{"id":7115,"date":"2025-01-28T08:41:40","date_gmt":"2025-01-28T14:41:40","guid":{"rendered":"https:\/\/www.darkreading.com\/data-privacy\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice"},"modified":"2025-01-28T08:41:40","modified_gmt":"2025-01-28T14:41:40","slug":"data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/01\/28\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice\/","title":{"rendered":"Data Privacy Day 2025: Time for Data Destruction to Become Standard Business Practice"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blta0fb9324e36f3532\/6798f60aae4913ce5ef885dc\/Adam_Strange_2023.png?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Compliance standards are shining new light on the need to better control and protect data. There are a multitude of different ways to implement a data protection and security strategy, but most organizations would admit that destroying data is not one typically prioritized.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As well as good business and cyber process, there are also data privacy regulations which mandate the deletion of data, such as the \u201cright to be forgotten\u201d under GDPR. Organizations need to be of the mindset that they both could and should be reducing their data estate as a part of normal business and compliance operations.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"More Controls Across the Entire Data Estate\">More Controls Across the Entire Data Estate<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There are many good reasons why organizations need to assume better control over their entire data estate. Among them: data privacy legislation, a growing sustainability agenda, and risk to the business of data exposure. But improved control should also involve acceptance that data has a lifecycle: a creation point, a period of operational life, and then a point when the data is beyond its useful life and should be deleted or removed. Operationally, at very least, less data is easier to control and manage.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Data deletion, or more precisely, data erasure, is an area of growing importance in IT and cybersecurity, driven by the reasons above, and more. The notion that data is created, used and stored away with little, if any, thought given to what happens to that data once it is no longer needed, is now from a bygone era. There is a need for a much more focused and cyclical approach, ultimately to destroy data when it is no longer of any business value.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Omdia believes enterprises should establish timelines for deletion or erasure once data is beyond its useful lifespan, or as a first step at least, to review the data for its business viability. Data should not be retained if its removal is required under some areas of data privacy legislation, or if that data no longer fulfils the purposes for which it was collected. This retention period, however, will depend on various factors, including legal obligations, the purpose of data processing, industry standards, and business needs.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"To Erase or Not to Erase?\">To Erase or Not to Erase?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Data destruction is not usually a commonly employed cybersecurity tactic. It almost seems to conflict with the human psyche, which seems to embrace the idea that the wholesale collection of data is somehow beneficial. \u201cThe more data, the better,\u201d seems to be the mantra.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, there is now beginning to be some movement against the \u201cmore is better\u201d ideology. As more and more data is created, organizations are wrestling with what to do with it all, and moreover, how to address compliancy with data privacy legislation. Large, and growing data volumes present a significant headache to CISOs and their teams. Can organizations put a hand on heart and claim they even know where all their data is, or that they know <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">what<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> it is?&nbsp; In a recent Omdia survey, only 11% of respondents, asked what percentage of their data they would be confident their organization could account for, felt they would be able to identify their entire data estate.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As data grows in volume and cost, there are also questions to be asked about how all the arrays necessary to store all the data are to be powered. Not forgetting, in addition, that as the threat landscape continues to grow, an effective backup strategy with duplicate copies of data is an increasingly important aspect of data security. This creates even more data, consuming more space and power. Failure to adopt a cyclical approach to data security therefore exposes an organization to significant risk as users and security teams alike invest most of their effort protecting and securing operational rather than archived data.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations have tended to take an \u201cignorance is bliss\u201d approach to stored or archived data. Now though, with regulatory pressures, increasingly limited available storage, an unwieldy and difficult-to-manage data estate, data subjects wanting more privacy, and the requirement for a demonstrable sustainability agenda, there is an urgent need to act.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Sustainability\">Sustainability<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The IT industry generates an enormous amount of waste as part of regular equipment refresh cycles; old equipment becomes redundant and needs disposal, which often means landfill. The outgoing equipment often still functions, but is less advanced and technically capable than a newer version more able to manage escalating workloads.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Omdia questions the sustainability of the way the industry currently operates, particularly in view of directives in the EU and elsewhere, around reducing the energy consumption required to process and transmit data. Furthermore, as many organizations begin to factor in environmental responsibility as a tool for brand enhancement, consuming more and more IT resources, to process growing volumes of data, is self-defeating.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Where infrastructure does need replacing, it is logical to clean all the data from the systems being replaced before items are disposed of or repurposed. In this case erasing data is a process in itself and needs to include written proof that the data has been permanently erased, with no potential for recourse.To simply go on creating more and more data, to use it for a period of time and then store it away, largely to be forgotten about, is a mindset that is antiquated and needs to be substantially adjusted. Data warrants much more focus; enterprises must adopt a lifecycle approach to data management, in particular that it has an end point, after which it needs removal. Storing data away and leaving it in perpetuity is dangerous, irresponsible and unnecessary. Ignored data poses risk to the business. Today, the risks data can present to an organization mean it is too important to be ignored.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/data-privacy\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Compliance standards are shining new light on the need to<\/p>\n","protected":false},"author":12,"featured_media":7116,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-7115","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?fit=1280%2C720&ssl=1",1280,720,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?fit=1280%2C720&ssl=1",1280,720,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?fit=1280%2C720&ssl=1",1280,720,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/data-privacy-day-2025-time-for-data-destruction-to-become-standard-business-practice.png?fit=1280%2C720&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=7115"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7115\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/7116"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=7115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=7115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=7115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}