ISO 27001 Annex A 5.34 Privacy and Protection of PII Explained

Stuart Barker - High Table - ISO27001 Director

ISO 27001 Privacy and Protection of PII

ISO 27001 Annex A 5.34 Privacy and Protection of PII is an ISO 27001 control that wants you to protect personally identifiable information (PII).

It requires you to identify and meet any requirements including those laid out in law, contracts and regulations.

Key Takeaways

ISO 27001 Annex A 5.34 requires organizations to identify and protect Personally Identifiable Information (PII) in accordance with applicable laws, regulations, and contracts. It acts as the bridge between your information security management system (ISMS) and privacy frameworks like GDPR, ensuring that personal data is not just “secure” but also handled legally.

What is PII?

Personally identifiable information (PII) is any information that can be used to identify a specific individual. This can include things like a person’s name, address, phone number, email address or date of birth. PII can also include things like a person’s biometric data, such as their fingerprints or facial recognition data.

PII is considered sensitive data because it can be used to commit identity theft, fraud, or other crimes. It is important to protect PII from unauthorised access, use, disclosure, disruption, modification, or destruction.

There are often specific laws, such as the GDPR that relate to the protection of PII and these take precedence over this clause.

Consult with a GDPR or Data Protection professional.

Purpose

The purpose of ISO 27001 Annex A 5.34 Privacy and Protection of PII is to ensure you comply with legal, statutory, regulatory and contractual requirements related to the protection of personally identifiable information (PII) .

Organisations should have a clear understanding of their obligations when it comes to the protection of PII and make sure that they adhere to those requirements.

Definition

The ISO 27001 standard defines ISO 27001 Annex A 5.34 as:

The organisation should identify and meet the requirements regarding the preservation of privacy and protection of PII according to applicable laws and regulations and contractual requirements.

ISO 27001:2022 Annex A 5.34 Privacy and Protection of PII

Explanation

ISO 27001 Annex A 5.34 Privacy and Protection of PII is a security control that mandates the identification and fulfilment of legal data protection requirements. By establishing a formal PII register and specific technical safeguards, organisations achieve the business benefit of regulatory compliance and reduced litigation risk.

Requirement

  • Legal Register: You must clearly identify which privacy laws apply to you (e.g., GDPR in Europe, CCPA in California) and list them in your legal register.
  • Topic-Specific Policy: Create a dedicated policy for “Privacy and Protection of PII.” This should define how you classify, handle, and protect personal data specifically, separate from general company data.
  • Role Assignment: Appoint a responsible person, such as a Data Protection Officer (DPO) or Privacy Officer, to provide leadership.
  • Technical Measures: Implement specific controls to protect PII, such as encryption, access control, and data masking.

Audit Focus

Auditors will look for evidence that you understand why you are holding data. They will check your PII Register (or Record of Processing Activities) to see if you have defined a “Lawful Basis” for every type of personal data you store, whether it’s employee payroll, customer emails, or CCTV footage.

Practical Application: This control acknowledges that ISO 27001 is not a privacy standard by itself. It requires you to “consult with a professional” and potentially integrate with ISO 27701 (the privacy extension) if you process significant amounts of personal data.

FREE Training Video

In this free training video you will learn How to implement ISO 27001 Privacy and Protection of PII (Annex A 5.34) and Pass Your Audit.

Have a topic specific policy on privacy and protection of PII

You are going to implement an ISO 27001 Information Classification and Handling Policy that includes and specifically addresses as part of it, the protection and handling of PII.

Implement Process and procedures for PII

Building on the ISO 27001 Information Classification and Handling Policy you will implement the processes and procedures to protect the preservation and privacy of PII.

Assign roles and responsibilities

Roles and responsibilities will be defined and assigned. Consideration will be given to appointing someone to be responsible such as a privacy officer who will provide that leadership and guidance to people on their responsibilities and the procedures to be followed.

Put in place technical and organisational measures

Appropriate measures for both the organisation and technology will be implemented to protect PII.

Ensure you cover different country requirements

There is a difference in the international approach to data protection and requirements on PII. These should be addressed based on where you are operating. This forms part of the ISO 27001 legal register and the requirements that we covered in ISO 27001 Annex A 5.31 Legal, regulatory, statutory and contractual requirements.

Use a data protection professional

The ISO 27001 standard is actually dabbling in other areas with this particular control. It is one isolated part of a bigger profession and requirement and as such for this and in more general terms we strongly recommend engaging the services of a data protection professional.

CEO at High Table: The Compliance Agency

How to implement It

Implementing ISO 27001 Annex A 5.34 ensures your organisation meets the rigorous legal and regulatory requirements for safeguarding Personally Identifiable Information (PII). As an ISO 27001 Lead Auditor, I look for a technical framework that balances statutory obligations, such as the UK GDPR, with robust security controls. Follow these ten technical steps to formalise your privacy framework and ensure PII remains protected throughout its entire lifecycle.

1. Formalise a Topic-Specific Policy on Privacy and PII Protection

Formalise a mandatory policy that defines the organisation’s approach to managing and protecting PII: result: establishes the legal and procedural baseline for both ISO 27001 compliance and data protection legislation.

  • Identify the specific legal, regulatory, and contractual requirements relevant to your jurisdiction.
  • Define clear roles and responsibilities, including the appointment of a Data Protection Officer (DPO) if required.
  • Document the consequences of policy violations to ensure staff accountability.

2. Provision PII Entities into the Organisational Asset Register

Provision the Asset Register to include specific entries for all PII data sets and information systems: result: provides the visibility required to apply granular security controls and track data ownership.

  • Identify the “Data Controller” and “Data Processor” status for every PII asset.
  • Record the location of PII, whether residing in cloud repositories, on-premise servers, or physical archives.
  • Link PII assets to your broader ISMS risk assessment process.

3. Implement Comprehensive Data Flow Mapping

Implement technical data flow mapping to visualise how PII enters, moves through, and leaves the organisation: result: identifies potential leakage points and ensures cross-border transfers are legally authorised.

  • Document the purpose of processing for every data flow identified.
  • Identify third-party recipients and the technical methods used for data transmission.
  • Verify that data retention periods are applied to each stage of the data flow.

Publish clear, external-facing privacy notices that inform data subjects about how their PII is utilised: result: satisfies the statutory “right to be informed” and ensures processing is lawful and transparent.

  • Ensure notices are written in plain English and are easily accessible at the point of data collection.
  • Implement granular consent mechanisms that allow users to opt-in to specific processing activities.
  • Establish a process to update notices whenever processing activities change.

5. Deploy Encryption and Pseudonymisation Technologies

Deploy technical obfuscation measures, such as AES-256 encryption and pseudonymisation, to protect PII at rest and in transit: result: mitigates the impact of data breaches by rendering intercepted data unintelligible.

  • Enforce full-disk encryption on all mobile devices and laptops handling PII.
  • Utilise pseudonymisation for testing and development environments to reduce the risk of accidental exposure.
  • Manage cryptographic keys securely using a formalised Key Management Policy.

6. Restrict Access via Role-Based Identity and Access Management (IAM)

Restrict access to PII repositories using strict IAM roles and the principle of least privilege: result: ensures that only authorised personnel with a legitimate business need can interact with sensitive data.

  • Mandate Multi-Factor Authentication (MFA) for all administrative and remote access to PII.
  • Perform quarterly access reviews to revoke permissions for users who have changed roles or left the organisation.
  • Implement automated logging of all access attempts to PII data sets.

7. Establish Data Subject Access Request (DSAR) Procedures

Establish a formalised workflow for managing and responding to Data Subject Access Requests: result: ensures the organisation can meet the 30-day statutory response deadline and respect individual privacy rights.

  • Create a secure portal or dedicated email address for receiving DSARs.
  • Train specific staff members on the technical extraction and redaction of data.
  • Maintain a log of all requests and the organisational response to provide audit evidence.

8. Conduct Data Protection Impact Assessments (DPIA)

Conduct a DPIA for any new technical project or change in processing that involves high-risk PII: result: identifies and mitigates privacy risks before processing begins, supporting the “Privacy by Design” principle.

  • Utilise a standardised DPIA template to ensure consistency in risk identification.
  • Involve the DPO or legal lead early in the project lifecycle.
  • Document the technical and organisational measures implemented to reduce identified risks.

9. Validate Third-Party Data Processing Agreements (DPA)

Validate that all third-party suppliers handling PII have signed a formal Data Processing Agreement: result: ensures that suppliers are contractually obligated to provide the same level of protection as your organisation.

  • Include “Right to Audit” clauses in all supplier contracts.
  • Review the Rules of Engagement (ROE) for third parties to ensure they understand their PII protection obligations.
  • Perform due diligence on the supplier’s security certifications, such as ISO 27001 or SOC 2.

10. Audit PII Handling and Incident Response Logs

Audit the effectiveness of PII controls through regular internal reviews and monitoring of security logs: result: provides the continuous assurance required for certification and demonstrates regulatory compliance.

  • Test the incident response plan specifically for PII breach scenarios, including mandatory 72-hour notification windows.
  • Review Data Loss Prevention (DLP) logs to identify attempted unauthorised transfers.
  • Document all audit findings in the Corrective Action Log to drive continuous improvement.

ISO 27001 Templates

ISO 27001 Templates - ISO 27001 Annex A 5.34 Privacy and Protection of PII Templates
ISO 27001 Templates

PII Register Example

Data Category (PII)Data Controller/OwnerLawful Basis (UK GDPR)Technical Retention PeriodISO 27001:2022 Mapping
Employee PayrollHR ManagerContractual Necessity7 Years (Tax Law).5.34 (PII Protection)
Customer EmailSales LeadConsent (Marketing)Until Unsubscribed/Withdrawal.5.34 (PII Protection)
CCTV FootageFacilities ManagerLegitimate Interest30 Days.8.10 (Information Deletion)
Medical RecordHealth and Safety OfficerLegal Obligation40 Years.5.34 (PII Protection)

How to Audit It

Auditing ISO 27001 Annex A 5.34 requires a meticulous examination of how your organisation identifies, processes, and safeguards Personally Identifiable Information. As a Lead Auditor, I look for technical evidence that privacy is embedded into the system architecture, not just the policy. Use this 10 step technical roadmap to ensure your PII controls withstand the scrutiny of a rigorous certification audit.

1. Audit the Privacy and PII Protection Policy

Audit the topic-specific policy for privacy and PII protection to confirm it defines the organisational approach to managing personal data: result: establishes the legal and procedural baseline for both ISO 27001 and statutory data protection compliance.

  • Verify that the policy explicitly references relevant legislation, such as the UK GDPR and Data Protection Act 2018.
  • Check for clear definitions of PII and sensitive personal data within the organisational context.
  • Confirm the policy is reviewed annually and carries executive-level sign-off.

2. Inspect the Asset Register for PII Mapping

Inspect the organisational Asset Register to ensure all PII data sets and processing systems are identified and classified: result: provides the visibility required to apply granular security controls and determine data ownership.

  • Review entries for employee data, customer databases, and marketing lists.
  • Verify that the classification levels, such as “Highly Confidential,” align with the sensitivity of the PII.
  • Confirm that an “Asset Owner” or Data Custodian is assigned to every PII category.

3. Review Data Flow Documentation and Processing Maps

Review the technical data flow mapping to visualise how PII enters, moves through, and leaves the organisation: result: identifies potential leakage points and verifies the lawfulness of cross-border data transfers.

  • Inspect the maps for third-party processing points and external storage locations.
  • Verify that international transfers are supported by appropriate legal mechanisms, such as Standard Contractual Clauses or the UK Addendum.
  • Check that data flows align with the purposes documented in the privacy notice.

Audit external-facing privacy notices and the technical mechanisms used to capture consent: result: confirms the organisation meets transparency requirements and maintains a lawful basis for processing.

  • Check that notices are provided at the point of data collection and include all mandatory disclosures.
  • Verify that consent logs are stored securely and demonstrate an active “opt-in” for specific processing activities.
  • Confirm that mechanisms for withdrawing consent are as easy to use as the mechanisms for providing it.

5. Verify Data Subject Rights Procedures and DSAR Logs

Verify the procedures for managing Data Subject Access Requests and other individual rights, such as deletion or portability: result: ensures the organisation can respond to legal requests within the 30-day statutory window.

  • Review the DSAR log for completion rates and response timestamps.
  • Inspect the technical process for redaction to ensure the privacy of third parties is protected during data release.
  • Verify that staff are trained to recognise and escalate a data subject request immediately.

6. Inspect Encryption and Anonymisation Configurations

Inspect the technical configuration for PII at rest and in transit to verify that obfuscation measures meet industry standards: result: mitigates the impact of unauthorised access by rendering intercepted PII unintelligible.

  • Audit the implementation of AES-256 encryption on servers and end-user devices.
  • Verify that pseudonymisation or anonymisation is utilised for testing and development environments.
  • Check the Key Management Policy to ensure cryptographic keys are stored separately from the PII they protect.

7. Audit IAM Roles and MFA Enforcement

Audit Identity and Access Management roles to verify that the Principle of Least Privilege is applied to all PII repositories: result: prevents internal data breaches and ensures only authorised personnel can access sensitive information.

  • Inspect access control lists for HR systems, CRM platforms, and financial databases.
  • Verify that Multi-Factor Authentication is mandated for all administrative and remote access points.
  • Review logs for orphaned accounts or excessive permissions granted to temporary staff or contractors.

8. Review Data Processing Agreements with Third Parties

Review the Data Processing Agreements and Rules of Engagement for all suppliers handling organisational PII: result: confirms that third-party risks are contractually mitigated and that suppliers provide adequate security guarantees.

  • Verify that contracts include “Right to Audit” clauses and mandatory breach notification timeframes.
  • Check that sub-processors are explicitly authorised and held to the same security standards.
  • Inspect the due diligence records for key suppliers, including their own ISO 27001 certifications.

9. Audit Data Protection Impact Assessments

Audit the records of Data Protection Impact Assessments performed for high-risk processing activities: result: provides evidence that the organisation follows a “Privacy by Design” approach to mitigate risks early in the lifecycle.

  • Review DPIA documents for new product launches or significant system migrations.
  • Verify that identified risks have been addressed through documented technical or organisational controls.
  • Confirm that the DPO or privacy lead was consulted during the assessment process.

10. Verify PII Retention and Secure Disposal Logs

Verify that PII is retained only as long as necessary and that disposal logs confirm secure destruction: result: reduces the organisational attack surface and prevents the storage of redundant, high-risk data.

  • Compare the actual stored data against the timeframes defined in the Retention Schedule.
  • Inspect certificates of destruction for physical media and shredding services.
  • Verify that automated data purging rules are functioning correctly within cloud storage environments.

Applicability across different business models

Business TypeApplicabilityExamples of Control Implementation
Small BusinessesHighly applicable for meeting basic GDPR or local privacy obligations. The focus is on identifying where customer and employee data (PII) is stored and ensuring it is handled with a clear “Lawful Basis.”
  • Maintaining a PII Register that lists all personal data held, such as employee payroll and customer contact lists.
  • Enforcing a 7-year retention period for financial PII in line with tax laws, with automated deletion thereafter.
  • Appointing the Office Manager as the internal “Privacy Lead” to oversee basic data subject access requests (DSARs).
Tech StartupsCritical for protecting high volumes of user data and ensuring compliance across multiple jurisdictions (e.g., GDPR and CCPA). Focus is on technical safeguards and privacy-by-design during development.
  • Implementing Data Masking or pseudonymization in development and testing environments to prevent developer exposure to real user PII.
  • Integrating Data Protection Impact Assessments (DPIA) into the change management process for any new product feature that processes personal data.
  • Enforcing AES-256 encryption for all cloud databases containing sensitive user PII.
AI CompaniesVital for protecting specialized AI datasets that may contain “Special Category” PII. Focus is on ensuring that training data pipelines do not ingest or leak sensitive personal information.
  • Utilizing automated Data Discovery Tools to scan large AI training datasets for accidental inclusion of biometrics or medical PII.
  • Establishing strict “Model Training Privacy” protocols that ensure proprietary model weights do not inadvertently memorize PII from the training set.
  • Formalizing Data Processing Agreements (DPAs) with all sub-processors and cloud GPU providers who handle research datasets.
Standard / LawRelevant Control / ArticleMapping and Requirements
GDPR / UK GDPRArticles 5, 24, 25, 30, 32, 35Direct Alignment: Requires Privacy by Design, security of processing, and Data Protection Impact Assessments (DPIA). Annex A 5.34 provides the technical implementation for these legal mandates.
NIST CSF v2.0GV.PO-01, PR.PS-01Privacy Governance: CSF v2.0 integrates privacy via Governance (GV) and Protective Technology (PR) categories to ensure PII is identified and managed.
UK Data (Use and Access) Act 2025Smart Data & Portability ClausesModernised GDPR: Focuses on Smart Data schemes. Requires high security thresholds for data sharing while reducing administrative burdens for smaller firms.
NIS2 Directive (EU)Article 21Cyber Risk Management: Includes the protection of personal data as a fundamental component of cybersecurity risk management for essential and important entities.
DORA (EU)Articles 8, 9, 10Financial Data Integrity: Mandates that ICT systems in the financial sector protect the integrity and confidentiality of all data, specifically client PII.
SOC 2 (AICPA)Privacy Trust Services Criteria (TSC)Privacy Criteria: Directly maps to the Privacy category, focusing on Notice, Choice, Collection, Use, Retention, Access, and Disclosure of personal information.
EU AI ActArticles 10, 15, 53AI Data Governance: Requires high-risk AI systems to use high-quality datasets. Annex A 5.34 ensures training data containing PII is pseudonymised to prevent model leakage.
ISO/IEC 42001 (AI)Annex A.4 (Data for AI)AI Privacy Management: Addresses the protection of PII within the AI lifecycle, particularly regarding data acquisition and dataset curation.
UK Cyber Security & Resilience BillMSP Reporting ObligationsExpanded Scope: Expands NIS2-style reporting to Managed Service Providers (MSPs). Breaches involving PII within an MSP environment trigger mandatory reporting.
CIRCIA (USA)Section 2242Incident Reporting: Critical infrastructure entities must report significant cyber incidents (including PII exfiltration) to CISA within 72 hours.
EU Product Liability Directive (PLD) UpdateArticle 4 (Defectiveness)Strict Liability: Classifies software as a product. A lack of Annex A 5.34 privacy controls leading to a breach can be evidence of a product defect.
ECCF (European Cybersecurity Certification Framework)Harmonised LabelsConsumer Trust: Annex A 5.34 compliance serves as a baseline for achieving harmonised security labels (Basic, Substantial, High) for products and services.
HIPAA (USA)Privacy Rule (45 CFR § 164.500)Health Data: Aligns with the protection of Protected Health Information (PHI). Provides the administrative and technical safeguards required for healthcare data.
CCPA / CPRA (California)Sections 1798.100 – 1798.199Consumer Rights: Mapping for data subject rights (access, deletion, opt-out) and the requirement for reasonable security to protect Sensitive PII.

ISO 27001 Annex A 5.34 FAQ

Is a Data Protection Impact Assessment (DPIA) mandatory for Annex A 5.34?

Yes, a DPIA is mandatory under Annex A 5.34 for any processing activity deemed high-risk to individual privacy rights. This technical assessment identifies potential leakage points before a project begins; failing to conduct a DPIA can result in regulatory fines from the ICO of up to £17.5 million or 4% of global annual turnover.

How does ISO 27001 Annex A 5.34 align with GDPR?

Annex A 5.34 serves as the technical bridge to GDPR compliance by providing the organisational framework for “Privacy by Design.” While GDPR sets the legal requirements, ISO 27001 5.34 mandates the implementation of specific controls to meet those requirements, such as data flow mapping, retention schedules, and Multi-Factor Authentication (MFA).

What are the PII breach notification rules for ISO 27001?

Organisations must report a PII breach within a strict 72-hour window to the relevant supervisory authority once they become aware of it. Statistics indicate that organisations with a formalised incident response plan, as required by Annex A 5.34, reduce the financial impact of a breach by approximately 35% through faster containment.

Can we use cloud storage for PII under ISO 27001?

Yes, cloud storage is permitted for PII provided that the provider meets the high security thresholds mandated by Annex A 5.34 and the UK Data (Use and Access) Act 2025. You must verify end-to-end encryption and that your Data Processing Agreement (DPA) includes a “Right to Audit” clause.

Further Reading

ISO 27001 Controls and Attribute values

Control typeInformation security propertiesCybersecurity conceptsOperational capabilitiesSecurity domains
PreventiveAvailability Confidentiality IntegrityIdentify ProtectLegal and compliance Information protectionProtection

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

ISO 27001 Annex A 5.34 Privacy and protection of PII
Shopping Basket
Scroll to Top