ISO 27001 Privacy and Protection of PII
ISO 27001 Annex A 5.34 Privacy and Protection of PII is an ISO 27001 control that wants you to protect personally identifiable information (PII).
It requires you to identify and meet any requirements including those laid out in law, contracts and regulations.
Table of contents
- ISO 27001 Privacy and Protection of PII
- Key Takeaways
- What is PII?
- Purpose
- Definition
- Explanation
- Requirement
- Audit Focus
- FREE Training Video
- How to implement It
- ISO 27001 Templates
- How to Audit It
- Applicability across different business models
- Applicable Laws and Related Standards
- Related ISO 27001 Controls
- ISO 27001 Annex A 5.34 FAQ
- Further Reading
- ISO 27001 Controls and Attribute values
Key Takeaways
ISO 27001 Annex A 5.34 requires organizations to identify and protect Personally Identifiable Information (PII) in accordance with applicable laws, regulations, and contracts. It acts as the bridge between your information security management system (ISMS) and privacy frameworks like GDPR, ensuring that personal data is not just “secure” but also handled legally.
What is PII?
Personally identifiable information (PII) is any information that can be used to identify a specific individual. This can include things like a person’s name, address, phone number, email address or date of birth. PII can also include things like a person’s biometric data, such as their fingerprints or facial recognition data.
PII is considered sensitive data because it can be used to commit identity theft, fraud, or other crimes. It is important to protect PII from unauthorised access, use, disclosure, disruption, modification, or destruction.
There are often specific laws, such as the GDPR that relate to the protection of PII and these take precedence over this clause.
Consult with a GDPR or Data Protection professional.
Purpose
The purpose of ISO 27001 Annex A 5.34 Privacy and Protection of PII is to ensure you comply with legal, statutory, regulatory and contractual requirements related to the protection of personally identifiable information (PII) .
Organisations should have a clear understanding of their obligations when it comes to the protection of PII and make sure that they adhere to those requirements.
Definition
The ISO 27001 standard defines ISO 27001 Annex A 5.34 as:
The organisation should identify and meet the requirements regarding the preservation of privacy and protection of PII according to applicable laws and regulations and contractual requirements.
ISO 27001:2022 Annex A 5.34 Privacy and Protection of PII
Explanation
ISO 27001 Annex A 5.34 Privacy and Protection of PII is a security control that mandates the identification and fulfilment of legal data protection requirements. By establishing a formal PII register and specific technical safeguards, organisations achieve the business benefit of regulatory compliance and reduced litigation risk.
Requirement
- Legal Register: You must clearly identify which privacy laws apply to you (e.g., GDPR in Europe, CCPA in California) and list them in your legal register.
- Topic-Specific Policy: Create a dedicated policy for “Privacy and Protection of PII.” This should define how you classify, handle, and protect personal data specifically, separate from general company data.
- Role Assignment: Appoint a responsible person, such as a Data Protection Officer (DPO) or Privacy Officer, to provide leadership.
- Technical Measures: Implement specific controls to protect PII, such as encryption, access control, and data masking.
Audit Focus
Auditors will look for evidence that you understand why you are holding data. They will check your PII Register (or Record of Processing Activities) to see if you have defined a “Lawful Basis” for every type of personal data you store, whether it’s employee payroll, customer emails, or CCTV footage.
Practical Application: This control acknowledges that ISO 27001 is not a privacy standard by itself. It requires you to “consult with a professional” and potentially integrate with ISO 27701 (the privacy extension) if you process significant amounts of personal data.
FREE Training Video
In this free training video you will learn How to implement ISO 27001 Privacy and Protection of PII (Annex A 5.34) and Pass Your Audit.
How to implement It
Have a topic specific policy on privacy and protection of PII
You are going to implement an ISO 27001 Information Classification and Handling Policy that includes and specifically addresses as part of it, the protection and handling of PII.
Implement Process and procedures for PII
Building on the ISO 27001 Information Classification and Handling Policy you will implement the processes and procedures to protect the preservation and privacy of PII.
Assign roles and responsibilities
Roles and responsibilities will be defined and assigned. Consideration will be given to appointing someone to be responsible such as a privacy officer who will provide that leadership and guidance to people on their responsibilities and the procedures to be followed.
Put in place technical and organisational measures
Appropriate measures for both the organisation and technology will be implemented to protect PII.
Ensure you cover different country requirements
There is a difference in the international approach to data protection and requirements on PII. These should be addressed based on where you are operating. This forms part of the ISO 27001 legal register and the requirements that we covered in ISO 27001 Annex A 5.31 Legal, regulatory, statutory and contractual requirements.
Use a data protection professional
The ISO 27001 standard is actually dabbling in other areas with this particular control. It is one isolated part of a bigger profession and requirement and as such for this and in more general terms we strongly recommend engaging the services of a data protection professional.
ISO 27001 Starter Kit – ($97)
Instant download of the mandatory ISO 27001 ISMS and Polices. Auditor verifed and certification body aprroved, downloaded 5.000+ times globablly to achieve ISO 27001 certification first time.
ISO 27001 Templates

How to Audit It
Auditing ISO 27001 Annex A 5.34 requires a meticulous examination of how your organisation identifies, processes, and safeguards Personally Identifiable Information. As a Lead Auditor, I look for technical evidence that privacy is embedded into the system architecture, not just the policy. Use this 10 step technical roadmap to ensure your PII controls withstand the scrutiny of a rigorous certification audit.
1. Audit the Privacy and PII Protection Policy
Audit the topic-specific policy for privacy and PII protection to confirm it defines the organisational approach to managing personal data: result: establishes the legal and procedural baseline for both ISO 27001 and statutory data protection compliance.
- Verify that the policy explicitly references relevant legislation, such as the UK GDPR and Data Protection Act 2018.
- Check for clear definitions of PII and sensitive personal data within the organisational context.
- Confirm the policy is reviewed annually and carries executive-level sign-off.
2. Inspect the Asset Register for PII Mapping
Inspect the organisational Asset Register to ensure all PII data sets and processing systems are identified and classified: result: provides the visibility required to apply granular security controls and determine data ownership.
- Review entries for employee data, customer databases, and marketing lists.
- Verify that the classification levels, such as “Highly Confidential,” align with the sensitivity of the PII.
- Confirm that an “Asset Owner” or Data Custodian is assigned to every PII category.
3. Review Data Flow Documentation and Processing Maps
Review the technical data flow mapping to visualise how PII enters, moves through, and leaves the organisation: result: identifies potential leakage points and verifies the lawfulness of cross-border data transfers.
- Inspect the maps for third-party processing points and external storage locations.
- Verify that international transfers are supported by appropriate legal mechanisms, such as Standard Contractual Clauses or the UK Addendum.
- Check that data flows align with the purposes documented in the privacy notice.
Check Your Work?
You buit it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let a trained ISO 27001 auditor check your work.

Applicability across different business models
| Business Type | Applicability | Examples of Control Implementation |
|---|---|---|
| Small Businesses | Highly applicable for meeting basic GDPR or local privacy obligations. The focus is on identifying where customer and employee data (PII) is stored and ensuring it is handled with a clear “Lawful Basis.” |
|
| Tech Startups | Critical for protecting high volumes of user data and ensuring compliance across multiple jurisdictions (e.g., GDPR and CCPA). Focus is on technical safeguards and privacy-by-design during development. |
|
| AI Companies | Vital for protecting specialized AI datasets that may contain “Special Category” PII. Focus is on ensuring that training data pipelines do not ingest or leak sensitive personal information. |
|
Applicable Laws and Related Standards
| Standard / Law | Relevant Control / Article | Mapping and Requirements |
|---|---|---|
| GDPR / UK GDPR | Articles 5, 24, 25, 30, 32, 35 | Direct Alignment: Requires Privacy by Design, security of processing, and Data Protection Impact Assessments (DPIA). Annex A 5.34 provides the technical implementation for these legal mandates. |
| NIST CSF v2.0 | GV.PO-01, PR.PS-01 | Privacy Governance: CSF v2.0 integrates privacy via Governance (GV) and Protective Technology (PR) categories to ensure PII is identified and managed. |
| UK Data (Use and Access) Act 2025 | Smart Data & Portability Clauses | Modernised GDPR: Focuses on Smart Data schemes. Requires high security thresholds for data sharing while reducing administrative burdens for smaller firms. |
| NIS2 Directive (EU) | Article 21 | Cyber Risk Management: Includes the protection of personal data as a fundamental component of cybersecurity risk management for essential and important entities. |
| DORA (EU) | Articles 8, 9, 10 | Financial Data Integrity: Mandates that ICT systems in the financial sector protect the integrity and confidentiality of all data, specifically client PII. |
| SOC 2 (AICPA) | Privacy Trust Services Criteria (TSC) | Privacy Criteria: Directly maps to the Privacy category, focusing on Notice, Choice, Collection, Use, Retention, Access, and Disclosure of personal information. |
| EU AI Act | Articles 10, 15, 53 | AI Data Governance: Requires high-risk AI systems to use high-quality datasets. Annex A 5.34 ensures training data containing PII is pseudonymised to prevent model leakage. |
| ISO/IEC 42001 (AI) | Annex A.4 (Data for AI) | AI Privacy Management: Addresses the protection of PII within the AI lifecycle, particularly regarding data acquisition and dataset curation. |
| UK Cyber Security & Resilience Bill | MSP Reporting Obligations | Expanded Scope: Expands NIS2-style reporting to Managed Service Providers (MSPs). Breaches involving PII within an MSP environment trigger mandatory reporting. |
| CIRCIA (USA) | Section 2242 | Incident Reporting: Critical infrastructure entities must report significant cyber incidents (including PII exfiltration) to CISA within 72 hours. |
| EU Product Liability Directive (PLD) Update | Article 4 (Defectiveness) | Strict Liability: Classifies software as a product. A lack of Annex A 5.34 privacy controls leading to a breach can be evidence of a product defect. |
| ECCF (European Cybersecurity Certification Framework) | Harmonised Labels | Consumer Trust: Annex A 5.34 compliance serves as a baseline for achieving harmonised security labels (Basic, Substantial, High) for products and services. |
| HIPAA (USA) | Privacy Rule (45 CFR § 164.500) | Health Data: Aligns with the protection of Protected Health Information (PHI). Provides the administrative and technical safeguards required for healthcare data. |
| CCPA / CPRA (California) | Sections 1798.100 – 1798.199 | Consumer Rights: Mapping for data subject rights (access, deletion, opt-out) and the requirement for reasonable security to protect Sensitive PII. |
Related ISO 27001 Controls
ISO 27001 Annex A 5.34 FAQ
Yes, a DPIA is mandatory under Annex A 5.34 for any processing activity deemed high-risk to individual privacy rights. This technical assessment identifies potential leakage points before a project begins; failing to conduct a DPIA can result in regulatory fines from the ICO of up to £17.5 million or 4% of global annual turnover.
Annex A 5.34 serves as the technical bridge to GDPR compliance by providing the organisational framework for “Privacy by Design.” While GDPR sets the legal requirements, ISO 27001 5.34 mandates the implementation of specific controls to meet those requirements, such as data flow mapping, retention schedules, and Multi-Factor Authentication (MFA).
Organisations must report a PII breach within a strict 72-hour window to the relevant supervisory authority once they become aware of it. Statistics indicate that organisations with a formalised incident response plan, as required by Annex A 5.34, reduce the financial impact of a breach by approximately 35% through faster containment.
Yes, cloud storage is permitted for PII provided that the provider meets the high security thresholds mandated by Annex A 5.34 and the UK Data (Use and Access) Act 2025. You must verify end-to-end encryption and that your Data Processing Agreement (DPA) includes a “Right to Audit” clause.
Further Reading
- ISO 27001 Privacy and Personally Identifiable Information (PII): Your Complete FAQ Guide
- ISO 27001 Data Protection Policy Template
ISO 27001 Controls and Attribute values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Availability Confidentiality Integrity | Identify Protect | Legal and compliance Information protection | Protection |
