ISO/IEC 29134:2023 PDF
Information technology — Security techniques — Guidelines for privacy impact assessment
Information technology — Security techniques — Guidelines for privacy impact assessment
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 44
- Дата публикации:
- 8 мая 2023 г.
- Издание:
- ISO/IEC IS 29134 edition 2 version 1
- ICS:
- 35.030
This document gives guidelines for: a process on privacy impact assessments, and a structure and content of a PIA report. It is applicable to all types and sizes of organizations, including public companies, private companies, government entities and not-for-profit organizations. This document is relevant to those involved in designing or implementing projects, including the parties operating data processing systems and services that process PII.
Abstract
Overview
ISO/IEC 29134:2023 - "Information technology - Security techniques - Guidelines for privacy impact assessment" provides internationally recognized guidance for conducting Privacy Impact Assessments (PIAs). The standard describes a scalable, repeatable PIA process and the recommended structure and content of a PIA report, applicable to all types and sizes of organizations (public, private, government, and not‑for‑profit). It promotes privacy by design and supports accountability when processing personally identifiable information (PII).
Key technical topics and requirements
- PIA process lifecycle: preparing for a PIA, threshold/necessity analysis, planning, performing the PIA, and follow‑up (including reporting, publication and review).
- Preparation steps: setting up a PIA team, defining objectives, scope and resources, and stakeholder engagement.
- Information flows and use‑case analysis: mapping PII flows, identifying where and how personal data are processed.
- Privacy risk assessment: identifying risk sources, threats, likelihood, impacts, compliance analysis and risk evaluation.
- Risk treatment: defining, documenting and implementing privacy risk treatment plans and controls.
- PIA report content: scope, process under evaluation, risk criteria, stakeholder consultation, privacy requirements, risk assessment results, treatment plans, conclusions and a public summary.
- Scalability and context: guidance is adaptable to initiatives of varying scale and jurisdictional expectations.
- Supporting material: informative annexes provide scale criteria for impact/likelihood, generic threats, term clarifications and illustrative examples.
Practical applications and who uses it
- PII controllers and processors conducting or commissioning PIAs to meet regulatory, contractual or organizational privacy requirements.
- Project managers and system designers integrating privacy by design into new products, services or information systems.
- Privacy officers, compliance and risk teams assessing privacy risk and documenting mitigation measures.
- Suppliers and device manufacturers, especially those providing digitally connected devices, who must share privacy‑relevant design information or perform supplier PIAs.
- SMEs and public bodies seeking a scalable framework to evaluate and manage privacy risks across initiatives, programmes or cross‑organizational projects.
Related standards
- ISO/IEC 27001 (ISMS) and ISO/IEC 27002 - for information security controls that can support PIA risk treatment
- ISO/IEC 29151 - PII protection controls
- ISO/IEC 27000 and ISO Guide 73 - terminology and risk management vocabulary
ISO/IEC 29134:2023 is a practical, standards‑based reference for embedding privacy impact assessment into governance, design and operational processes to improve data protection and demonstrate accountability.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 29134:2023
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…
BS EN ISO/IEC 27017:2021
ОтменёнInformation technology. Security techniques. Code of practice for information security controls based on ISO/…
1 Scope This Recommendation International Standard gives guidelines for information security controls applicable to the provision and use of cloud services by providing: – additional implementation g…
ISO/IEC 29151:2026
ДействующийInformation security, cybersecurity and privacy protection — Controls, requirements, and guidance for persona…
Overview ISO/IEC 29151:2026 is a key international standard developed by ISO and IEC for information security, cybersecurity, and privacy protection. The standard specifically addresses controls, req…
BS EN ISO/IEC 27000:2020
ОтменёнInformation technology. Security techniques. Information security management systems. Overview and vocabulary
1 Scope This document provides the overview of information security management systems (ISMS). It also provides terms and definitions commonly used in the ISMS family of standards. This document is a…