Overview
ISO/IEC 29151:2017 - "Information technology - Security techniques - Code of practice for personally identifiable information protection" - provides a practical code of practice for protecting personally identifiable information (PII). It establishes control objectives, specific controls, and implementation guidelines to address risks and impacts identified through a risk and impact assessment. Built on the guidance of ISO/IEC 27002, ISO/IEC 29151 adapts information security controls to the special requirements of PII processing and is applicable to all types and sizes of organizations acting as PII controllers (public, private, government and not-for-profit).
Key topics and technical requirements
ISO/IEC 29151 organizes guidance in a structure that mirrors ISO/IEC 27002 and covers core information security domains (clauses 5–18), including:
- Information security policies and management direction
- Organization of information security, mobile devices and teleworking
- Human resource security (prior to, during, and after employment)
- Asset management, classification and media handling
- Access control (user management, system and application access)
- Cryptographic controls
- Physical and environmental security
- Operations security (backup, malware protection, logging, vulnerability management)
- Communications security and information transfer
- System acquisition, development and maintenance
- Supplier relationships and service delivery management
- Incident management, business continuity and compliance
The standard includes a normative Annex A: an extended control set specific to PII protection. These PII controls are aligned with ISO/IEC 29100 privacy principles and cover 12 categories such as:
- Consent and choice
- Purpose legitimacy and specification
- Collection limitation and data minimization
- Use, retention and disclosure limitation
- Accuracy, openness/transparency and notice
- Individual participation/access, accountability, and privacy compliance
Controls are selected and tailored based on an organization’s information security risk environment and privacy risk assessments.
Practical applications - who uses ISO/IEC 29151
ISO/IEC 29151 is used by organizations that collect, store or process personal data and need to:
- Strengthen privacy-by-design and PII protection practices
- Align information security controls with privacy requirements
- Develop or refine policies, procedures and technical safeguards for PII
- Demonstrate due diligence and privacy compliance to stakeholders and regulators
Typical users include corporate security and privacy teams, IT managers, compliance officers, auditors, and third-party suppliers supporting PII controllers.
Related standards
ISO/IEC 29151 bridges information security and privacy practice by adapting ISO/IEC 27002 controls for PII protection, making it a practical, risk-based code of practice for protecting personal data.