Standard and Guide

ISO 27001 — Information Security and Data Destruction

ISO/IEC 27001:2022 explained: the information security standard, its Annex A controls on storage media, equipment disposal and deletion, and the link to Turkey's KVKK data destruction rules.

Status
Yürürlükte

What is ISO 27001 and which version applies?

ISO/IEC 27001 is an international standard that defines the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). It is not a Turkish law or regulation; it is published by ISO and IEC. The current version is ISO/IEC 27001:2022, the third edition, published in October 2022 and complemented by a 2024 amendment on climate action.

The standard aims to protect the confidentiality, integrity and availability of information through a risk management process. Under the transition timetable set by the International Accreditation Forum (IAF), certificates based on the 2013 version expired on 31 October 2025; certificates valid today are based on the 2022 version.

How does information destruction relate to Annex A controls?

Annex A of ISO/IEC 27001:2022 groups the 93 controls of ISO/IEC 27002:2022 under four themes: organisational, people, physical and technological. Three controls bear directly on destruction:

  • 7.10 — Managing storage media through their life cycle, from acquisition and use to transport and disposal
  • 7.14 — Disposing of equipment securely, or re-using it safely
  • 8.10 — Deleting information in systems, devices and other media once it is no longer needed

These controls ask how, and by whom, an organisation disposes of assets such as old disks, backup tapes, devices and paper archives. The organisation chooses how to implement the controls according to its own risk assessment and documents that choice.

What is the link to the KVKK and the deletion and destruction regulation?

Under Article 7 of the Personal Data Protection Law No. 6698, when the reasons for processing disappear, personal data are deleted, destroyed or anonymised, either on the controller's own initiative or at the data subject's request. Article 12 of the Law requires the data controller to take all necessary technical and administrative measures to ensure an appropriate level of security.

The procedure is set out in the Regulation on the Deletion, Destruction or Anonymisation of Personal Data, published in the Official Gazette dated 28 October 2017, No. 30224. The Regulation defines deletion, destruction and anonymisation separately (Articles 8-10); for a data controller with a retention and destruction policy, the interval for periodic destruction cannot exceed six months (Article 11). All operations are recorded and the records are kept for at least three years (Article 7).

Is ISO 27001 mandatory in Turkey?

ISO 27001 is an international, voluntary standard; the provisions of the Law cited on this page do not require a certificate for any specific standard. Article 12 of the Law names no standard and asks for technical and administrative measures. Customer contracts or sector requirements may, however, ask for a certificate separately.

Holding an ISO 27001 certificate does not in itself mean that KVKK obligations have been met; the two frameworks complement each other. The standard offers a management system and a control framework, while the KVKK sets the legal obligations.

Why does secure destruction matter in practice?

Being able to show that deletion or destruction took place is as important as the operation itself. The type, date, method and person responsible for each destroyed medium should be recorded, and those records kept for the periods the KVKK sets. For physical media, a written internal procedure and, where a third party is used, the contract and handover documents with that party are part of this chain of records.

Bu içerik bilgilendirme amaçlıdır; hukuki veya mali görüş yerine geçmez. Bağlayıcı metin için mevzuat.gov.tr'yi esas alınız. Kurumunuza özel değerlendirme için Scrap uzmanlarıyla görüşün.