In this guide you will learn how to implement ISO 27001 Annex A 5.34 Data Protection & PII and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 5.34 Privacy and Protection of PII is an ISO 27001 control that wants you to protect personally identifiable information (PII).
Table of contents
What is PII?
Personally identifiable information (PII) is any information that can be used to identify a specific individual. This can include things like a person’s name, address, phone number, email address or date of birth. PII can also include things like a person’s biometric data, such as their fingerprints or facial recognition data.
PII is considered sensitive data because it can be used to commit identity theft, fraud, or other crimes. It is important to protect PII from unauthorised access, use, disclosure, disruption, modification, or destruction.
There are often specific laws, such as the GDPR that relate to the protection of PII and these take precedence over this clause.
Consult with a GDPR or Data Protection professional.
Purpose & Definition
The purpose of ISO 27001 Annex A 5.34 Privacy and Protection of PII is to ensure you comply with legal, statutory, regulatory and contractual requirements related to the protection of personally identifiable information (PII) .
Organisations should have a clear understanding of their obligations when it comes to the protection of PII and make sure that they adhere to those requirements.
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 5.34 Training Video
In this free training video you will learn How to implement ISO 27001 Privacy and Protection of PII (Annex A 5.34) and Pass Your Audit.
How to implement ISO 27001 Annex A 5.34
Have a topic specific policy on privacy and protection of PII
You are going to implement an ISO 27001 Information Classification and Handling Policy that includes and specifically addresses as part of it, the protection and handling of PII.
Implement Process and procedures for PII
Building on the ISO 27001 Information Classification and Handling Policy you will implement the processes and procedures to protect the preservation and privacy of PII.
Assign roles and responsibilities
Roles and responsibilities will be defined and assigned. Consideration will be given to appointing someone to be responsible such as a privacy officer who will provide that leadership and guidance to people on their responsibilities and the procedures to be followed.
Put in place technical and organisational measures
Appropriate measures for both the organisation and technology will be implemented to protect PII.
Ensure you cover different country requirements
There is a difference in the international approach to data protection and requirements on PII. These should be addressed based on where you are operating. This forms part of the ISO 27001 legal register and the requirements that we covered in ISO 27001 Annex A 5.31 Legal, regulatory, statutory and contractual requirements.
Use a data protection professional
The ISO 27001 standard is actually dabbling in other areas with this particular control. It is one isolated part of a bigger profession and requirement and as such for this and in more general terms we strongly recommend engaging the services of a data protection professional.
ISO 27001 Starter Kit
Instant download of mandatory ISMS core policies and documentation. Verified by Lead Auditors and used by 5,000+ businesses worldwide to pass Stage 1 certification first time.
ISO 27001 Templates

How to Audit ISO 27001 Annex A 5.34
Auditing ISO 27001 Annex A 5.34 requires a meticulous examination of how your organisation identifies, processes, and safeguards Personally Identifiable Information. As a Lead Auditor, I look for technical evidence that privacy is embedded into the system architecture, not just the policy. Use this 10 step technical roadmap to ensure your PII controls withstand the scrutiny of a rigorous certification audit.
1. Audit the Privacy and PII Protection Policy
Audit the topic-specific policy for privacy and PII protection to confirm it defines the organisational approach to managing personal data: result: establishes the legal and procedural baseline for both ISO 27001 and statutory data protection compliance.
- Verify that the policy explicitly references relevant legislation, such as the UK GDPR and Data Protection Act 2018.
- Check for clear definitions of PII and sensitive personal data within the organisational context.
- Confirm the policy is reviewed annually and carries executive-level sign-off.
2. Inspect the Asset Register for PII Mapping
Inspect the organisational Asset Register to ensure all PII data sets and processing systems are identified and classified: result: provides the visibility required to apply granular security controls and determine data ownership.
- Review entries for employee data, customer databases, and marketing lists.
- Verify that the classification levels, such as “Highly Confidential,” align with the sensitivity of the PII.
- Confirm that an “Asset Owner” or Data Custodian is assigned to every PII category.
3. Review Data Flow Documentation and Processing Maps
Review the technical data flow mapping to visualise how PII enters, moves through, and leaves the organisation: result: identifies potential leakage points and verifies the lawfulness of cross-border data transfers.
- Inspect the maps for third-party processing points and external storage locations.
- Verify that international transfers are supported by appropriate legal mechanisms, such as Standard Contractual Clauses or the UK Addendum.
- Check that data flows align with the purposes documented in the privacy notice.
Check Your Work?
You built it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Related ISO 27001 Controls
ISO 27001 Annex A 5.34 FAQ
Yes, a DPIA is mandatory under Annex A 5.34 for any processing activity deemed high-risk to individual privacy rights. This technical assessment identifies potential leakage points before a project begins; failing to conduct a DPIA can result in regulatory fines from the ICO of up to £17.5 million or 4% of global annual turnover.
Annex A 5.34 serves as the technical bridge to GDPR compliance by providing the organisational framework for “Privacy by Design.” While GDPR sets the legal requirements, ISO 27001 5.34 mandates the implementation of specific controls to meet those requirements, such as data flow mapping, retention schedules, and Multi-Factor Authentication (MFA).
Organisations must report a PII breach within a strict 72-hour window to the relevant supervisory authority once they become aware of it. Statistics indicate that organisations with a formalised incident response plan, as required by Annex A 5.34, reduce the financial impact of a breach by approximately 35% through faster containment.
Yes, cloud storage is permitted for PII provided that the provider meets the high security thresholds mandated by Annex A 5.34 and the UK Data (Use and Access) Act 2025. You must verify end-to-end encryption and that your Data Processing Agreement (DPA) includes a “Right to Audit” clause.
Further Reading
- ISO 27001 Privacy and Personally Identifiable Information (PII): Your Complete FAQ Guide
- ISO 27001 Data Protection Policy Template
ISO 27001 Controls and Attribute values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Availability Confidentiality Integrity | Identify Protect | Legal and compliance Information protection | Protection |
