Destruction of Personal Information

Destruction of Personal Information

Once your are no longer allowed to retain Personal Information (i.e. the retention period prescribed by law or determined by the company has come to an end), that Personal Information must be destroyed securely so that it cannot be reconstructed.

Remember, this applies to both hard copy and electronic versions of Personal Information, and care must be taken to ensure that (if multiple versions of electronic or hard copy information are retained) all of the Personal Information is destroyed.

The information must be destroyed securely. Secure destruction is as important as secure Processing and secure retention. Many data breaches arise as a result of not disposing of Personal Information correctly and securely.

De-identification can be used as an alternative to destruction, where necessary. Information is de-identified where it is no longer capable of re-identification by any reasonably foreseeable method.

To de-identify Personal Information means to destroy any information that:

  •  identifies the Data Subject (e.g. names and identification numbers), or
  • can be used, manipulated or linked by a reasonably foreseeable method to identify the Data Subject.