prBAS EN ISO/IEC 27555:2026

Information security, cybersecurity and privacy protection - Guidelines on personally identifiable information deletion (ISO/IEC 27555:2021)


General information
Status:Project
Number of pages:38
Adoption method:Proglašavanje
Language:engleski
Edition:1.
Realization date:19.11.2025
Forseen date for next stage code:26.11.2025
Technical committee:BAS/TC 1, Information technology
ICS:
35.030, IT Security

Abstract
This document contains guidelines for developing and establishing policies and procedures for deletion of personally identifiable information (PII) in organizations by specifying: —    a harmonized terminology for PII deletion; —    an approach for defining deletion rules in an efficient way; —    a description of required documentation; —    a broad definition of roles, responsibilities and processes. This document is intended to be used by organizations where PII is stored or processed. This document does not address: —    specific legal provision, as given by national law or specified in contracts; —    specific deletion rules for particular clusters of PII that are defined by PII controllers for processing PII; —    deletion mechanisms; —    reliability, security and suitability of deletion mechanisms; —    specific techniques for de-identification of data.

Lifecycle
...

Original document and degree of correspondence
EN ISO/IEC 27555:2025, identical
ISO/IEC 27555:2021, identical

Relation to BAS standards

Work material

Only members of the technical committee have access to work material. If you are a members of this technical committee you need to login to view the documents. Login