Overview
EN ISO/IEC 29151:2022 (identical to ISO/IEC 29151:2017) is a code of practice for protecting personally identifiable information (PII). It establishes control objectives, controls and implementation guidelines to meet requirements identified by a risk and impact assessment for PII protection. The standard builds on ISO/IEC 27002 and is intended for all types and sizes of organisations acting as PII controllers (as defined in ISO/IEC 29100), including private companies, government bodies and not‑for‑profit organisations. EN ISO/IEC 29151:2022 has been adopted by CEN and published as a European Standard.
Key topics and technical requirements
The standard provides structured guidance across information security domains with PII‑specific controls and practical recommendations. Key topics include:
- Governance and policies: management direction for PII protection, policy creation and organisation‑specific guidelines.
- Risk‑based control selection: choose and tailor controls based on PII risk and impact assessments.
- Human resources: personnel screening, awareness and termination/change processes impacting PII.
- Asset and media handling: classification, inventory and secure handling of PII assets and media.
- Access control and authentication: user access management and system/application access specifically for PII.
- Cryptographic controls: guidance on protecting stored and transmitted PII.
- Operations and logging: operational procedures, malware protection, backup, logging and monitoring relevant to PII.
- Supplier and third‑party management: contract, delivery and security controls for suppliers processing PII.
- Incident management and continuity: detection, response and recovery for information security incidents affecting PII.
- Compliance and audit: meeting legal, contractual and regulatory requirements for PII protection.
Annex A (Extended control set) details privacy‑centric controls such as consent and choice, purpose specification, collection limitation, data minimization, retention and disclosure limits, accuracy, transparency and PII subject access and accountability.
Practical applications and who uses it
EN ISO/IEC 29151:2022 is practical for organizations that need to:
- Implement or improve PII protection as part of an information security management system (ISMS).
- Map security controls to privacy requirements when processing personal data.
- Demonstrate due care and a risk‑based approach to stakeholders, auditors and regulators.
Typical users:
- Information security and privacy officers
- Compliance and legal teams aligning controls with data protection laws
- IT architects and operations teams implementing technical controls (access, encryption, logging)
- Procurement and vendor managers governing third‑party PII handling
Related standards
- ISO/IEC 27002 (information security controls) - source guidance referenced in this standard
- ISO/IEC 29100 (privacy framework) - defines PII controller/processor roles used by 29151
EN ISO/IEC 29151:2022 is a practical, standards‑based reference for integrating privacy controls into an organisation’s security program and for operationalising PII protection in a risk‑driven way.