Overview
EN ISO/IEC 27555:2025 (identical to ISO/IEC 27555:2021) provides harmonized guidelines for organizations to develop and maintain policies and procedures for deletion of personally identifiable information (PII). It defines a common terminology, an efficient approach to specify deletion rules, required documentation, and a broad allocation of roles, responsibilities and processes. The standard is intended for any organization that stores or processes PII and was adopted by CEN as EN ISO/IEC 27555:2025.
Note: the standard does not prescribe national legal requirements, specific deletion mechanisms or their reliability, nor specific de‑identification techniques.
Key topics and requirements
- Harmonized terminology for PII deletion to ensure consistent understanding across teams and systems.
- Framework for deletion covering constraints, clusters of PII, retention and regular deletion periods, archives and backups, and special situations.
- Clusters of PII - guidance on identifying and documenting groups of related PII to apply consistent deletion rules.
- Retention and deletion periods - concepts for defining standard and regular deletion periods, starting points and adjustments for special cases.
- Deletion classes and rules - abstract starting points and a matrix approach to classify data and assign deletion rules efficiently.
- Documentation requirements - what policies, records and justifications should exist to demonstrate compliant deletion practices.
- Implementation requirements - organization-wide and system-level considerations (backup handling, logs, transmission systems, disposal), plus requirements for processors and manual processes.
- Responsibilities and governance - allocation of roles, exception management and control of deletions in special cases.
Practical applications & who should use it
This standard is practical for:
- Data protection officers, privacy teams and legal/compliance teams establishing PII deletion policies.
- Information security and IT operations implementing deletion across applications, backups and archives.
- Records managers and business process owners defining retention schedules and exception workflows.
- Third‑party processors to align contractual deletion responsibilities with clients’ policies.
Use cases include building an auditable deletion program, mapping PII clusters to deletion classes, documenting retention rules, and designing processes that handle backups, exceptions and system‑level deletion triggers.
Related standards
- ISO/IEC 27555 complements broader information security and privacy frameworks and is commonly used alongside standards such as ISO/IEC 27001 (information security management).
- Adopted by CEN as EN ISO/IEC 27555:2025 - applicable across member national standards bodies.
Keywords: PII deletion, ISO/IEC 27555, EN ISO/IEC 27555:2025, information security, privacy protection, deletion policies, retention periods, deletion classes, data deletion guidelines.