← ISO 27001 · A.5 — Organisational
A.5.34 — Privacy and protection of personally identifiable information
high
lawful-basisprivacy-noticedata-minimisation
Requirement
The organisation shall identify and meet the requirements regarding the preservation of privacy and protection of PII according to applicable laws and regulations and contractual requirements.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Required element 1 — any one of
piipersonal datapersonal informationprivacy
Required element 2 — any one of
protectrequirementlawfulconsentminimis…
Supporting terms — specificity signals
dpodpiaropadata subjectretentiontransfer
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| GDPR | Art.5(1)(a) | Lawfulness, fairness and transparency | lawful-basis privacy-notice |
| GDPR | Art.5(1)(b) | Purpose limitation | data-minimisation lawful-basis |
| SOC 2 | P1.1 | Notice and communication of privacy commitments | privacy-notice lawful-basis |
| NDPA 2023 | s.24 | Principles of data processing | lawful-basis data-minimisation |
| GDPR | Art.5(1)(c) | Data minimisation | data-minimisation |
| GDPR | Art.6 | Lawful basis for processing | lawful-basis |
| GDPR | Art.8 | Conditions for a child's consent to online services | lawful-basis |
| GDPR | Art.9 | Special category data | lawful-basis |