Secure deletion begins with deciding which information should be deleted and which must be retained for a justified purpose. Map the copies and systems involved before acting. Deleting a customer profile from one application may leave the same information in email, exports or supplier systems.
Distinguish a routine retention action from an individual erasure request, which requires its own assessment. Check legal obligations and relevant holds without using them as an excuse to keep everything. Record the action and outcome without recreating the deleted information in the deletion log.
Establish the reason and scope of deletion
Identify whether the task follows the retention schedule, a customer request or a system migration. Each has different questions to resolve before removal. A request to stop marketing is not automatically a request to erase all transaction records, while a general account closure may leave necessary evidence for another justified purpose. Record the categories affected and the reason for any information that will remain.
Check scoped legal or dispute holds before launching an automatic process. Ask the responsible adviser to identify the relevant records rather than accepting an instruction to preserve everything without review. The ICO's storage limitation guidance supports reviewing information no longer needed. [1] Separate that assessment from the technical method used to remove it; software cannot decide the legal purpose merely from a file's age.
Locate copies that ordinary deletion misses
Map the customer identifier across the CRM, email, documents, support tickets and supplier systems. Include exports, spreadsheets and duplicate profiles using old contact details. Check whether deleting the visible account leaves attachments or notes accessible elsewhere. A system's delete button may deactivate an interface record while retaining content for another period, so ask for a clear explanation of actual behaviour.
Treat shared links and synchronised devices as separate checks. Removing a central record does not necessarily remove a downloaded copy or an attachment already sent to a colleague. Decide what instructions and evidence are appropriate for those locations. Where data is genuinely anonymous after a process, document why re-identification is not reasonably possible instead of assuming removal of a name is sufficient.
Choose an appropriate technical method
For cloud records, use the provider's supported deletion and account closure processes with appropriate verification. For physical media or devices, consider suitable secure erasure or destruction and obtain competent technical support where needed. Ordinary file deletion can leave recoverable content. Do not reuse or sell equipment containing client information simply because its desktop folders appear empty after a routine reset.
Keep evidence proportionate to the risk: the dataset or device identifier, method, responsible person and outcome may be useful without retaining the erased material itself. If a supplier carries out the work, verify what its certificate or report actually covers. A document confirming disposal of one device does not establish that backups, cloud synchronisation and another exported copy have also been addressed.
Handle backups and suppression deliberately
Document controlled backup expiry and the procedure following restoration. Restrict archived information from ordinary use while it awaits the appropriate cycle. Avoid an absolute promise of immediate removal from every backup if the technical design does not support it. Conversely, do not maintain an accessible operational copy indefinitely under the convenient label backup.
Marketing suppression may require limited identifiers to prevent future contact. Explain that purpose and restrict the record accordingly, rather than deleting the objection and later importing the same address again. The guide to Marketing consent and customer preferences covers this distinction, while Creating a personal data retention schedule establishes the retention categories and triggers that routine deletion should implement. Check migration imports against suppression before the new system is used for campaigns.
Verify outcomes without recreating the information
Test a sample using appropriate identifiers and confirm that the intended live records are no longer available. Investigate errors and unresolved copies before marking the task complete. Record retained categories and reasons clearly enough to explain the result to the relevant person where necessary. Avoid retaining screenshots of entire deleted records as proof, since that creates another copy of the information the process was meant to remove.
For Business privacy notice review, provide the deletion reason, system map and any proposed exceptions. Ask the technical team to identify inaccessible copies and backup constraints honestly. The resulting plan should distinguish immediate actions, controlled expiry and justified retention, with an owner for each unresolved item. Review the process when a new integration or export route creates additional copies outside the existing deletion instructions.
Retire devices through a documented route
Before disposing of a laptop or returning leased equipment, identify local downloads, synchronised folders and removable storage associated with it. Confirm who performs the chosen erasure or destruction method and what evidence they provide. Deleting visible desktop files does not establish that the device is ready to leave the business.
Match the completion record to an asset identifier so the organisation can distinguish equipment awaiting treatment from equipment already cleared. Where a specialist contractor is used, check collection custody and any subcontracting arrangements. Keep the evidence limited to what is needed to demonstrate the process; it should not contain copies of the confidential documents that were supposed to be removed.
Illustrative scenario
A retailer removes an old customer from its marketing platform but retains an export on a shared drive. The revised deletion process includes the export location and suppresses re-import into future campaigns. Transaction records that need lawful retention are treated separately from unnecessary marketing data.
Preparation checklist
- Identify the purpose and authority for deletion.
- Locate copies, exports, archives and supplier records.
- Check justified retention exceptions and scoped holds.
- Record completion and any controlled backup expiry process.
Frequently asked questions
Does closing an account erase every record?
Not necessarily. Check attachments, exports, connected systems and the provider's retention behaviour. Some information may remain for a justified purpose, which needs a separate documented decision.
Can we retain a copy to prove deletion?
Keep limited process evidence without recreating the removed content. A log of categories, method and outcome is usually more appropriate than screenshots containing the complete personal record.
What about an active legal dispute?
Apply a properly scoped hold to relevant records and review it. Avoid treating one dispute as a reason to retain unrelated information indefinitely across every system.
Does a marketing objection require deleting suppression data?
Limited suppression information may be needed to prevent future contact. Restrict it to that purpose and ensure future imports cannot silently restore the person to an active audience.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction