ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.34: Privacy and protection of PII

The organization is to identify, and then satisfy, the requirements for preserving privacy and protecting personally identifiable information that arise from applicable laws, regulations and contracts. Purpose: comply with the legal, regulatory and contractual requirements concerning the security aspects of PII protection. Guidance: set a topic-specific policy covering privacy and the protection of PII and communicate it to relevant parties; develop and implement privacy and PII protection procedures and make them known to everyone involved in processing PII. Meeting these procedures and the relevant laws requires suitable roles, responsibilities and controls, usually best achieved by appointing someone such as a privacy officer who guides staff, service providers and others on their individual responsibilities and the procedures to follow. Responsibility for handling PII is assigned with regard to the relevant laws, and appropriate technical and organizational measures are put in place to protect it. Other information: many countries regulate how PII is gathered, processed, sent and erased, may impose duties on those who collect and share it, and may restrict transfers abroad; ISO/IEC 29100 gives a high-level framework, ISO/IEC 27701 covers privacy information management, ISO/IEC 27018 covers public cloud PII processors, and ISO/IEC 29134 gives guidance on privacy impact assessment for identifying and reducing privacy risks.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 151 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 39 controls

  • 6.1 General
  • 6.15.1 Compliance with legal and contractual requirements
  • 7.1 General
  • 7.2 Conditions for collection and processing
  • 7.2.1 Identify and document purpose
  • 7.2.2 Identify lawful basis
  • 7.2.3 Determine when and how consent is to be obtained
  • 7.2.4 Obtain and record consent
  • 7.2.5 Privacy impact assessment
  • 7.2.7 Joint PII controller
  • 7.3 Obligations to PII principals
  • 7.3.1 Determining and fulfilling obligations to PII principals
  • 7.3.10 Automated decision making
  • 7.3.2 Determining information for PII principals
  • 7.3.3 Providing information to PII principals
  • 7.3.4 Providing mechanism to modify or withdraw consent
  • 7.3.5 Providing mechanism to object to PII processing
  • 7.3.6 Access, correction and/or erasure
  • 7.3.7 PII controllers' obligations to inform third parties
  • 7.3.8 Providing copy of PII processed
  • 7.3.9 Handling requests
  • 7.4 Privacy by design and privacy by default
  • 7.4.1 Limit collection
  • 7.4.3 Accuracy and quality
  • 7.4.4 PII minimization objectives
  • 7.4.5 PII de-identification and deletion at the end of processing
  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 7.5.4 Records of PII disclosure to third parties
  • 8.1 General
  • 8.2 Conditions for collection and processing
  • 8.2.2 Organization’s purposes
  • 8.2.3 Marketing and advertising use
  • 8.3 Obligations to PII principals
  • 8.3.1 Obligations to PII principals
  • 8.5.1 Basis for PII transfer between jurisdictions
  • 8.5.3 Records of PII disclosure to third parties
  • 8.5.4 Notification of PII disclosure requests
  • 8.5.5 Legally binding PII disclosures
  • 8.5.7 Engagement of a subcontractor to process PII

NIST SP 800-53 Rev 5 · 18 controls

SOC 2 · 14 controls

  • SOC2-P1.1 P1.1 Privacy notice to data subjects
  • SOC2-P2.1 P2.1 Choice and consent
  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC2-P3.2 P3.2 Explicit consent before collecting information that requires it
  • SOC2-P4.1 P4.1 Limiting use to identified purposes
  • SOC2-P4.2 P4.2 Retaining personal information
  • SOC2-P5.2 P5.2 Correction of personal information
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent
  • SOC2-P6.2 P6.2 Record of authorised disclosures
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • SOC2-P7.1 P7.1 Quality of personal information
  • SOC2-P8.1 P8.1 Inquiries, complaints, disputes and compliance monitoring

ISO/IEC 42001:2023 · 10 controls

  • 6.1.4 AI system impact assessment
  • 8.4 AI system impact assessment
  • A.5 Assessing impacts of AI systems
  • A.5.2 AI system impact assessment process
  • A.5.4 Assessing AI system impact on individuals or groups of individuals
  • A.7 Data for AI systems
  • A.7.3 Acquisition of data
  • A.8 Information for interested parties of AI systems
  • A.9 Use of AI systems
  • A.9.3 Objectives for responsible use of AI system
  • CCM-DSP-01 Security and Privacy Policy and Procedures
  • CCM-DSP-08 Data Privacy by Design and Default
  • CCM-DSP-09 Data Protection Impact Assessment
  • CCM-DSP-11 Personal Data Access, Reversal, Rectification and Deletion
  • CCM-DSP-12 Limitation of Purpose in Personal Data Processing
  • CCM-DSP-18 Disclosure Notification

HIPAA Security Rule · 6 controls

APPI · 4 controls

  • APPI-A18 Restriction on Handling Beyond the Purpose of Use
  • APPI-A21 Notice or Public Announcement of the Purpose of Use
  • APPI-A23 Security Control Measures
  • APPI-A32 Matters Concerning Retained Personal Data to Be Made Accessible

CIS Controls v8 · 4 controls

  • CIS-3.10 Encrypt Sensitive Data in Transit
  • CIS-3.11 Encrypt Sensitive Data at Rest
  • CIS-3.13 Deploy a Data Loss Prevention Solution
  • CIS-3.7 Establish and Maintain a Data Classification Scheme

GDPR · 4 controls

PCI DSS 4.0 · 4 controls

  • 3.3.1.1 3.3.1.1 Full track data not retained after authorization
  • 3.2.1 3.2.1 Data retention and disposal minimise stored account data
  • 3.3.1 3.3.1 SAD not retained after authorization, even encrypted
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • ISM-1880 Reporting incidents involving customer data
  • ISM-2021 System owner data minimisation practices
  • ISM-2103 Consent for training on organisational data

C5 (Germany) · 3 controls

  • C5-INQ-03 Conditions for Access to or Disclosure of Data in Investigation Requests
  • C5-OPS-11 Logging and Monitoring - Metadata Management Concept
  • C5-PSS-12 Locations of Data Processing and Storage

ETSI EN 303 645 · 3 controls

  • Provision 5.8-2 Sensitive personal data in transit protected
  • Provision 6-1 Clear information on what personal data is processed, why, by whom and for how long
  • Provision 6-4 Personal data in telemetry limited to what the functionality needs

NIST SP 800-66 Rev 2 · 3 controls

  • B.6.1 B.6.1 Defining video system parameters: purpose, retention and image quality
  • B.6.13 B.6.13 Policies and procedures for system use
  • SEC07-BP02 Apply data protection controls based on data sensitivity
  • SEC07-BP03 Automate identification and classification
  • AUCDR-PS-1 Privacy Safeguard 1 - Open and transparent management of CDR data
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data
  • MYHR-CUD-1 Authorised collection, use and disclosure only
  • MYHR-CUD-3 Use limited to My Health Record purposes

DORA · 2 controls

  • DORA-Art.45 Information-sharing arrangements on cyber threat information and intelligence
  • DORA-Art.56 Data protection

NIST SP 800-161 Rev 1 · 2 controls

  • 41 s 41 No surveillance in toilets, change rooms, showers, parent or nursing rooms, prayer rooms, sick bays or first-aid rooms
  • CPS230-9 Management of the Full Range of Operational Risks
  • ASBv3-DP-1 Discover, classify, and label sensitive data

ISO 27001:2022 · 1 control

  • 5.34 Privacy and protection of personal identifiable information (PII)

ISO/IEC 38500:2024 · 1 control

  • 5.12 Viability and performance over time

MTCS (Singapore) · 1 control

  • 12.6 Data protection

NIS2 Directive · 1 control

  • Art.28 Maintain accurate domain name registration data and answer lawful access requests within 72 hours
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • s15 s 15 No surveillance in change rooms, toilets, showers or bathing facilities
  • 11.5.16.C.03 11.5.16.C.03 Privacy legislation compliance for medically permitted wearables

PTES · 1 control

  • PTES-4.1 Protect and, where required, avoid holding the organisation's sensitive data
  • 0153 0153 Informed consent to collect, use and disclose personal information for vetting
  • 9B s 9B No optical or listening device in workplace toilets, washrooms, change rooms or lactation rooms

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.34 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 151 it maps to, and the evidence behind each claim, over MCP and REST.