DAT-04Data and Privacy
Complete disposal
Data is removed from primary systems, backups, caches, exports and third parties when it is no longer needed or on request.
Why it exists
Deletion that stops at the database is not deletion.
What usually proves it
Disposal procedure, backup expiry evidence, third-party confirmations.
Smaller organizations
Know your backup horizon and state it honestly.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC6.5
- Fully addressedISO/IEC 27001 Annex A · A.8.10
- Fully addressedNIST Cybersecurity Framework · PR.DS-03
- Fully addressedPCI DSS · 3.2.1
- Fully addressedHIPAA Security Rule · 164.310(d)(2)(i)
- Fully addressedGDPR · Art. 17
- Deliberately absentEU AI Act — No disposal obligation; record-keeping durations are specified instead.
- Deliberately absentNIST AI Risk Management Framework — Out of scope: the framework addresses AI risk, not data lifecycle disposal.