Data Destruction
What is Data Destruction?
The process of permanently and irreversibly eliminating data stored on electronic media so that it cannot be recovered. Methods include degaussing, physical destruction, and cryptographic erasure.
Frameworks that govern data destruction
What the standards actually require on data destruction
Requirements naming data destruction across 6 standards, quoted from the control text.
Keep approved procedures for securely disposing of equipment used away from company premises, and where equipment is not physically destroyed, apply a data destruction method that makes recovery impossible. Review at least annually.
CCM-DCS-01 · Off-Site Equipment Disposal Policy and Procedures →Article 6(1) sets the recoverable damage categories: (a) death or personal injury, including medically recognised damage to PSYCHOLOGICAL health; (b) damage to or destruction of any property other than the defective product itself;
PLD-Art.6 · Categories of damage covered (PLD Article 6) →HKMA C-RAF Domain 3 PROTECTION + Domain 4 DETECTION. DOMAIN 3 PROTECTION (6 sub-areas): (1) ACCESS CONTROL - identity + access management + privileged access (PAM) + MFA + zero trust + just-in-time access + role-based access + access reviews + offboarding;
HKMA-CRAF-Domain3-4-Protection-Detection · HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel →Section 9.4 of IRS Publication 1075 establishes specific requirements for cloud services and addresses the prohibition on offshore processing of FTI.
IRSPub1075-Section94-Cloud-FedRAMP-Offshore-Prohibition-CSP-USRegion-PrivateGovCloud-AzureGov-AWSGov · IRS Pub 1075 Section 9.4 + Cloud Services + FedRAMP Authorisation Required + Offshore Prohibition + AWS GovCloud + Azure Government + Oracle US Federal + Google Workspace Federal + US-Region Data Residency →The organisation defines and communicates end of cybersecurity support and decommissioning conditions for items including data destruction.
21434-14 · End of Cybersecurity Support and Decommissioning →Apply pseudonymisation and de-identification under Sections 14-4610 and 14-4611 to enable lawful internal research + product improvement + aggregated reporting while protecting consumer privacy.
MD-MODPA-Pseudonymisation-De-Identification-Section-14-4610-4611-Internal-Research-Aggregated · Maryland MODPA Pseudonymisation + De-Identification + Section 14-4610 + 14-4611 + Internal Research + Aggregated →Questions people ask about data destruction
What is Data Destruction?
Why is Data Destruction important for compliance?
Which compliance frameworks address Data Destruction?
Where can I learn more about Data Destruction?
See how Data Destruction applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.