Overview
ISO/IEC 21964-1:2018 defines the principles and terms for the secure destruction of data carriers. The standard clarifies key concepts (data carrier, destruction, dissolving, equipment, collection point), establishes protection classes for data sensitivity, and describes a graded set of security levels (1–7) that characterize the effort required to recover information after destruction. It provides procedural guidance for selecting, assigning and - where appropriate - increasing security levels for destroyed media.
Key topics and requirements
- Definitions and scope: Precise meanings for terms such as data carrier, destruction, data controller and collection point to support consistent implementation.
- Protection classes (1–3):
- Class 1 - normal protection (internal data)
- Class 2 - higher protection (confidential data)
- Class 3 - very high protection (strictly confidential / secret data)
- Security levels (1–7): Describes levels from easily reproducible with modest effort (Level 1) to unrecoverable with current technology or scientific knowledge (Levels 6–7). These levels guide how aggressively media must be destroyed.
- Assignment and selection: Protection classes are mapped to appropriate security levels; organizations should perform a risk analysis when choosing the destruction requirements. Consider media characteristics (density, colour, miniaturization) when selecting a level.
- Collection point handling: If media of different security levels are co-located, sort by level or destroy to the higher level to avoid under-protection.
- Altering security level: Increasing security by mixing/compacting shredded material is permitted under controlled conditions (applicable rules include minimum mass and single-cycle processing); machines/equipment must be clearly labelled with their security level.
- Responsibility: The data controller determines methods to increase security, subject to applicable regulations. On-site destruction by the data controller is preferable when available.
Applications
ISO/IEC 21964-1:2018 is intended for any organization that processes personal, confidential, or sensitive data and must ensure privacy through physical destruction of media. Typical users:
- Data controllers and compliance officers designing data disposal policies
- IT asset disposal (ITAD) and secure destruction service providers
- Records managers and information security teams
- Procurement specialists specifying destruction equipment and services
Practical uses include defining destruction requirements for paper, magnetic and optical media; selecting appropriate shredders or destruction processes; establishing collection-point procedures; and demonstrating due diligence for privacy and regulatory compliance.
Related standards
- ISO/IEC 21964 series (other parts addressing equipment/media specifics)
- DIN 66399-1 (origin referenced in standard preparation)
- ISO 9000, EN 50131, EN 14968 (references cited in the document)
For implementation details or national adoption, consult your national standards body or the full ISO/IEC 21964-1:2018 text.