What should the return and deletion outcome cover?
Start with the trigger and authorized outcome: a customer instruction, purpose expiry, retention-schedule event, contract termination, or valid legal requirement. Then define the export format and verification, timing, contract-end recovery buffer, erasure method, live systems, temporary files, logs, backups and continuity copies, subprocessor copies, archives, legal holds, and completion notice.
ISO/IEC 27018 recognizes return, transfer to another processor or controller, secure deletion or destruction, , and archival as possible dispositions. Return or transfer requires a usable export and confirmed recipient; deletion or destruction requires a defined mechanism; anonymization requires evidence that the result is no longer identifiable by reasonably likely means; archival requires a valid purpose, restricted access, and a retention end. None should be used to avoid a required return or deletion.
- State the retention period after contract termination that protects against accidental lapse without turning the buffer into indefinite retention.
- Specify the disposition mechanism in the contract, such as de-linking, overwriting, demagnetization, physical destruction, or another applicable commercial standard.
- Apply a documented age limit and periodic cleanup to unused temporary files.
Primary ISO listing for the 2025 edition of ISO/IEC 27018.
ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.
Binding EU data protection regulation used for ISO/IEC 27018 comparison.