ISO/IEC 21964 — the standard behind shredding security levels and destruction certificates
When a disposal contractor’s certificate says “destroyed to P-4” or “security level H-5”, this is the standard being cited. ISO/IEC 21964 is the international version of Germany’s DIN 66399 and sets out how data carriers — paper, film, optical and magnetic media, hard drives, solid-state storage — are classified and physically destroyed.
- Published by
- ISO and IEC, Joint Technical Committee 1.
- Type
- International standard in three parts: Part 1, Principles and definitions (6 pages); Part 2, Requirements for equipment for destruction of data carriers; Part 3, Process of destruction of data carriers (8 pages).
- Versions and language
- Edition 1, August 2018 (Part 1 published 30 July 2018). All three parts stand at ISO stage 90.93, confirmed 10 May 2025. English.
- Jurisdiction
- International; German origin (DIN 66399).
- Primary audience
- DPOs and records managers writing disposal policies; procurement; IT asset disposal providers.
- Topic tags
- data destruction · retention and disposal · storage limitation · UK GDPR Art. 5(1)(e) · Art. 32
- Availability
- Paid (Part 1 CHF 44 and Part 3 CHF 67 from ISO at the time of verification).
Why it matters
Retention schedules end in disposal, and disposal is where a good policy meets a contractor’s certificate. Two standards divide the ground. NIST SP 800-88 Rev. 2 covers sanitisation — clearing, purging or destroying media so that data cannot be recovered, including overwriting and cryptographic erase — and is what most UK retention policies cite for “securely erased”. ISO/IEC 21964 covers only physical destruction, but it is the standard that defines the vocabulary contractors use: protection classes for the sensitivity of the data and security levels for each carrier type (P for paper, F for film, O for optical, T for magnetic, H for hard drives, E for electronic media).
Part 3 sets requirements for the destruction process — ISO’s abstract describes it as applicable to the responsible authority and to all parties involved — which is the part a DPO auditing an Article 28 processor is most likely to need: who is responsible, how custody is evidenced, and what the certificate should show.
The UK position. Neither UK GDPR nor the ICO mandates any destruction standard. The ICO’s disposal guidance expects appropriate methods and evidence that they were used; a certificate against this standard is one recognisable way of evidencing that. Where an ISO/IEC 21964 level is specified in a contract, it is worth checking that the level matches the sensitivity of the data rather than the contractor’s default — the standard supplies the scale, not the choice. The ADISA ICT Asset Recovery Standard, listed in Codes & Schemes, is the ICO-approved UK GDPR certification for the disposal industry and sits alongside this.
