Frameworks / ISO 27001:2022 / 5.34 ISO 27001:2022
Organizational controls – ISO 27001:2022
ISO 27001:2022 5.34: Privacy and protection of personal identifiable information (PII) The organization is to identify, and then satisfy, the requirements for preserving privacy and protecting personally identifiable information that arise from applicable laws, regulations and contracts. Purpose (stated in ISO/IEC 27002:2022): ensures compliance with requirements on the information security aspects of protecting PII. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.34.
Maintained by Gerard Blokdyk · Verified against the published standard 18 August 2026 · Control text last updated 25 September 2026 What else in your programme already covers this This control maps to 135 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
6.1 General 6.15.1 Compliance with legal and contractual requirements 7.1 General 7.2.1 Identify and document purpose 7.2.2 Identify lawful basis 7.2.3 Determine when and how consent is to be obtained 7.2.4 Obtain and record consent 7.2.5 Privacy impact assessment 7.2.7 Joint PII controller 7.2.8 Records related to processing PII 7.3 Obligations to PII principals 7.3.1 Determining and fulfilling obligations to PII principals 7.3.10 Automated decision making 7.3.2 Determining information for PII principals 7.3.3 Providing information to PII principals 7.3.4 Providing mechanism to modify or withdraw consent 7.3.5 Providing mechanism to object to PII processing 7.3.6 Access, correction and/or erasure 7.3.8 Providing copy of PII processed 7.3.9 Handling requests 7.4.1 Limit collection 7.4.2 Limit processing 7.4.3 Accuracy and quality 7.4.4 PII minimization objectives 7.5 PII sharing, transfer, and disclosure 7.5.1 Identify basis for PII transfer between jurisdictions 7.5.4 Records of PII disclosure to third parties 8.1 General 8.2 Conditions for collection and processing 8.2.3 Marketing and advertising use 8.2.5 Customer obligations 8.3 Obligations to PII principals 8.3.1 Obligations to PII principals 8.4 Privacy by design and privacy by default 8.5.1 Basis for PII transfer between jurisdictions 8.5.2 Countries and international organizations to which PII can be transferred 8.5.3 Records of PII disclosure to third parties 8.5.4 Notification of PII disclosure requests 8.5.5 Legally binding PII disclosures 8.5.8 Change of subcontractor to process PII SOC2-P1.1 P1.1 Privacy notice to data subjects SOC2-P2.1 P2.1 Choice and consent SOC2-P3.1 P3.1 Collecting personal information consistent with objectives SOC2-P3.2 P3.2 Explicit consent before collecting information that requires it SOC2-P4.1 P4.1 Limiting use to identified purposes SOC2-P4.2 P4.2 Retaining personal information SOC2-P4.3 P4.3 Securely disposing of personal information SOC2-P5.1 P5.1 Data subject access SOC2-P5.2 P5.2 Correction of personal information SOC2-P6.1 P6.1 Disclosure to third parties with consent SOC2-P6.2 P6.2 Record of authorised disclosures SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties SOC2-P6.6 P6.6 Notifying breaches and incidents SOC2-P6.7 P6.7 Accounting of personal information held and disclosed SOC2-P7.1 P7.1 Quality of personal information SOC2-P8.1 P8.1 Inquiries, complaints, disputes and compliance monitoring 8.4 AI system impact assessment A.2.3 Alignment with other organizational policies A.5.4 Assessing AI system impact on individuals or groups of individuals A.7 Data for AI systems A.7.3 Acquisition of data A.9 Use of AI systems A.9.2 Processes for responsible use of AI systems CCM-DSP-01 Security and Privacy Policy and Procedures CCM-DSP-08 Data Privacy by Design and Default CCM-DSP-09 Data Protection Impact Assessment CCM-DSP-11 Personal Data Access, Reversal, Rectification and Deletion CCM-DSP-12 Limitation of Purpose in Personal Data Processing CCM-DSP-18 Disclosure Notification APPI-A18 Restriction on Handling Beyond the Purpose of Use APPI-A21 Notice or Public Announcement of the Purpose of Use APPI-A23 Security Control Measures APPI-A32 Matters Concerning Retained Personal Data to Be Made Accessible APPI-A46 Security and Proper Handling of Anonymized Personal Information EUAI-Art.26 Obligations of deployers of high-risk AI systems EUAI-Art.27 Fundamental rights impact assessment for high-risk AI systems EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox EUAI-Art.86 Right to explanation of individual decision-making 4.2.2 Legal and regulatory requirements 6.1.2 Addressing risks and opportunities 7.4 Communication 8.2.2 Business impact analysis 3.2.1 3.2.1 Data retention and disposal minimise stored account data 3.3.1 3.3.1 SAD not retained after authorization, even encrypted 3.4.1 3.4.1 PAN masked on display except for authorized roles SEC07-BP01 Understand your data classification scheme SEC07-BP03 Automate identification and classification AUCDR-PS-1 Privacy Safeguard 1 - Open and transparent management of CDR data AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data MYHR-CUD-1 Authorised collection, use and disclosure only MYHR-CUD-3 Use limited to My Health Record purposes DORA-Art.45 Information-sharing arrangements on cyber threat information and intelligence DORA-Art.56 Data protection CPS230-9 Management of the Full Range of Operational Risks ASBv3-DP-1 Discover, classify, and label sensitive data C5-INQ-03 Conditions for Access to or Disclosure of Data in Investigation Requests A.18.1.4 Privacy and protection of personally identifiable information 5.34 Privacy and protection of PII Art.28 Maintain accurate domain name registration data and answer lawful access requests within 72 hours NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed 27(1)(k) Art. 27(1)(k) Obtain the works council's consent to a staff arrangement: processing and protection of staff personal data Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Organizational controls – ISO 27001:2022 You are reading one control. How much of ISO 27001:2022 have you already done? ISO 27001:2022 5.34 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 135 it maps to, and the evidence behind each claim, over MCP and REST.