Skip to content
compliancebase
ISO 27001A.5 — Privacy and protection of PII

A.5.34

Privacy and protection of PII

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Protect privacy and personally identifiable information as required by applicable law and contractual obligations.

Points of focus

  • Define scope and requirements for privacy and protection of pii
  • Assign ownership and operating cadence
  • Integrate with risk treatment and SoA status
  • Retain dated records proving operation

Implementation notes

Connect ISMS controls to privacy obligations (notices, retention, DSRs). Certification does not equal GDPR compliance — coordinate with counsel. Tie the SoA implementation summary to the systems of record engineers already use, and keep dated samples ready for Stage 2 sampling.

Audit tip: Present the SoA line for A.5.34, the current procedure, and one recent dated operating sample with a named owner.

Evidence auditors typically request:

  • Approved information security policy set with version and owner
  • Statement of Applicability entry with applicability rationale
  • Management review minutes referencing the control theme
  • Ticket or register samples showing the process operated

Common gaps

  • SoA marks privacy and protection of pii applicable without dated operating samples
  • Procedure exists but interviews describe a different tribal process
  • Owner unclear or last review older than the stated cadence

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.34This control
GDPRArticle 32, Article 6Related GDPR articles for personal-data security or processor themes — not a compliance claim.
HIPAA164.308(a)(1)Related HIPAA Security Rule citations when PHI is in scope — SoA does not replace BAAs.

Primary sources

Frequently Asked Questions

Applicability depends on risk and scope. Many cloud-native SoAs still include organizational and technological controls; physical themes may be partially inherited from providers with documented shared responsibility.

Applicability decision, brief implementation summary, and justification if excluded. Vague 'N/A — cloud' without rationale is a common Stage 1 finding.

Name the owner, the system of record, and the cadence. Auditors sample reality — tickets, configs, and interviews — not synonym-rewritten ISO text.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above