EN ISO/IEC 27555:2025

Information security, cybersecurity and privacy protection - Guidelines on personally identifiable information deletion (ISO/IEC 27555:2021)

Publication date:   Apr 14, 2025

General information

60.60   Standard published   Mar 12, 2025

CEN/CENELEC

CEN/CLC/JTC 13 Cybersecurity and Data Protection

European Norm

35.030   IT Security

Buying

  Published

PDF - €58.20

  English  



Buy

Scope

This document contains guidelines for developing and establishing policies and procedures for deletion of personally identifiable information (PII) in organizations by specifying:
—    a harmonized terminology for PII deletion;
—    an approach for defining deletion rules in an efficient way;
—    a description of required documentation;
—    a broad definition of roles, responsibilities and processes.
This document is intended to be used by organizations where PII is stored or processed.
This document does not address:
—    specific legal provision, as given by national law or specified in contracts;
—    specific deletion rules for particular clusters of PII that are defined by PII controllers for processing PII;
—    deletion mechanisms;
—    reliability, security and suitability of deletion mechanisms;
—    specific techniques for de-identification of data.

Related legislation

Legislation related to this standard

2016/679

Life cycle

NOW

PUBLISHED
EN ISO/IEC 27555:2025
60.60 Standard published
Mar 12, 2025

REVISED BY

IN_DEVELOPMENT
prEN ISO/IEC 27555

Relations

Adopted from ISO/IEC 27555:2021 IDENTICAL