Skip to content
arrow_back
search
Annex A 8.10 verified ISO/IEC 27001:2022

Secure deletion of information when no longer needed

Delete data you don't need anymore to reduce risk and comply with laws.

record_voice_over

Plain language

This control is about securely deleting information you no longer need, to protect your business from data breaches and to comply with the law. If you keep old or unnecessary data, it could be exposed or stolen, leading to legal troubles or financial loss.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

12 Apr 2026

Maturity levels

N/A

Official control statement

Information stored in information systems, devices or in any other storage media shall be deleted when no longer required.
verified ISO/IEC 27001:2022 Annex A 8.10
priority_high

Why it matters

Failing to securely delete unneeded data can lead to data breaches and legal non-compliance, risking penalties and reputational damage.

settings

Operational notes

Regularly review retention schedules and deletion workflows; use verified sanitisation tools and destruction methods for media, and keep evidence of deletion.

Mapping detail

Mapping

Direction

Controls