Answers to the questions practitioners most commonly ask about Information Deletion.
Does implementing an information deletion control automatically satisfy both SOC 2 and ISO 27001?
No. Although deletion practices can support requirements in both frameworks, satisfying one does not automatically satisfy the other. In a SOC 2 examination, deletion-related controls are assessed by a CPA firm against the applicable Trust Services Criteria selected for the scope, most relevantly the Confidentiality or Privacy categories where those are in scope, alongside the required Security (Common Criteria) category. Under ISO 27001, deletion is typically addressed through Annex A reference controls selected via the Statement of Applicability and informed by risk assessment, while the certifiable requirements themselves sit in clauses 4 through 10. Mapping between the two frameworks is possible but partial, so deletion evidence usually needs to be evaluated separately against each framework's expectations.
Is there a single mandatory retention or deletion period I must follow to pass an audit?
No. Neither a SOC 2 examination nor ISO 27001 certification prescribes a universal, fixed deletion period. Deletion timelines typically depend on the scope, applicable criteria, contractual commitments, and any legal or regulatory obligations that apply to your organization. In most engagements, the auditor or certification body assesses whether your defined deletion practices are appropriate to your stated policies and risk assessment and whether they operate as described, rather than checking against a single mandated interval.
What evidence typically demonstrates that information deletion controls are operating effectively?
In most engagements, evidence includes documented deletion policies and procedures, records of deletion requests and their fulfilment, system logs or tickets showing deletion actions, and confirmation that data was removed within the timeframes your policy defines. For a SOC 2 Type II examination, which assesses operating effectiveness over a defined review period, examiners typically sample deletion events across that period; for a Type I, which assesses suitability of design at a point in time, the focus is usually on whether the control is appropriately designed. The specific evidence expected varies by auditor, scope, and applicable criteria.
How do deletion controls apply to data held by third-party subservice organizations or cloud providers?
Deletion obligations often extend to data processed or stored by third parties, so many organizations address this through contractual terms and by reviewing the provider's own assurance reports. Depending on scope, a subservice organization's SOC 2 report may cover its deletion-related controls, and cloud-focused standards such as ISO 27017 or the privacy-oriented ISO 27018 may be relevant to how a provider handles deletion. It is generally advisable to confirm how deletion responsibilities are divided between your organization and the provider, and to retain evidence of that allocation, since the exact treatment depends on your contracts and scope.
How does information deletion relate to backups and archived copies?
Backups and archives are a common practical challenge because deletion from production systems does not necessarily remove data from backup or archival copies. In most implementations, organizations document how deletion applies across backups, including any retention cycles after which backup copies expire, so that the overall approach remains consistent with stated policies. Auditors and certification bodies typically look for a coherent, documented rationale rather than a specific technical method, and the appropriate handling depends on your scope and risk assessment.
How should deletion controls be documented for scoping purposes under each framework?
For SOC 2, deletion controls are typically described in the control descriptions mapped to the applicable Trust Services Criteria within the defined system boundary, since the report attests only to the controls and period covered. For ISO 27001, where deletion is addressed through Annex A reference controls, the relevant controls are typically recorded in the Statement of Applicability with justification for inclusion or exclusion, and the certificate covers only the defined scope of the ISMS. In both cases, clearly bounding what data, systems, and locations the deletion controls apply to helps keep the assessment aligned with the intended scope.