SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Destruction of printed confidential data

  Quote
Guest
Guest user Created:   May 06, 2020 Last commented:   May 08, 2020

Destruction of printed confidential data

Hi, I'm trying to validate internal guidance I have been provided that says that in order to comply with ISO27001 we cannot use our own shredders to dispose of our own media but MUST use an outside company to do this? We currently have our own locked shredders and have appointed personnel to dispose of the shredded media via re-cycling.

0 0

Assign topic to the user

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Alessandra Nisticò May 08, 2020

ISO 27001 and GDPR give no unique solution on how to dispose of your printed documents. ISO 27001 requires classifying documentation and you can implement different procedures depending on the information incorporated in the printed document. Is there any confidential information? Are you dealing with a particular kind of personal data under Article 9 GDPR? Do the printed documents contain no personal information or anonymized information? The solution can be different.

Any disposal should comply with your data retention policy and data protection policy in order to avoid accidental destruction of documentation which is considered a data breach because of its impact on the integrity of data.If you decide to appoint an outside company, you need to check their compliance with GDPR requirements and other quality standards such as ISO 27001 and the recycling process. Under GDPR you should make a data processing agreement with your supplier because the outside company will process (through destruction) data on your behalf.

Here you can find some useful information on printed documentation under ISO 27001

Our template of Supplier Data Processing Agreement may be of help:https://advisera.com/eugdpracademy/documentation/supplier-data-processing-agreement/  

You can also consider enrolling in this free online training EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//

If you need more information, you can also consider enrolling in this free online training ISO 27001 Foundations Course: https://advisera.com/training/iso-27001-foundations-course/ 

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 06, 2020

May 08, 2020

Suggested Topics

Guest user Created:   Feb 23, 2023 EU GDPR
Replies: 1
0 0

Data privacy question