ISO 27001:2022
Organizational controls – ISO 27001:2022

ISO 27001:2022 5.34: Privacy and protection of personal identifiable information (PII)

The organization is to identify, and then satisfy, the requirements for preserving privacy and protecting personally identifiable information that arise from applicable laws, regulations and contracts. Purpose (stated in ISO/IEC 27002:2022): ensures compliance with requirements on the information security aspects of protecting PII. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.34.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 135 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 40 controls

  • 6.1 General
  • 6.15.1 Compliance with legal and contractual requirements
  • 7.1 General
  • 7.2.1 Identify and document purpose
  • 7.2.2 Identify lawful basis
  • 7.2.3 Determine when and how consent is to be obtained
  • 7.2.4 Obtain and record consent
  • 7.2.5 Privacy impact assessment
  • 7.2.7 Joint PII controller
  • 7.2.8 Records related to processing PII
  • 7.3 Obligations to PII principals
  • 7.3.1 Determining and fulfilling obligations to PII principals
  • 7.3.10 Automated decision making
  • 7.3.2 Determining information for PII principals
  • 7.3.3 Providing information to PII principals
  • 7.3.4 Providing mechanism to modify or withdraw consent
  • 7.3.5 Providing mechanism to object to PII processing
  • 7.3.6 Access, correction and/or erasure
  • 7.3.8 Providing copy of PII processed
  • 7.3.9 Handling requests
  • 7.4.1 Limit collection
  • 7.4.2 Limit processing
  • 7.4.3 Accuracy and quality
  • 7.4.4 PII minimization objectives
  • 7.5 PII sharing, transfer, and disclosure
  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 7.5.4 Records of PII disclosure to third parties
  • 8.1 General
  • 8.2 Conditions for collection and processing
  • 8.2.3 Marketing and advertising use
  • 8.2.5 Customer obligations
  • 8.3 Obligations to PII principals
  • 8.3.1 Obligations to PII principals
  • 8.4 Privacy by design and privacy by default
  • 8.5.1 Basis for PII transfer between jurisdictions
  • 8.5.2 Countries and international organizations to which PII can be transferred
  • 8.5.3 Records of PII disclosure to third parties
  • 8.5.4 Notification of PII disclosure requests
  • 8.5.5 Legally binding PII disclosures
  • 8.5.8 Change of subcontractor to process PII

NIST SP 800-53 Rev 5 · 17 controls

SOC 2 · 17 controls

  • SOC2-P1.1 P1.1 Privacy notice to data subjects
  • SOC2-P2.1 P2.1 Choice and consent
  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC2-P3.2 P3.2 Explicit consent before collecting information that requires it
  • SOC2-P4.1 P4.1 Limiting use to identified purposes
  • SOC2-P4.2 P4.2 Retaining personal information
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • SOC2-P5.1 P5.1 Data subject access
  • SOC2-P5.2 P5.2 Correction of personal information
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent
  • SOC2-P6.2 P6.2 Record of authorised disclosures
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • SOC2-P6.7 P6.7 Accounting of personal information held and disclosed
  • SOC2-P7.1 P7.1 Quality of personal information
  • SOC2-P8.1 P8.1 Inquiries, complaints, disputes and compliance monitoring

ISO/IEC 42001:2023 · 7 controls

  • 8.4 AI system impact assessment
  • A.2.3 Alignment with other organizational policies
  • A.5.4 Assessing AI system impact on individuals or groups of individuals
  • A.7 Data for AI systems
  • A.7.3 Acquisition of data
  • A.9 Use of AI systems
  • A.9.2 Processes for responsible use of AI systems
  • CCM-DSP-01 Security and Privacy Policy and Procedures
  • CCM-DSP-08 Data Privacy by Design and Default
  • CCM-DSP-09 Data Protection Impact Assessment
  • CCM-DSP-11 Personal Data Access, Reversal, Rectification and Deletion
  • CCM-DSP-12 Limitation of Purpose in Personal Data Processing
  • CCM-DSP-18 Disclosure Notification

APPI · 5 controls

  • APPI-A18 Restriction on Handling Beyond the Purpose of Use
  • APPI-A21 Notice or Public Announcement of the Purpose of Use
  • APPI-A23 Security Control Measures
  • APPI-A32 Matters Concerning Retained Personal Data to Be Made Accessible
  • APPI-A46 Security and Proper Handling of Anonymized Personal Information

HIPAA Security Rule · 5 controls

EU AI Act · 4 controls

  • EUAI-Art.26 Obligations of deployers of high-risk AI systems
  • EUAI-Art.27 Fundamental rights impact assessment for high-risk AI systems
  • EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox
  • EUAI-Art.86 Right to explanation of individual decision-making

GDPR · 4 controls

ISO 22301:2019 · 4 controls

  • 4.2.2 Legal and regulatory requirements
  • 6.1.2 Addressing risks and opportunities
  • 7.4 Communication
  • 8.2.2 Business impact analysis

NIST SP 800-66 Rev 2 · 3 controls

PCI DSS 4.0 · 3 controls

  • 3.2.1 3.2.1 Data retention and disposal minimise stored account data
  • 3.3.1 3.3.1 SAD not retained after authorization, even encrypted
  • 3.4.1 3.4.1 PAN masked on display except for authorized roles
  • SEC07-BP01 Understand your data classification scheme
  • SEC07-BP03 Automate identification and classification
  • AUCDR-PS-1 Privacy Safeguard 1 - Open and transparent management of CDR data
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data
  • MYHR-CUD-1 Authorised collection, use and disclosure only
  • MYHR-CUD-3 Use limited to My Health Record purposes

DORA · 2 controls

  • DORA-Art.45 Information-sharing arrangements on cyber threat information and intelligence
  • DORA-Art.56 Data protection

NIST SP 800-161 Rev 1 · 2 controls

  • CPS230-9 Management of the Full Range of Operational Risks
  • ASBv3-DP-1 Discover, classify, and label sensitive data

C5 (Germany) · 1 control

  • C5-INQ-03 Conditions for Access to or Disclosure of Data in Investigation Requests

CMMC 2.0 · 1 control

ISO 27001:2013 · 1 control

  • A.18.1.4 Privacy and protection of personally identifiable information

ISO 27002:2022 · 1 control

  • 5.34 Privacy and protection of PII

NIS2 Directive · 1 control

  • Art.28 Maintain accurate domain name registration data and answer lawful access requests within 72 hours
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • 27(1)(k) Art. 27(1)(k) Obtain the works council's consent to a staff arrangement: processing and protection of staff personal data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 5.34 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 135 it maps to, and the evidence behind each claim, over MCP and REST.