HomeKnowledge HubStandards & Frameworks › ISO/IEC 21964 (DIN 66399)

International standard · Standards & Frameworks

ISO/IEC 21964 — the standard behind shredding security levels and destruction certificates

ISO/IEC JTC 1Edition 1, August 2018Confirmed by ISO, May 2025

When a disposal contractor’s certificate says “destroyed to P-4” or “security level H-5”, this is the standard being cited. ISO/IEC 21964 is the international version of Germany’s DIN 66399 and sets out how data carriers — paper, film, optical and magnetic media, hard drives, solid-state storage — are classified and physically destroyed.

Published by
ISO and IEC, Joint Technical Committee 1.
Type
International standard in three parts: Part 1, Principles and definitions (6 pages); Part 2, Requirements for equipment for destruction of data carriers; Part 3, Process of destruction of data carriers (8 pages).
Versions and language
Edition 1, August 2018 (Part 1 published 30 July 2018). All three parts stand at ISO stage 90.93, confirmed 10 May 2025. English.
Jurisdiction
International; German origin (DIN 66399).
Primary audience
DPOs and records managers writing disposal policies; procurement; IT asset disposal providers.
Topic tags
data destruction · retention and disposal · storage limitation · UK GDPR Art. 5(1)(e) · Art. 32
Availability
Paid (Part 1 CHF 44 and Part 3 CHF 67 from ISO at the time of verification).

Why it matters

Retention schedules end in disposal, and disposal is where a good policy meets a contractor’s certificate. Two standards divide the ground. NIST SP 800-88 Rev. 2 covers sanitisation — clearing, purging or destroying media so that data cannot be recovered, including overwriting and cryptographic erase — and is what most UK retention policies cite for “securely erased”. ISO/IEC 21964 covers only physical destruction, but it is the standard that defines the vocabulary contractors use: protection classes for the sensitivity of the data and security levels for each carrier type (P for paper, F for film, O for optical, T for magnetic, H for hard drives, E for electronic media).

Part 3 sets requirements for the destruction process — ISO’s abstract describes it as applicable to the responsible authority and to all parties involved — which is the part a DPO auditing an Article 28 processor is most likely to need: who is responsible, how custody is evidenced, and what the certificate should show.

The UK position. Neither UK GDPR nor the ICO mandates any destruction standard. The ICO’s disposal guidance expects appropriate methods and evidence that they were used; a certificate against this standard is one recognisable way of evidencing that. Where an ISO/IEC 21964 level is specified in a contract, it is worth checking that the level matches the sensitivity of the data rather than the contractor’s default — the standard supplies the scale, not the choice. The ADISA ICT Asset Recovery Standard, listed in Codes & Schemes, is the ICO-approved UK GDPR certification for the disposal industry and sits alongside this.

A curated reference entry maintained by VulaPri. We summarise and link to the original; we do not reproduce or host it. Listed since 15 September 2026 · last verified 15 September 2026 — facts verified against iso.org (Parts 1 and 3 life-cycle pages read 11 September 2026; Part 2 title from ISO’s catalogue listing). Suggest a correction.