Overview
ISO/IEC 21964-3:2018 - “Information technology - Destruction of data carriers - Part 3: Process of destruction of data carriers” defines requirements for a secure, auditable process of data carrier destruction. It applies to the responsible authority (data controller) and all parties involved in collection, transport, destruction and environmentally compliant disposal. The standard treats destruction as a controlled process from origin to final destruction, ensuring that reproduction of protected information is impossible or highly impractical.
Key topics and technical requirements
- Process definition and lifecycle: The standard requires a documented destruction process that covers collection, storage, transport, handling and final destruction.
- Risk analysis and protection classes: Data must be categorized by sensitivity (see ISO/IEC 21964-1) and assigned protection classes to determine required security levels.
- Process execution and responsibilities: The data controller remains responsible for the entire process and must clearly delimit responsibilities when using external service providers. Decisions include on-site vs. off-site destruction and who performs each step.
- Technical and organizational measures: Measures must reflect state-of-the-art restoration technologies, including early impairment of data carrier functionality and, where feasible, erasure/overwrite prior to destruction. Equipment must meet requirements referenced in ISO/IEC 21964-2.
- Inspection, testing and documentation: Service providers must document process steps; data controllers must verify process reliability before and during contracts. Audits and on-site inspections are required, and certificates for providers should be issued by accredited bodies and limited to three years.
- Process criteria and varieties: The standard defines criteria for several process varieties (e.g., destruction by the data controller, by an external provider, hybrid scenarios) and includes requirements for records such as take-over and destruction logs.
Applications - who should use it
- Data controllers (public authorities, enterprises) designing secure disposal workflows for confidential, personal or sensitive data.
- IT asset disposal (ITAD) and shredding service providers implementing auditable destruction processes to meet client and regulatory requirements.
- Security officers and compliance teams establishing procurement criteria, verifying service-provider certificates and conducting audits.
- Auditors and certifying bodies assessing conformity with data destruction process requirements.
Related standards
Use ISO/IEC 21964-3:2018 when you need an auditable, risk-based framework for secure data carrier destruction that ties process controls, equipment requirements and supplier verification into a single, standards-based program.