DAT-04Data and Privacy

Complete disposal

Data is removed from primary systems, backups, caches, exports and third parties when it is no longer needed or on request.

Why it exists

Deletion that stops at the database is not deletion.

What usually proves it

Disposal procedure, backup expiry evidence, third-party confirmations.

Smaller organizations

Know your backup horizon and state it honestly.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC6.5
  • Fully addressedISO/IEC 27001 Annex A · A.8.10
  • Fully addressedNIST Cybersecurity Framework · PR.DS-03
  • Fully addressedPCI DSS · 3.2.1
  • Fully addressedHIPAA Security Rule · 164.310(d)(2)(i)
  • Fully addressedGDPR · Art. 17
  • Deliberately absentEU AI Act — No disposal obligation; record-keeping durations are specified instead.
  • Deliberately absentNIST AI Risk Management Framework — Out of scope: the framework addresses AI risk, not data lifecycle disposal.