ISO 27001 information deletion (control 8.10)

ISO 27001 is about an information security management system — and one of its controls is simply: delete information when you're done with it.

t tScrub Team Last updated 22 Sep 2026 5 min read

ISO/IEC 27001:2022 addresses erasure through Annex A control 8.10, "Information deletion". It requires organisations to delete information when it's no longer needed, in a way that accounts for legal, statutory, regulatory, and contractual requirements.

What the control asks for

Unlike GDPR or HIPAA, ISO 27001 doesn't prescribe a technique — it prescribes a management system. Control 8.10 expects you to have a policy and procedure for deleting information, to apply it consistently, and to keep evidence that it happened. The supporting guidance points to sanitisation of media before disposal or reuse.

Where disk erasure fits

When the "information" in question lives on decommissioned storage, the deletion procedure is media sanitisation:

Evidence for the auditor

In an ISO 27001 audit, the question isn't "do you erase?" — it's "show me your last ten erasures." A chain-of-custody report tied to serial numbers, with a certificate of destruction you can produce on request, is exactly the kind of objective evidence an auditor wants to see. It turns a policy document into a demonstrated practice.

FAQ

Is ISO 27001 the same as GDPR?

No. ISO 27001 is a voluntary management-system certification; GDPR is law. They overlap — both demand verifiable deletion — but satisfying one doesn't automatically satisfy the other. A good erasure practice helps with both.

Do I need a certificate of destruction for ISO 27001?

It's not strictly mandated, but a verifiable certificate is the most efficient way to demonstrate control 8.10 in an audit.

Keep reading

Turn policy into demonstrated practice

tScrub produces the verifiable records ISO 27001 auditors ask to see.

Get tScrub