What does ETSI EN 303 645 require for personal data deletion?
Clause 5.11 separates mandatory device erasure from recommended service deletion. Provision 5.11-1 says users shall have functionality to erase all their from the device in a simple manner. Here, user data means data stored on the device that the user created or that the device generated through user activity, including , configuration, event logs, and cryptographic material such as passwords or keys. It excludes data present before the user's first use.
Provision 5.11-2 says the consumer should have functionality on the device to delete from in a simple manner. Relevant moments include ownership transfer, a personal-data deletion request, removal of a service, and device disposal. "Simple" means minimal steps, each with minimal complexity.
The explanatory text says a consumer who requests complete deletion also expects retrospective deletion of backup copies. Treat backup handling as part of the product's deletion design and evidence, but do not present that explanation as a separate mandatory EN 303 645 provision. Applicable law or another requirement may independently control whether particular records must be deleted or retained.
- Treat device erasure and associated-service removal as two related but distinct deletion paths.
- Do not assume a factory reset is enough for every privacy scenario; ETSI gives a shared-use example where resetting the whole device would not be appropriate for deleting one user's .
- Keep GDPR statements narrow: EN 303 645 says the functionality is expected to comply with applicable data protection law, including GDPR, but the standard itself presents technical baseline provisions rather than a full legal assessment.
Primary ETSI source for consumer IoT user-data erasure, personal-data removal from associated services, deletion instructions, confirmation, and the caution that factory reset is not always the right mechanism.