ISO27001:2022 – A5.34 – Privacy and protection of PII
Introduction to ISO 27001 – A5.34
For many, ISO 27001 – A5.34 is one of the most important—because it speaks directly to the protection of people. At its core, ISO27001 is about protecting valuable business assets, and there are few assets more valuable than personal data.
What does ISO 27001 – A5.34 require?
“The organisation shall identify and meet the requirements regarding the preservation of privacy and protection of PII according to applicable laws and regulations and contractual requirements.”
(ISO 27001 – A5.34 – Privacy and protection of PII)
Personal Data vs. PII
The term “PII” (Personally Identifiable Information) is commonly used in the US, while in the UK and EU the preferred term is “personal data” as defined in GDPR:
“Any information relating to an identified or identifiable natural person (‘data subject’)…”
– GDPR Article 4(1)
Though similar, PII tends to focus on specific identifiers (like a Social Security Number), while personal data has a broader context, encompassing any data that could directly or indirectly identify a person.
Why is this required?
Data breaches are about more than systems—they affect real people. Personal data includes emails, names, addresses, medical records, and financial data. When breached, the harm can be severe.
Protecting this data is about safeguarding trust, maintaining compliance, and protecting your organisation’s reputation. A breach could result in regulatory fines, legal action, or a ban on processing data, depending on the severity and response.
What the auditor is looking for
This control works closely with several others, especially:
Specifically, the auditor will look for:
- A legal register that includes privacy laws (e.g. GDPR, UK DPA 2018)
- A data retention policy and proof that it is being followed
- Data Protection Impact Assessments (DPIAs)
- Records of Processing Activities (RoPA)
- Privacy notices that are accurate, up to date, and legally compliant
What do you need to do?
- Create or update your legal register with specific privacy and data protection laws relevant to your region and contracts.
- Work with your DPO (if you have one) to ensure proper DPIA and RoPA processes are in place.
- Publish and maintain an accurate privacy notice on your website.
- Develop and enforce a data retention policy that reflects your business needs and legal obligations.
- Conduct regular audits to show compliance with data protection requirements.
In short, demonstrate that your organisation takes the protection of personal data seriously—and has controls in place to prove it.
Q & A
Is it possible to get this wrong?
Yes. Failing to document your legal obligations, or failing to show evidence that you follow your retention or privacy practices, will likely result in a nonconformity.
What documents should we prioritise?
- Your legal register
- Your data retention schedule
- Evidence of DPIA and RoPA processes
- Your privacy notice
Difficulty Rating
2 out of 5 – While not technically difficult, this control can be complex if you process large volumes of personal data or operate in multiple jurisdictions. It often requires cross-functional input—from legal, compliance, HR, and your DPO.
Final Tip
Remember that this is one of the most visible ISO27001 controls to your customers and the public. Treat your privacy obligations not just as a compliance issue, but as a trust-building opportunity.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001”—available now on Amazon.
