The National Security Scheme (ENS) establishes a security framework for the protection of information managed by public administrations in Spain, ensuring the integrity, availability and confidentiality of the data.
Point 5.5.5 of the ENS, labeled [mp.si.5], specifies the requirements for the secure erasure and destruction of information, in order to prevent the recovery or reconstruction of sensitive data once it has been decided its elimination. This process is essential to ensure that personal data and sensitive information are not accessible once they are no longer needed.
To comply with the ENS, entities must adopt erasure methods that ensure the definitive deletion of data. This includes:
It is essential that organizations implement procedures to verify that data erasure and destruction have been carried out correctly. Additionally, they must maintain detailed documentation of the deletion process, including the methods used and confirmation that the data has indeed been deleted.
Adhering to this requirement not only protects sensitive information but also ensures compliance with data protection regulations. Entities must be prepared to demonstrate, in the event of an audit, that they have implemented secure data erasure practices in accordance to the standards established by the ENS.