Overview
EN ISO/IEC 29101:2021 (ISO/IEC 29101:2018) defines a privacy architecture framework for information and communication technology (ICT) systems that store and process personally identifiable information (PII). The standard specifies PII-related concerns, lists components for implementing privacy-aware systems, and provides multiple architectural views to contextualize those components. It is intended for organizations involved in specifying, procuring, designing, testing, operating and maintaining ICT systems - especially systems that interact directly with PII principals.
Key topics
- Scope and purpose: a high-level architecture to help implement privacy controls consistently across ICT systems that process PII.
- PII lifecycle: explicit consideration of PII phases - collection, transfer, use, storage, disposal - so privacy can be addressed at each stage.
- Actors and roles: definitions and views for PII principals, controllers and processors, and their ICT systems.
- Privacy concerns and requirements: alignment with the privacy principles in ISO/IEC 29100 and guidance on deriving privacy safeguarding requirements.
- Architectural views:
- Component view - layers such as privacy settings, identity & access management, and PII layer.
- Actor view - ICT systems for principals, controllers and processors.
- Interaction view - how components and actors exchange PII and enforce controls.
- Privacy enhancing technologies (PETs): how PETs can be used as privacy controls and integrated into architectures.
- Informative examples: annexes include examples such as PII aggregation with secure computation and pseudonymous identity/access-management systems.
Applications
EN ISO/IEC 29101 is practical for:
- Designing privacy-by-architecture solutions and embedding privacy controls in system architectures.
- Specifying requirements for procurement contracts, RFPs and vendor assessments for systems that process PII.
- Guiding software architects, system integrators and security teams on layering identity, access and PII handling.
- Supporting privacy impact assessments, testing and operational controls by mapping technical controls to PII lifecycle stages.
- Informing choices of privacy enhancing technologies (pseudonymization, secure computation, selective disclosure) as part of an architecture.
Who should use this standard
- IT architects, security architects and system designers
- Data protection officers and privacy engineers
- Procurement teams and technical evaluators
- Developers, testers and operations teams managing PII-processing systems
Related standards
- ISO/IEC 29100 - Privacy framework (privacy principles referenced throughout 29101)
- ISO/IEC/IEEE 42010 - Systems and software engineering - Architecture description
EN ISO/IEC 29101 helps organizations translate privacy principles into concrete architecture components and views, making it a practical reference for building, procuring and operating privacy-aware ICT systems that process PII.