FAQGLOBALETSI EN 303 645

ETSI EN 303 645 Personal data deletion for consumer IoT products

ETSI EN 303 645 V3.1.3 requires a simple way to erase all user data from the device and recommends device-initiated deletion of personal data from associated services.

This FAQ stays within the ETSI source text: it summarizes the technical deletion expectations and the evidence fields used by ETSI TS 103 701, without treating the standard as a complete GDPR compliance checklist.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Provision 5.11-1 requires a simple way to erase all from the consumer IoT device. V3.1.3 then recommends a device-based way to delete from , clear instructions, and confirmation covering devices and associated services. A factory reset may be unsuitable when it would erase another user's settings or disrupt a future user.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What does ETSI EN 303 645 require for personal data deletion?

Clause 5.11 separates mandatory device erasure from recommended service deletion. Provision 5.11-1 says users shall have functionality to erase all their from the device in a simple manner. Here, user data means data stored on the device that the user created or that the device generated through user activity, including , configuration, event logs, and cryptographic material such as passwords or keys. It excludes data present before the user's first use.

Provision 5.11-2 says the consumer should have functionality on the device to delete from in a simple manner. Relevant moments include ownership transfer, a personal-data deletion request, removal of a service, and device disposal. "Simple" means minimal steps, each with minimal complexity.

The explanatory text says a consumer who requests complete deletion also expects retrospective deletion of backup copies. Treat backup handling as part of the product's deletion design and evidence, but do not present that explanation as a separate mandatory EN 303 645 provision. Applicable law or another requirement may independently control whether particular records must be deleted or retained.

  • Treat device erasure and associated-service removal as two related but distinct deletion paths.
  • Do not assume a factory reset is enough for every privacy scenario; ETSI gives a shared-use example where resetting the whole device would not be appropriate for deleting one user's .
  • Keep GDPR statements narrow: EN 303 645 says the functionality is expected to comply with applicable data protection law, including GDPR, but the standard itself presents technical baseline provisions rather than a full legal assessment.
Citations
ETSI EN 303 645 V3.1.3, clause 5.11

Primary ETSI source for consumer IoT user-data erasure, personal-data removal from associated services, deletion instructions, confirmation, and the caution that factory reset is not always the right mechanism.

Question 2

What should the user experience include?

The standard uses simple, user-facing language. Deletion should require minimal steps and minimal complexity, and users should receive clear instructions on how to delete their .

Provision 5.11-4 recommends clear confirmation that has been deleted and, where possible, erased from devices and . The current edition does not list applications as a separate confirmation target. An app may still be part of the device or an associated service, but the product boundary must establish that.

  • Show the deletion entry point in the relevant device, app, or service interface instead of burying it in support-only processes.
  • Explain whether the action erases device-stored , removes from , deletes an app or account profile, or does more than one of these.
  • Confirm which device and associated-service data the action covered, including any practical consequence such as logout, loss of remote services, or return to factory-default state.
  • Document any data that remains because deletion is not available or because another requirement applies; ETSI EN 303 645 alone does not decide the legal retention question.
Citations
ETSI TS 103 701 V2.1.1, sample IXIT 25-DelFunc

The sample IXIT illustrates deletion-function evidence fields such as description, target type, initiation and interaction, and confirmation for device reset and online-profile removal examples.

Question 3

What evidence should teams keep for assessment?

ETSI TS 103 701 maps the deletion provisions to concrete IXIT entries. For 5.11-1, the required deletion-function evidence includes an ID, description, target type, and initiation and interaction. For 5.11-2, teams also need personal-data evidence that describes the and processing activities, linked to the deletion functionality.

For 5.11-3 and 5.11-4, the evidence extends to user information: documentation of deletion, personal-data and deletion-function entries, and confirmation evidence. The useful evidence packet therefore joins three views: the inventory, the deletion function, and the user-facing documentation or confirmation.

  • Maintain a personal-data inventory that records what is processed, the purpose, authorized parties, lifecycle, and processing activities where those fields apply.
  • Maintain a deletion-function record for each deletion route, including the target type and the exact user interaction that initiates it.
  • Retain screenshots, user documentation, or other visible evidence showing the deletion instructions and the confirmation shown after deletion.
  • Test the result on the device and each associated service, including shared-user behavior, ownership transfer, account removal, service removal, factory reset, disposal, and any stated backup outcome.
  • Reassess the deletion map when a data category, storage location, backup process, account model, associated service, reset flow, retention rule, or product software version changes.
Citations
Primary sources

References and citations

etsi.org
Referenced sections
  • Primary ETSI source for consumer IoT user-data erasure, personal-data removal from associated services, deletion instructions, confirmation, and the caution that factory reset is not always the right mechanism.
"Make it easy for users to delete user data"
etsi.org
Referenced sections
  • Current ETSI source for device user-data erasure, associated-service personal-data deletion, instructions, confirmation, and the separate technical data-protection provisions.
"Users shall be provided with functionality such that all their user data can be erased"
etsi.org
Referenced sections
  • Current source for clear deletion instructions and confirmation that personal data has been deleted and, where possible, erased from devices and associated services.
"clear confirmation"
etsi.org
Referenced sections
  • Assessment methodology and provision-to-IXIT mapping for 5.11-1 through 5.11-4, including IXIT 21-PersData, IXIT 25-DelFunc, IXIT 2-UserInfo, and the external-evidence concept.
"Provision vs Required IXIT entries"
etsi.org
Referenced sections
  • The sample IXIT illustrates deletion-function evidence fields such as description, target type, initiation and interaction, and confirmation for device reset and online-profile removal examples.
"Deletion Functionalities"
Related guides

Explore more topics

ETSI EN 303 645 Applicability and Scope
Decide whether a connected product is in scope of ETSI EN 303 645, define the consumer IoT evidence boundary, and document N/A justifications for assessment.
ETSI EN 303 645 compliance: ICS, IXIT, evidence
Plan ETSI EN 303 645 compliance evidence for consumer IoT products with scope, ICS, IXIT, TS 103 701 assessment steps, verdict risks, and cited controls.
ETSI EN 303 645 consumer IoT products: what is in scope?
Decide whether a device and its associated services are in scope of ETSI EN 303 645 V3.1.3 and document the DUT, ICS, IXIT, and assessment boundary.
ETSI EN 303 645 Current Version Tracker
Track ETSI EN 303 645 version evidence, ETSI deliverable status checks, TS 103 701 assessment alignment, and change triggers for consumer IoT security work.
ETSI EN 303 645 CVD Workflow for IoT Vulnerability Reports
Cited workflow for ETSI EN 303 645 vulnerability disclosure: public policy contents, reporting contact, acknowledgement and status timelines, timely action, and TS 103 701 evidence.
ETSI EN 303 645 Data Protection Provisions
Guide to ETSI EN 303 645 data protection provisions for consumer IoT, including security, consent, telemetry, deletion, minimization, aggregation, and anonymization.
ETSI EN 303 645 default passwords: what must consumer IoT teams do?
ETSI EN 303 645 default password guidance for consumer IoT: unique or user-defined passwords, pre-installed password generation, change mechanisms, brute-force controls, and TS 103 701 evidence.
ETSI EN 303 645 FAQ: Consumer IoT Security Questions
Practical answers to common ETSI EN 303 645 questions on consumer IoT scope, associated services, passwords, updates, vulnerability disclosure, telemetry, deletion, and assessment evidence.
ETSI EN 303 645 ICS and IXIT Evidence Template
Build a cited ICS and IXIT evidence template for ETSI EN 303 645 consumer IoT assessments, with clear separation between EN provisions and TS 103 701 test information.
ETSI EN 303 645 implementation checklist
This ETSI EN 303 645 implementation checklist helps scope a consumer IoT product, record Annex B support statuses, map IXIT evidence, and avoid weak conformance claims.
ETSI EN 303 645 Implementation Evidence Guide
Build ETSI EN 303 645 implementation evidence from Annex B support/detail records, TS 103 701 ICS and IXIT inputs, test verdicts, and scoped external evidence.
ETSI EN 303 645 IoT Applicability Workflow
Decide whether ETSI EN 303 645 applies to a consumer IoT product, what associated services belong in scope, and how to record justified non-applicability.
ETSI EN 303 645 requirements: consumer IoT provision map
Map ETSI EN 303 645 consumer IoT requirements to product scope, Annex B ICS entries, TS 103 701 evidence, and implementation owners.
ETSI EN 303 645 Secure Update Evidence Workflow
Build secure-update evidence for ETSI EN 303 645 using provision 5.3, Annex B support/detail records, and TS 103 701 ICS, IXIT, and test-plan inputs.
ETSI EN 303 645 Secure Update Workflow
Map ETSI EN 303 645 secure-update provisions into a practical workflow for consumer IoT update mechanisms, support-period disclosures, and TS 103 701 evidence.
ETSI EN 303 645 Secure Updates and Vulnerability Disclosure
Source-backed guide to ETSI EN 303 645 clauses 5.2 and 5.3 for consumer IoT vulnerability disclosure, security updates, support periods, and assessment evidence.
ETSI EN 303 645 support period: what must consumer IoT teams publish?
ETSI EN 303 645 support-period guidance for consumer IoT: defined security-update support periods, user-accessible publication, non-updateable-device replacement support, model designation, and TS 103 701 evidence.
ETSI EN 303 645 telemetry: what should consumer IoT teams evidence?
ETSI EN 303 645 telemetry guidance for consumer IoT teams: security anomaly examination, IXIT 24-TelData evidence, personal-data minimization, and consumer telemetry disclosures.
ETSI EN 303 645 test evidence: what should consumer IoT teams keep?
ETSI EN 303 645 test evidence guidance for consumer IoT teams: ICS support claims, IXIT detail, TS 103 701 test plans, verdicts, and external evidence checks.
ETSI EN 303 645 vs EU CRA for Consumer IoT
Compare ETSI EN 303 645 consumer IoT evidence with the EU Cyber Resilience Act's scope, manufacturer duties, application dates, and conformity requirements.
ETSI EN 303 645 vs RED Cybersecurity Delegated Act
Compare ETSI EN 303 645 consumer IoT evidence with the RED cybersecurity requirements, EN 18031 standards, application date, and conformity routes.
ETSI EN 303 645 vs UK PSTI: Evidence Crosswalk
Compare ETSI EN 303 645 evidence with UK PSTI scope, three mandatory security requirements, statements of compliance, duties, and enforcement.
ETSI EN 303 645 vulnerability disclosure requirements for consumer IoT
What ETSI EN 303 645 requires for consumer IoT vulnerability disclosure policies, report handling, status updates, timely action, and TS 103 701 evidence.
ETSI TS 103 701 Test Evidence Workflow for EN 303 645
Build an ETSI TS 103 701 test evidence workflow for EN 303 645 consumer IoT assessments: DUT identification, ICS, IXIT, test plans, verdicts, and external evidence.
How should teams handle constrained devices under ETSI EN 303 645 for consumer IoT products?
How ETSI EN 303 645 V3.1.3 treats use-case resource constraints, non-updateable devices, N/A claims, authentication controls, and assessment evidence.