SOC 2 Control Implementation Guide

Asset, Data & Architecture

Secure Disposal and Deletion for SOC 2

Confidential information, customer data, system data, and personal information are deleted, anonymized, or rendered unrecoverable when no longer required or upon authorized request.

Use this guide to put the control into operation, decide what records to retain, and check that an auditor can trace the evidence back to the work your team performed.

Maintained by GreenHat Security · Reviewed August 21, 2026

What this control should accomplish

When data is no longer required or an authorized deletion is approved, all in-scope copies are removed, de-identified, or made unrecoverable using an appropriate method, and the company can show what happened, when, and with what result.

First SOC 2 program

A credible starting point

Run deletion through a tracked ticket that identifies the person or customer, data categories, systems, authorization, and expected backup expiry. Have an engineer execute and verify the work, and use device-management or certified disposal for physical media.

As the company scales

Make it repeatable

Build orchestrated deletion across product stores, search indexes, analytics, support tools, and subprocessors. Record job results, alert on failed steps, reconcile completed cases, and clearly communicate delayed removal from immutable backups where that behavior is authorized and documented.

How to implement Secure Disposal and Deletion

  1. 1

    Validate the deletion authority

    Confirm who authorized the deletion, the identity or tenant involved, what data is in scope, and whether a hold or other approved reason prevents any part of the request.

    You should end up with: An approved deletion case with verified subject, scope, and exclusions.

  2. 2

    Locate every relevant copy

    Use current data flows and inventories to identify primary stores, replicas, files, indexes, logs, analytics, support systems, vendors, backups, and physical media.

    You should end up with: A case-specific system and data-location list.

  3. 3

    Choose the disposal method

    Select hard deletion, lifecycle expiry, cryptographic erasure, approved de-identification, media sanitization, or another method suitable for the storage and data category.

    You should end up with: A documented method and expected completion or expiry time for each location.

  4. 4

    Execute across systems

    Perform the approved actions in each system and notify third parties or internal owners responsible for copies outside the primary product.

    You should end up with: Deletion job logs, administrative activity, disposal certificate, or third-party confirmation.

  5. 5

    Verify the result

    Query the relevant systems using stable identifiers, check job status and failure queues, and confirm that removed data is not available through normal product or administrative paths.

    You should end up with: A verification record with queries, status, reviewer, and date.

  6. 6

    Close exceptions and delayed copies

    Record any authorized residual copy, backup expiry date, access restriction, owner, and follow-up, then close only after all immediate steps are verified.

    You should end up with: A completed case with residual-copy tracking and closure approval.

Evidence to keep, and what it should prove

Build the evidence set in three layers: what defines the control, who approved or reviewed it, and what proves it operated. Collect operating records when the work happens so they remain dated, attributable, correctly scoped, and traceable to the underlying activity.

Before sharing, remove unrelated personal or customer data, never expose passwords, tokens, or secret values, preserve enough source context to authenticate the record, and use the secure exchange approved for the engagement.

Operating / technical evidence

Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

Deletion tickets

  • Confirm what the record proves

    Shows that a specific authorized deletion was scoped across relevant systems, executed, verified, and closed with residual copies or delays explicitly tracked.

  • Include this context

    case and subject or tenant identifier

  • Include this context

    authorization and scope

  • Include this context

    systems and data categories

  • Include this context

    actions and timestamps

  • Include this context

    verification result

  • Include this context

    exceptions and closure approver

Weak evidence to avoid

A closed task saying data deleted without authorization, system list, job result, verification query, or backup treatment.

disposal certificates

  • Confirm what the record proves

    Shows that identified media, devices, or records entrusted to an internal team or disposal provider were destroyed or rendered unrecoverable by a stated method.

  • Include this context

    certificate identifier

  • Include this context

    asset or media identifiers

  • Include this context

    quantity and custody owner

  • Include this context

    disposal method

  • Include this context

    completion date

  • Include this context

    provider or witness

Weak evidence to avoid

A recycling receipt with no serial numbers, media count, destruction method, completion date, or link to the retired assets.

media sanitization records

  • Confirm what the record proves

    Shows the exact device or medium sanitized, the approved technique and tool result, and the person who verified it before reuse or disposal.

  • Include this context

    asset and media identifier

  • Include this context

    data classification

  • Include this context

    sanitization method and tool

  • Include this context

    execution date and result

  • Include this context

    performer

  • Include this context

    verifier and final disposition

Weak evidence to avoid

An asset status changed to wiped without a device identifier, method, tool output, performer, or verification result.

anonymization evidence

  • Confirm what the record proves

    Shows that approved transformation removed or altered the identifiers and linkages relevant to the stated use, and that the resulting data was evaluated before being treated as de-identified.

  • Include this context

    source data set and purpose

  • Include this context

    fields and linkages addressed

  • Include this context

    transformation method and execution

  • Include this context

    resulting data location

  • Include this context

    validation method and result

  • Include this context

    reviewer and date

Weak evidence to avoid

A claim that names were removed while stable account IDs, free text, exact timestamps, or lookup tables still allow records to be linked back.

Which records should you prepare for the audit?

Type 1

Evidence at the as-of date

The current deletion, disposal, sanitization, and de-identification procedure, named roles, and system-to-data-location mapping, together with every related case open on the examination date. If none are open, include complete dated zero-result exports from each intake, job, asset, and disposal source and a reviewer-approved reconciliation showing no unmatched case, failed job, retired asset, or pending verification.

Type 2

Evidence across the review period

Every authorized customer or individual deletion, scheduled retention-expiry deletion run, system or record disposal, device or media sanitization, and approved de-identification operation performed during the review period, including failed, retried, partially completed, and canceled occurrences; plus every quarterly review due for production or customer-impacting assets and every annual review due for supporting assets, including completed no-change reviews, missed reviews, and rescheduled reviews.

Completeness check

Reconcile the quarterly production or customer-impacting and annual supporting-asset review schedules to dated review results, including no-change results, misses, and reschedules. Then reconcile approved privacy and customer deletion cases, retention-expiry candidates, retired assets, and disposal-provider manifests to system job logs, tickets, certificates, and verification results; investigate every missing execution, failed system step, unmatched asset, and overdue residual copy.

Build the record set from

  • privacy and customer request cases
  • deletion orchestration and job logs
  • database, storage, analytics, and backup platforms
  • device and asset management
  • disposal provider records
  • support and vendor administration systems

Keep these fields for each record

  • case or job identifier
  • authorization and trigger
  • required frequency and scheduled date
  • subject, tenant, asset, or data-set identifier
  • systems and data categories
  • method and execution time
  • result and verification
  • residual copy or exception
  • closure reviewer

How an auditor may test this control

Use this checklist to prepare for procedures an auditor may perform. The exact steps and sample selection depend on your engagement scope and the service auditor's professional judgment.

  • Confirm the intended control outcome

    Determine whether the control is designed to achieve this result: When data is no longer required or an authorized deletion is approved, all in-scope copies are removed, de-identified, or made unrecoverable using an appropriate method, and the company can show what happened, when, and with what result.

  • Confirm ownership and operating cadence

    Compare the documented owner with the intended role (Engineering / Infrastructure / Data Owner), then compare dated records with the stated cadence: Quarterly for production/customer-impacting; annually for supporting assets.

  • Establish the complete audit record set

    Reconcile the quarterly production or customer-impacting and annual supporting-asset review schedules to dated review results, including no-change results, misses, and reschedules. Then reconcile approved privacy and customer deletion cases, retention-expiry candidates, retired assets, and disposal-provider manifests to system job logs, tickets, certificates, and verification results; investigate every missing execution, failed system step, unmatched asset, and overdue residual copy.

  • Prepare the as-of-date evidence for a Type 1 engagement

    The current deletion, disposal, sanitization, and de-identification procedure, named roles, and system-to-data-location mapping, together with every related case open on the examination date. If none are open, include complete dated zero-result exports from each intake, job, asset, and disposal source and a reviewer-approved reconciliation showing no unmatched case, failed job, retired asset, or pending verification.

  • Prepare period evidence for a Type 2 engagement

    Every authorized customer or individual deletion, scheduled retention-expiry deletion run, system or record disposal, device or media sanitization, and approved de-identification operation performed during the review period, including failed, retried, partially completed, and canceled occurrences; plus every quarterly review due for production or customer-impacting assets and every annual review due for supporting assets, including completed no-change reviews, missed reviews, and rescheduled reviews.

  • Inspect the operating / technical evidence

    Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

    • Inspect Deletion tickets

      For each selected record, confirm it demonstrates Shows that a specific authorized deletion was scoped across relevant systems, executed, verified, and closed with residual copies or delays explicitly tracked.

      • case and subject or tenant identifier
      • authorization and scope
      • systems and data categories
      • actions and timestamps
      • verification result
      • exceptions and closure approver
    • Inspect disposal certificates

      For each selected record, confirm it demonstrates Shows that identified media, devices, or records entrusted to an internal team or disposal provider were destroyed or rendered unrecoverable by a stated method.

      • certificate identifier
      • asset or media identifiers
      • quantity and custody owner
      • disposal method
      • completion date
      • provider or witness
    • Inspect media sanitization records

      For each selected record, confirm it demonstrates Shows the exact device or medium sanitized, the approved technique and tool result, and the person who verified it before reuse or disposal.

      • asset and media identifier
      • data classification
      • sanitization method and tool
      • execution date and result
      • performer
      • verifier and final disposition
    • Inspect anonymization evidence

      For each selected record, confirm it demonstrates Shows that approved transformation removed or altered the identifiers and linkages relevant to the stated use, and that the resulting data was evaluated before being treated as de-identified.

      • source data set and purpose
      • fields and linkages addressed
      • transformation method and execution
      • resulting data location
      • validation method and result
      • reviewer and date
  • Trace the control from design to operation

    Use the categories that apply to this control: connect any policy or design artifact to its approval or review record, then trace a selected operating record through execution, result, and any exception or remediation.

Common implementation and evidence gaps

  • A ticket is marked complete without system-generated results or a verification query.
  • Search indexes, analytics, logs, support attachments, replicas, or third-party copies remain accessible.
  • Soft deletion hides a record from the user but retains it indefinitely in the database.
  • A shared-tenant deletion risks removing another customer’s data because scope was not validated.
  • Backup handling is stated vaguely without an expiry period or access restriction.
  • Failed deletion jobs do not alert an owner or reopen the case.

Before you call this control ready

  • Can a sampled deletion be traced from authorization through every identified system to verification?
  • Were replicas, indexes, logs, analytics, support tools, vendors, backups, and media considered?
  • Does each residual copy have a documented reason, protection, owner, and expected removal date?
  • Do job failures create visible follow-up and prevent premature case closure?
  • Can the company demonstrate that deleted data is no longer available through normal user or administrator paths?

Trust Services Criteria references

These identifiers help you navigate related Trust Services Criteria. They do not reproduce the criteria or prove that this control fully addresses them in your environment.

  • CC6.5
  • C1.2
  • P4.3

Confirm final scope, mappings, and testing expectations with your service auditor. SOC 2® is an AICPA trademark; GreenHat Security is not affiliated with or endorsed by AICPA.