ISO/IEC 29134:2023
Information technology — Security techniques — Guidelines for privacy impact assessment
Information technology — Security techniques — Guidelines for privacy impact assessment
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 44
- Дата публикации:
- 8 мая 2023 г.
- Издание:
- ISO/IEC IS 29134 edition 2 version 1
- ICS:
- 35.030
This document gives guidelines for: a process on privacy impact assessments, and a structure and content of a PIA report. It is applicable to all types and sizes of organizations, including public companies, private companies, government entities and not-for-profit organizations. This document is relevant to those involved in designing or implementing projects, including the parties operating data processing systems and services that process PII.
Abstract
Overview
ISO/IEC 29134:2023 - "Information technology - Security techniques - Guidelines for privacy impact assessment" provides internationally recognized guidance for conducting Privacy Impact Assessments (PIAs). The standard describes a scalable, repeatable PIA process and the recommended structure and content of a PIA report, applicable to all types and sizes of organizations (public, private, government, and not‑for‑profit). It promotes privacy by design and supports accountability when processing personally identifiable information (PII).
Key technical topics and requirements
- PIA process lifecycle: preparing for a PIA, threshold/necessity analysis, planning, performing the PIA, and follow‑up (including reporting, publication and review).
- Preparation steps: setting up a PIA team, defining objectives, scope and resources, and stakeholder engagement.
- Information flows and use‑case analysis: mapping PII flows, identifying where and how personal data are processed.
- Privacy risk assessment: identifying risk sources, threats, likelihood, impacts, compliance analysis and risk evaluation.
- Risk treatment: defining, documenting and implementing privacy risk treatment plans and controls.
- PIA report content: scope, process under evaluation, risk criteria, stakeholder consultation, privacy requirements, risk assessment results, treatment plans, conclusions and a public summary.
- Scalability and context: guidance is adaptable to initiatives of varying scale and jurisdictional expectations.
- Supporting material: informative annexes provide scale criteria for impact/likelihood, generic threats, term clarifications and illustrative examples.
Practical applications and who uses it
- PII controllers and processors conducting or commissioning PIAs to meet regulatory, contractual or organizational privacy requirements.
- Project managers and system designers integrating privacy by design into new products, services or information systems.
- Privacy officers, compliance and risk teams assessing privacy risk and documenting mitigation measures.
- Suppliers and device manufacturers, especially those providing digitally connected devices, who must share privacy‑relevant design information or perform supplier PIAs.
- SMEs and public bodies seeking a scalable framework to evaluate and manage privacy risks across initiatives, programmes or cross‑organizational projects.
Related standards
- ISO/IEC 27001 (ISMS) and ISO/IEC 27002 - for information security controls that can support PIA risk treatment
- ISO/IEC 29151 - PII protection controls
- ISO/IEC 27000 and ISO Guide 73 - terminology and risk management vocabulary
ISO/IEC 29134:2023 is a practical, standards‑based reference for embedding privacy impact assessment into governance, design and operational processes to improve data protection and demonstrate accountability.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 29134:2023
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…