Information Deletion Control (8.10)
Information Deletion is an ISO 27001:2022 Annex A control that requires organizations to securely delete data held in systems, devices, and storage media once it is no longer needed. Its aim is to reduce the risk of unauthorized access to and unnecessary exposure of sensitive information. It also helps organizations meet legal, statutory, regulatory, and contractual obligations related to retaining and disposing of data.
Control 8.10 (Information Deletion) is a technological reference control listed in Annex A of ISO/IEC 27001:2022 and detailed in ISO/IEC 27002:2022. It requires that information stored in information systems, on devices, or on other storage media be deleted securely and permanently when it is no longer required, in order to prevent unauthorized access and unnecessary exposure of sensitive information and to support compliance with applicable legal, statutory, regulatory, and contractual requirements. As an Annex A control, its inclusion in a given ISMS is determined via the Statement of Applicability and informed by risk assessment rather than being universally mandatory; the specific deletion methods and retention parameters depend on organizational scope, data classification, and applicable obligations. This control applies only within the defined scope of the ISMS and does not, by itself, guarantee that data has been irrecoverably destroyed in all circumstances.
Why it matters
Information that is retained beyond its useful life represents an ongoing liability. Every additional copy of sensitive data held in systems, on devices, or on storage media expands the potential attack surface and increases the risk of unauthorized access and unnecessary exposure. Control 8.10 addresses this by requiring organizations to securely delete data once it is no longer required, reducing the volume of information an attacker, insider, or misconfigured system could expose.
Beyond security, timely and secure deletion supports compliance with legal, statutory, regulatory, and contractual obligations governing how long data may be kept and how it must be disposed of. Many retention regimes impose limits on how long certain categories of data may be held, and failure to delete data at the end of its retention period can create both regulatory exposure and evidentiary complications. Implementing this control helps align an organization's actual data-handling practices with its stated retention commitments.
As an Annex A reference control, 8.10 is included in an ISMS through the Statement of Applicability and informed by risk assessment rather than being universally mandatory. Its scope covers only the information environment defined within the ISMS, and by itself it does not guarantee that data has been irrecoverably destroyed in all circumstances. Organizations typically need to combine documented retention schedules, appropriate deletion methods, and verification to demonstrate the control is operating as intended.
Who it's relevant to
Inside Information Deletion Control (8.10)
Common questions
Answers to the questions practitioners most commonly ask about Information Deletion Control (8.10).