The organization should establish and maintain processes and technical capabilities for the secure and timely deletion of personal data across all its products, services, and associated systems. This includes ensuring that components, devices, operating systems, storage, integrated systems, applications, and business processes (including self-service, integration, cloud, and outsourced processes) provide the necessary functionality to delete personal data when required. Procedures should define how data is deleted, who is responsible, and how the deletion is verified.