Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.8.10 Information Deletion

Control Objective

Information stored in information systems, devices or in any other storage media shall be deleted when no longer required.

Policy Statement

anDREa ensures that information assets are systematically purged or destroyed once they have fulfilled their operational, legal, or contractual lifecycle requirements. This proactive data minimization limits the organization's data footprint, significantly reducing the security and compliance risks associated with storing obsolete information.


Data Deletion and Destruction Framework

Data lifecycle management is governed through strict procedural and technical controls:

  • Policy Alignment: All data retention timelines and destruction mechanisms are executed in strict compliance with the formalized Retention & Destruction Policy. This framework directly incorporates data minimization mandates from the GDPR, NIS 2, and applicable national and contractual obligations.
  • Authorized Deletion Rights: The ability to execute permanent data deletions is strictly restricted. Deletion privileges are treated as a high-risk capability and are assigned via Role-Based Access Control (RBAC) on a strict need-to-know basis. General system users and unauthorized personnel are blocked from purging compliance records, system logs, or master backups.
  • Endpoint Data Minimization: Personnel are required to continuously review local environments and permanently purge local business files or operational materials that are no longer actively required, shifting active workloads to our secure cloud infrastructure (see A.06.07 - Remote working).

Deletion Lifecycles by Component

To maintain operational integrity, deletion follows distinct pathways based on the asset type:

  • Customer Workspaces: Upon the formal decommissioning of a project or research workspace within the myDRE platform, data partitions are securely unmounted, overwritten, and archived or destroyed based on explicit client contractual clauses.
  • Corporate Asset Decommissioning: Hard drives and media carriers belonging to departing personnel or retired endpoints must undergo comprehensive cryptographic wiping and physical destruction where necessary, ensuring data is unrecoverable (see A.07.14 - Secure disposal or re-use of equipment).
  • Retention Lifecycles: For exact timeline tables specifying how long specific logs, customer data, and employee documents must be kept before deletion, refer directly to the Retention & Destruction Policy.