Security Questionnaire Mapper
Data protection and encryption ยท question family

Data retention and secure deletion: the clause the question tests

How long the customer's data is kept and how it is destroyed or handed back.

How the customer usually asks it

example

"How is customer data deleted or returned at the end of the contract?"

Read this question

Anchor clauses

5 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20228.10 Information deletion
SIG (Shared Assessments)domain D Asset and Information Management
CSA Cloud Controls Matrix v4.0.1DSP-16 Data Retention and Deletion
PCI DSS v4.0.13.2.1 Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following
GDPR, Regulation (EU) 2016/679Art. 28 Processor

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The retention schedule for the customer's data, the deletion method on each store including backups, and the deletion certificate template used at exit.

The clauses, with what an assessor asks for

ISO 27001 8.10 Information deletion

Delete information in systems, devices and media when no longer required.

Evidence an assessor expects: Deletion policy; Media disposal log; System deletion audit; Data retention schedule
Where answers usually fall short: Retaining data beyond approved period; No evidence of secure erase verification
Source: ISO/IEC 27001:2022
SIG domain D Asset and Information Management

What it asks for, in one line (the standard's own text is not quoted here):

Maintain a complete and current inventory of information assets, data classification, ownership, and handling requirements throughout the asset lifecycle.

Evidence an assessor expects: Asset inventory with owner and classification; Data classification policy and labeling guide; Onboarding and decommissioning records; Data flow diagrams
Where answers usually fall short: Inventory missing cloud assets; Classification labels inconsistent across systems
Source: SIG (Shared Assessments)
CSA CCM DSP-16 Data Retention and Deletion

What it asks for, in one line (the standard's own text is not quoted here):

Manage data retention, archiving and deletion against business requirements and applicable law, so data is neither kept longer nor destroyed sooner than allowed.

Evidence an assessor expects: The retention schedule by data type with the requirement behind each period; Evidence retention periods are enforced technically; Deletion records at end of retention; Legal hold procedure and its interaction with deletion
Where answers usually fall short: Retention schedule published with no technical enforcement; Data retained indefinitely because deletion was never built
Source: CSA Cloud Controls Matrix v4.0.1
PCI DSS 3.2.1 Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following

What it asks for, in one line (the standard's own text is not quoted here):

Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following:; Coverage for all locations of stored account data.

Evidence an assessor expects: Retention schedule by data type; Secure deletion procedure and logs; Data discovery scan results; Quarterly purge job evidence; Legal hold exception register
Where answers usually fall short: Indefinite retention by default; No deletion proof
Source: PCI DSS v4.0.1
GDPR Art. 28 Processor

Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.

Evidence an assessor expects: A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it; The Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names; Due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract; The sub-processor authorisation position for each processor, the current sub-processor list, and evidence changes were notified; Audit or assurance rights exercised in practice, such as a report reviewed with findings tracked, and end of service deletion certificates
Where answers usually fall short: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice; A processor inventory that misses tools adopted directly by individual teams, which is where undocumented processing usually sits
Source: GDPR, Regulation (EU) 2016/679

Other families in data protection and encryption