ISO 27001:2022 Annex A 5.34 Privacy and Protection of PII Explained

ISO 27001 Annex A 5.34 Privacy and protection of PII

In this guide you will learn how to implement ISO 27001 Annex A 5.34 Data Protection & PII and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

ISO 27001 Annex A 5.34 Privacy and Protection of PII is an ISO 27001 control that wants you to protect personally identifiable information (PII).

What is PII?

Personally identifiable information (PII) is any information that can be used to identify a specific individual. This can include things like a person’s name, address, phone number, email address or date of birth. PII can also include things like a person’s biometric data, such as their fingerprints or facial recognition data.

PII is considered sensitive data because it can be used to commit identity theft, fraud, or other crimes. It is important to protect PII from unauthorised access, use, disclosure, disruption, modification, or destruction.

There are often specific laws, such as the GDPR that relate to the protection of PII and these take precedence over this clause.

Consult with a GDPR or Data Protection professional.

Purpose & Definition

The purpose of ISO 27001 Annex A 5.34 Privacy and Protection of PII is to ensure you comply with legal, statutory, regulatory and contractual requirements related to the protection of personally identifiable information (PII) .

Organisations should have a clear understanding of their obligations when it comes to the protection of PII and make sure that they adhere to those requirements.

FREE ISO 27001 Annex A 5.34 Training Video

In this free training video you will learn How to implement ISO 27001 Privacy and Protection of PII (Annex A 5.34) and Pass Your Audit.

How to implement ISO 27001 Annex A 5.34

Have a topic specific policy on privacy and protection of PII

You are going to implement an ISO 27001 Information Classification and Handling Policy that includes and specifically addresses as part of it, the protection and handling of PII.

Implement Process and procedures for PII

Building on the ISO 27001 Information Classification and Handling Policy you will implement the processes and procedures to protect the preservation and privacy of PII.

Assign roles and responsibilities

Roles and responsibilities will be defined and assigned. Consideration will be given to appointing someone to be responsible such as a privacy officer who will provide that leadership and guidance to people on their responsibilities and the procedures to be followed.

Put in place technical and organisational measures

Appropriate measures for both the organisation and technology will be implemented to protect PII.

Ensure you cover different country requirements

There is a difference in the international approach to data protection and requirements on PII. These should be addressed based on where you are operating. This forms part of the ISO 27001 legal register and the requirements that we covered in ISO 27001 Annex A 5.31 Legal, regulatory, statutory and contractual requirements.

Use a data protection professional

The ISO 27001 standard is actually dabbling in other areas with this particular control. It is one isolated part of a bigger profession and requirement and as such for this and in more general terms we strongly recommend engaging the services of a data protection professional.

Stuart Barker - High Table - ISO27001 Director

Instant download of mandatory ISMS core policies and documentation. Verified by Lead Auditors and used by 5,000+ businesses worldwide to pass Stage 1 certification first time.

ISO 27001 Templates

ISO 27001 Templates - ISO 27001 Annex A 5.34 Privacy and Protection of PII Templates
ISO 27001 Templates

How to Audit ISO 27001 Annex A 5.34

Auditing ISO 27001 Annex A 5.34 requires a meticulous examination of how your organisation identifies, processes, and safeguards Personally Identifiable Information. As a Lead Auditor, I look for technical evidence that privacy is embedded into the system architecture, not just the policy. Use this 10 step technical roadmap to ensure your PII controls withstand the scrutiny of a rigorous certification audit.

1. Audit the Privacy and PII Protection Policy

Audit the topic-specific policy for privacy and PII protection to confirm it defines the organisational approach to managing personal data: result: establishes the legal and procedural baseline for both ISO 27001 and statutory data protection compliance.

  • Verify that the policy explicitly references relevant legislation, such as the UK GDPR and Data Protection Act 2018.
  • Check for clear definitions of PII and sensitive personal data within the organisational context.
  • Confirm the policy is reviewed annually and carries executive-level sign-off.

2. Inspect the Asset Register for PII Mapping

Inspect the organisational Asset Register to ensure all PII data sets and processing systems are identified and classified: result: provides the visibility required to apply granular security controls and determine data ownership.

  • Review entries for employee data, customer databases, and marketing lists.
  • Verify that the classification levels, such as “Highly Confidential,” align with the sensitivity of the PII.
  • Confirm that an “Asset Owner” or Data Custodian is assigned to every PII category.

3. Review Data Flow Documentation and Processing Maps

Review the technical data flow mapping to visualise how PII enters, moves through, and leaves the organisation: result: identifies potential leakage points and verifies the lawfulness of cross-border data transfers.

  • Inspect the maps for third-party processing points and external storage locations.
  • Verify that international transfers are supported by appropriate legal mechanisms, such as Standard Contractual Clauses or the UK Addendum.
  • Check that data flows align with the purposes documented in the privacy notice.

Check Your Work?

You built it yourself. Maybe with AI. But will it pass the audit?

Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Stuart Barker - High Table - ISO27001 Director

ISO 27001 Annex A 5.34 FAQ

Is a Data Protection Impact Assessment (DPIA) mandatory for Annex A 5.34?

Yes, a DPIA is mandatory under Annex A 5.34 for any processing activity deemed high-risk to individual privacy rights. This technical assessment identifies potential leakage points before a project begins; failing to conduct a DPIA can result in regulatory fines from the ICO of up to £17.5 million or 4% of global annual turnover.

How does ISO 27001 Annex A 5.34 align with GDPR?

Annex A 5.34 serves as the technical bridge to GDPR compliance by providing the organisational framework for “Privacy by Design.” While GDPR sets the legal requirements, ISO 27001 5.34 mandates the implementation of specific controls to meet those requirements, such as data flow mapping, retention schedules, and Multi-Factor Authentication (MFA).

What are the PII breach notification rules for ISO 27001?

Organisations must report a PII breach within a strict 72-hour window to the relevant supervisory authority once they become aware of it. Statistics indicate that organisations with a formalised incident response plan, as required by Annex A 5.34, reduce the financial impact of a breach by approximately 35% through faster containment.

Can we use cloud storage for PII under ISO 27001?

Yes, cloud storage is permitted for PII provided that the provider meets the high security thresholds mandated by Annex A 5.34 and the UK Data (Use and Access) Act 2025. You must verify end-to-end encryption and that your Data Processing Agreement (DPA) includes a “Right to Audit” clause.

Further Reading

ISO 27001 Controls and Attribute values

Control typeInformation security propertiesCybersecurity conceptsOperational capabilitiesSecurity domains
PreventiveAvailability Confidentiality IntegrityIdentify ProtectLegal and compliance Information protectionProtection

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top