prBAS EN ISO/IEC 27555:2026
Information security, cybersecurity and privacy protection - Guidelines on personally identifiable information deletion (ISO/IEC 27555:2021)
General information
Status:Project
Number of pages:38
Adoption method:Proglašavanje
Language:engleski
Edition:1.
Realization date:19.11.2025
Forseen date for next stage code:26.11.2025
Technical committee:BAS/TC 1, Information technology
ICS:
35.030, IT Security
Abstract
This document contains guidelines for developing and establishing policies and procedures for deletion of personally identifiable information (PII) in organizations by specifying:
— a harmonized terminology for PII deletion;
— an approach for defining deletion rules in an efficient way;
— a description of required documentation;
— a broad definition of roles, responsibilities and processes.
This document is intended to be used by organizations where PII is stored or processed.
This document does not address:
— specific legal provision, as given by national law or specified in contracts;
— specific deletion rules for particular clusters of PII that are defined by PII controllers for processing PII;
— deletion mechanisms;
— reliability, security and suitability of deletion mechanisms;
— specific techniques for de-identification of data.
Lifecycle
...
Original document and degree of correspondence
EN ISO/IEC 27555:2025, identical
ISO/IEC 27555:2021, identical
Relation to BAS standards
Work material
Only members of the technical committee have access to work material. If you are a members of this technical committee you need to login to view the documents. Login