← ISO 27001 · A.5 — Organisational

A.5.34 — Privacy and protection of personally identifiable information

high lawful-basisprivacy-noticedata-minimisation

Requirement

The organisation shall identify and meet the requirements regarding the preservation of privacy and protection of PII according to applicable laws and regulations and contractual requirements.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
piipersonal datapersonal informationprivacy
Required element 2 — any one of
protectrequirementlawfulconsentminimis…
Supporting terms — specificity signals
dpodpiaropadata subjectretentiontransfer

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
GDPR Art.5(1)(a) Lawfulness, fairness and transparency lawful-basis privacy-notice
GDPR Art.5(1)(b) Purpose limitation data-minimisation lawful-basis
SOC 2 P1.1 Notice and communication of privacy commitments privacy-notice lawful-basis
NDPA 2023 s.24 Principles of data processing lawful-basis data-minimisation
GDPR Art.5(1)(c) Data minimisation data-minimisation
GDPR Art.6 Lawful basis for processing lawful-basis
GDPR Art.8 Conditions for a child's consent to online services lawful-basis
GDPR Art.9 Special category data lawful-basis