletion logs
- Deletion records
- Customer-account deletion records
- Secure disposal records
Technical Evidence
- Database retention jobs
- Cloud lifecycle rules
- SaaS retention settings
- Log-retention configuration
- Backup retention configuration
Exception Evidence
- Legal holds
- Deletion exceptions
- Approved retention extensions
ISO 27001 Annex A 8.10 Audit Checklist
| Question | Yes/No | Evidence |
|---|---|---|
| Is information retention defined? | Retention schedule | |
| Is information mapped to systems? | Data inventory | |
| Are deletion requirements defined? | Procedure | |
| Are deletion triggers identified? | Retention matrix | |
| Are obsolete/expired records deleted? | Deletion records | |
| Are automated deletion mechanisms used where appropriate? | System configuration | |
| Are backups considered? | Backup policy | |
| Are replicated copies considered? | Data-flow documentation | |
| Is development/test data addressed? | Dev/test procedure | |
| Is deletion access restricted? | Access controls | |
| Are legal holds considered? | Legal-hold process | |
| Are deletion exceptions documented? | Exception register | |
| Can deletion activities be demonstrated? | Logs/records | |
| Is the deletion process periodically reviewed? | Review evidence |
Common Mistakes
1. “Delete” Means Deleted Everywhere
Removing a record from an application does not necessarily remove all copies.
2. Keeping Everything Forever
Organizations sometimes retain data simply because storage is inexpensive.
Cheap storage does not eliminate security and compliance risks.
3. No Retention Schedule
Without defined retention requirements, deletion becomes inconsistent.
4. Ignoring Backups
Production deletion and backup retention should be considered together.
5. Ignoring Development Environments
Copies of production data may remain in:
- Test databases
- Developer machines
- Data exports
- Analytics environments
6. No Deletion Evidence
An organization may have a deletion process but be unable to demonstrate that it actually operates.
7. Deleting Information That Must Be Retained
Deletion must consider:
- Legal requirements
- Regulatory requirements
- Contracts
- Audits
- Legal holds
8. Manual Deletion Without Controls
Uncontrolled manual deletion can result in:
- Accidental deletion
- Unauthorized deletion
- Incomplete deletion
- Lack of evidence
9. Ignoring SaaS Providers
Information may exist in third-party systems.
Organizations should understand the deletion and retention capabilities of relevant suppliers.
Information Deletion for Startups
A startup does not need a complicated enterprise data-destruction system.
Start with five questions:
1. What information do we hold?
Create a practical data inventory.
2. Where is it stored?
Identify databases, SaaS platforms, cloud storage, backups and other relevant locations.
3. Why are we keeping it?
Document the business, legal, contractual, regulatory, or operational reason.
4. When should it be deleted?
Define appropriate retention requirements.
5. How do we delete it?
Document the appropriate technical or physical method.
Practical Startup Implementation Model
A simple lifecycle is:
Identify → Classify → Retain → Trigger → Delete → Verify → Record → Review
Identify
Know what information you have.
Classify
Understand its sensitivity and importance.
Retain
Define how long it needs to be kept.
Trigger
Identify when deletion becomes applicable.
Delete
Use an appropriate deletion method.
Verify
Confirm deletion where appropriate.
Record
Maintain evidence of important deletion activities.
Review
Periodically review retention and deletion requirements.
Policy vs. Process vs. Evidence
| Type | Example |
|---|---|
| Policy | Information shall be retained and deleted according to defined requirements |
| Process | Eligible information is identified and deleted after the retention period |
| Standard | Customer information is subject to defined retention requirements |
| Technical Control | Automated database deletion job |
| Configuration | Cloud storage lifecycle rule |
| Evidence | Deletion log |
| Record | Deletion register |
| Exception | Approved legal hold |
The important audit trail is:
Retention Requirement → Deletion Trigger → Deletion Action → Verification/Evidence
A.8.10 vs A.7.14 – Secure Disposal or Re-use of Equipment
These controls can look similar but address different things.
| Control | Focus |
|---|---|
| A.8.10 | Deletion of information |
| A.7.14 | Secure disposal or re-use of equipment |
Example
Deleting customer information from a database:
A.8.10
Securely wiping a laptop before giving it to another employee:
A.7.14
Both may apply when information exists on physical equipment.
A.8.10 vs A.7.10 – Storage Media
| Control | Focus |
|---|---|
| A.7.10 | Managing storage media |
| A.8.10 | Deleting information |
For example:
Protecting a USB drive containing confidential information:
A.7.10
Deleting information when it is no longer required:
A.8.10
A.8.10 vs A.5.33 – Protection of Records
| Control | Focus |
|---|---|
| A.5.33 | Protecting records |
| A.8.10 | Deleting information when no longer required |
Records that must legally or contractually be retained should not be deleted simply because they are old.
A.8.10 vs A.5.34 – Privacy and Protection of PII
Where personal information is involved, deletion should also consider applicable privacy requirements and commitments.
For example:
Personal Information
↓
Purpose / Requirement
↓
Retention Period
↓
Deletion Eligibility
↓
Secure Deletion
Privacy requirements may establish specific deletion or retention obligations depending on the applicable jurisdiction and circumstances.
Questions an Auditor May Ask
1. How do you determine what information should be deleted?
Show the retention/deletion process.
2. How do you know where information exists?
Show data inventories and system mapping.
3. What happens when a customer leaves?
Demonstrate the customer-data lifecycle.
4. How do you handle backups?
Show backup retention and deletion arrangements.
5. How do you handle replicated information?
Show relevant data flows and system processes.
6. How do you handle test data?
Show development/test-data controls.
7. How do you prevent unauthorized deletion?
Show access controls and authorization.
8. How do you handle legal holds?
Show the exception/legal-hold process.
9. How do you demonstrate that information was deleted?
Show logs, deletion records, automated jobs, or other appropriate evidence.
10. Who owns information retention and deletion?
Show defined responsibilities.
Useful Resources
Organizations implementing Annex A 8.10 may maintain:
- Information Retention and Deletion Policy – [Insert Draft Document Link]
- Information Deletion Procedure – [Insert Draft Document Link]
- Data Retention Schedule – [Insert Draft Document Link]
- Data Retention and Deletion Matrix – [Insert Draft Document Link]
- Information/Data Inventory – [Insert Draft Document Link]
- Data Flow Diagram – [Insert Draft Document Link]
- Deletion Request Form – [Insert Draft Document Link]
- Deletion Register – [Insert Draft Document Link]
- Data Deletion Verification Checklist – [Insert Draft Document Link]
- Backup Retention Procedure – [Insert Draft Document Link]
- Data Deletion Exception Form – [Insert Draft Document Link]
- Information Deletion Audit Checklist – [Insert Draft Document Link]
Startup-Focused Quick Summary
A startup can implement A.8.10 using a straightforward lifecycle:
1. Identify
Know what information you hold.
2. Map
Know where it is stored and replicated.
3. Define Retention
Determine how long it needs to be kept.
4. Identify Triggers
Know when deletion becomes applicable.
5. Delete
Use an appropriate deletion method.
6. Consider Backups
Define how backup retention interacts with deletion.
7. Verify
Confirm important deletion activities where appropriate.
8. Document
Maintain sufficient evidence.
Startup-Focused Final Takeaway
ISO 27001 Annex A 8.10 is about preventing organizations from becoming permanent warehouses for information they no longer need.
A practical startup should be able to answer:
What information do we have?
Where is it stored?
Why are we keeping it?
How long should we keep it?
What triggers deletion?
How do we delete it?
How do we handle backups and copies?
The objective is not to delete information blindly.
It is to establish a controlled information lifecycle:
Create → Use → Retain → Review → Delete
For a cloud-native SaaS company, effective implementation can combine data inventories, retention schedules, automated lifecycle policies, database deletion processes, SaaS retention controls, backup policies, and appropriate deletion evidence.
One-Line Summary
ISO 27001 Annex A 8.10 ensures that information is retained only as long as necessary and is appropriately deleted when it is no longer required, while considering legal, regulatory, contractual, business, privacy, and security requirements.
