ISO/IEC 27001:2022 Annex A · Control 5.34
Privacy and Protection of Personally Identifiable Information (PII): A Practical Implementation Guide
Govern personal information according to applicable privacy duties across its entire lifecycle.
This control concerns identifying and meeting requirements for privacy and protection of personally identifiable information.
What should the control achieve?
- PII processing and responsibilities are known.
- Applicable privacy requirements are translated into controls.
- Protection reflects sensitivity and individual risk.
- Rights, incidents, suppliers and retention are managed.
Step-by-step implementation
Map PII processing
Record purposes, categories, individuals, systems, recipients, locations and retention.
Determine requirements
Identify lawful basis, notices, consent, contracts and jurisdiction obligations.
Apply privacy principles
Minimize collection, restrict use, ensure accuracy and limit retention.
Protect by risk
Use access control, encryption, masking, logging and secure transfer.
Operate individual rights
Verify identity and meet access, correction, deletion or objection processes.
Manage incidents and suppliers
Coordinate breach assessment, notification and processor oversight.
What this could look like in practice
A recruitment platform records candidate-data flows and retention. Access is role-based, exports are logged and inactive candidates are deleted on schedule. Privacy requests use identity verification and tracked deadlines.
| Activity | Practical implementation | Evidence |
|---|---|---|
| New processing | Privacy impact screening precedes launch. | Assessment |
| Rights request | Identity is verified and systems searched. | Case record |
| Retention | Automated deletion follows documented trigger. | Deletion log |
| Breach | Privacy impact and notification duties are assessed. | Decision record |
Implementation evidence
- PII processing register
- Privacy assessments
- Notices and lawful-basis records
- Data-subject request logs
- Access and encryption controls
- Processor agreements
- Retention evidence
- Breach assessments
Useful metrics
- Rights requests met on time
- PII repositories with owners
- Overdue privacy actions
- Retention deletions completed
Common mistakes
- Treating all personal data identically.
- Collecting data without clear purpose.
- Using consent when it is not appropriate.
- Keeping PII indefinitely.
- Assuming a processor owns compliance.
Questions an auditor may ask
- Where is PII processed and why?
- How are privacy requirements identified?
- Show a completed rights request.
- How is retention and breach assessment handled?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.