Overview
EN 17926:2023 provides European refinements to ISO/IEC 27701 for a Privacy Information Management System (PIMS). Published by CEN, the standard adapts the generic ISO/IEC 27701 requirements and controls to the European legal context-most notably to support implementation under the EU GDPR (Regulation 2016/679). EN 17926 is applicable to all types and sizes of organisations acting as PII controllers and/or PII processors and is intended for use by organisations, certification bodies, accreditation bodies and regulators.
Key topics and requirements
- Scope and applicability: Defines how to determine the PIMS scope, including interfaces and dependencies between internal and external PII processing activities.
- Refinements to ISO/IEC 27701 controls: Specifies which controls from ISO/IEC 27001 Annex A, ISO/IEC 27701 Annex A (controllers) and Annex B (processors) apply and when they are mandatory in a European/GDPR context.
- Statement of Applicability (SoA): Requires an SoA that lists necessary controls, justification for inclusion/exclusion, and implementation status - Annexes A/B/C cannot be excluded if in-scope.
- Data Protection Officer (DPO): Clarifies DPO appointment criteria and expectations - sufficient resources, reporting to top management, involved in PII protection issues, publicly available contact details, and independence from instructions.
- Risk assessment and treatment: Controls must be assessed for both information security and privacy risks to PII principals; applicability checks must reference Annex A/B/C.
- Certification models: Provides a basis for certification criteria under ISO/IEC 17065 for product/process/service PII processing and combination models with ISO/IEC 17021 for management system certification (see informative Annex D).
- GDPR relationship: Informative mapping to GDPR obligations and use of standard content for data protection certification mechanisms (Annex E).
Practical applications
Who uses EN 17926 and why:
- Organisations (public/private/not-for-profit): to implement a PIMS aligned with GDPR and demonstrate compliance through documented controls and SoA.
- Certification bodies: to develop certification schemes that assess PIMS conformity and processing operations (ISO/IEC 17065 and ISO/IEC 17021 models).
- Accreditation bodies and regulators: to establish certification mechanisms and criteria for data protection certification (GDPR Article 42).
- Service providers and vendors: to design products, services, or processes that process PII in ways that meet European refinements and support customer assurance.
Related standards
EN 17926 is essential for organisations seeking a GDPR-aligned privacy management framework and for bodies creating credible, comparable privacy certification schemes in Europe.