International (ISO/IEC JTC 1/SC 27)

ISO/IEC 29100:2024

64 controls. 249 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

64 controls 249 frameworks share controls with it International (ISO/IEC JTC 1/SC 27) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
29100-4.1Actors and roles169
29100-4.2Interactions between actors0
29100-4.3Privacy safeguarding requirements0
29100-5.1Recognizing PII0
29100-5.2Regulatory factors0
29100-5.3Privacy risk factors0
29100-6.1Consent and choice0
29100-6.10Information security123
29100-6.11Privacy compliance0
29100-6.2Purpose legitimacy and specification0
29100-6.3Collection limitation0
29100-6.4Data minimization0
29100-6.5Use, retention and disclosure limitation117
29100-6.6Accuracy and quality1
29100-6.7Openness, transparency and notice0
29100-6.8Individual participation and access0
29100-6.9Accountability117
ISO29100-5.1PII Actor Identification0
ISO29100-5.10.1Consent and Choice Principle0
ISO29100-5.10.10Information Security6
ISO29100-5.10.11Privacy Compliance0
ISO29100-5.10.2Purpose Legitimacy and Specification0
ISO29100-5.10.3Collection Limitation0
ISO29100-5.10.4Data Minimisation0
ISO29100-5.10.5Use, Retention, and Disclosure Limitation0
ISO29100-5.10.6Accuracy and Quality1
ISO29100-5.10.7Openness, Transparency, and Notice0
ISO29100-5.10.8Individual Participation and Access0
ISO29100-5.10.9Accountability0
ISO29100-5.2PII and Sensitive PII Categorisation0
ISO29100-6.1Privacy Safeguarding Requirements Identification0
ISO29100-6.2Privacy Risk Factors0
ISO29100-6.3Controls Selection and Implementation0
ISO29100-6.4Privacy by Design and Default1
ISO29100-6.5Cross Border PII Transfer Controls0
ISO29100-6.6Breach Management0
ISO29100-6.7Third Party Privacy Governance0
44 Basic elements of the privacy framework0
4.24.2 Actors and roles0
4.2.14.2.1 PII principals0
4.2.24.2.2 PII controllers0
4.2.34.2.3 PII processors0
4.2.44.2.4 Third parties0
4.34.3 Interactions0
4.44.4 Recognizing PII (identifiers, distinguishing characteristics, linkable information, pseudonymous data, metadata, unsolicited PII, sensitive PII)0
4.54.5 Privacy safeguarding requirements (legal and regulatory, contractual, business and other factors)0
4.64.6 Privacy policies0
4.74.7 Privacy controls0
55 The privacy principles of ISO/IEC 291000
5.105.10 Accountability0
5.115.11 Information security0
5.125.12 Privacy compliance0
5.25.2 Consent and choice0
5.35.3 Purpose legitimacy and specification0
5.45.4 Collection limitation0
5.55.5 Data minimization0
5.65.6 Use, retention and disclosure limitation0
5.75.7 Accuracy and quality0
5.85.8 Openness, transparency and notice0
5.95.9 Individual participation and access0
ANNEXAAnnex A (informative): Correspondence between ISO/IEC 29100 concepts and ISO/IEC 27000 concepts0
FRONTClauses 1 to 3: scope, normative references and terms0
STANDARDISO/IEC 29100:2024: the standard, its scope and what is held0
STATUSEdition status: 2024 is current and carries the 2011 plus Amd 1 text0

Tell me when ISO/IEC 29100:2024 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Internal audit reports on BIA
  • Peer review or external assurance reports
  • Improvement action log
  • compliance assessment reports
  • regulatory inventory
  • corrective action plans
  • rights request workflow
  • identity verification procedures
  • response time metrics
  • appeal mechanism

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 29100:2024, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition