29134-4 | General overview | 0 |
29134-5.1 | Determining PIA necessity | 0 |
29134-5.2 | Defining PIA scope | 0 |
29134-5.3 | Stakeholder identification | 0 |
29134-6.1 | Information flow identification | 0 |
29134-6.2 | PII processing description | 0 |
29134-6.3 | Legal basis analysis | 0 |
29134-7.1 | Risk identification | 2 |
29134-7.2 | Impact assessment | 0 |
29134-7.3 | Likelihood assessment | 0 |
29134-7.4 | Risk evaluation | 2 |
29134-8.1 | Treatment options | 0 |
29134-8.2 | Control selection | 0 |
29134-8.3 | Residual risk assessment | 0 |
29134-9.1 | PIA report structure | 206 |
29134-9.2 | Report findings and recommendations | 64 |
29134-9.3 | PIA review and update | 0 |
29134-9.4 | Publication and communication | 0 |
ISO29134-10.1 | PIA Implementation Tracking | 0 |
ISO29134-10.2 | PIA Review and Update | 0 |
ISO29134-10.3 | Prior Consultation with Supervisory Authority | 0 |
ISO29134-11.1 | PIA Programme Maturity | 0 |
ISO29134-5.1 | PIA Trigger Identification | 0 |
ISO29134-5.2 | PIA Scope Definition | 0 |
ISO29134-5.3 | PIA Team Composition | 0 |
ISO29134-6.1 | Processing Description | 0 |
ISO29134-6.2 | Necessity and Proportionality Assessment | 0 |
ISO29134-6.3 | Stakeholder Consultation | 0 |
ISO29134-7.1 | Privacy Risk Identification | 0 |
ISO29134-7.2 | Likelihood Assessment | 0 |
ISO29134-7.3 | Severity Assessment | 0 |
ISO29134-7.4 | Risk Evaluation Against Criteria | 2 |
ISO29134-8.1 | Risk Treatment Measures | 3 |
ISO29134-8.2 | Residual Risk Documentation | 0 |
ISO29134-8.3 | Action Plan | 0 |
ISO29134-9.1 | PIA Report Documentation | 0 |
ISO29134-9.2 | PIA Approval and Sign Off | 0 |
ISO29134-9.3 | PIA Publication and Sharing | 0 |
5 | 5 Preparing the grounds for PIA | 0 |
5.1 | 5.1 Benefits of carrying out a PIA | 0 |
5.2 | 5.2 Objectives of PIA reporting | 0 |
5.3 | 5.3 Accountability to conduct a PIA | 0 |
5.4 | 5.4 Scale of a PIA | 0 |
6 | 6 Guidance on the process for conducting a PIA | 0 |
6.1 | 6.1 Guidance on the process: general | 0 |
6.2 | 6.2 Determine whether a PIA is necessary (threshold analysis) | 0 |
6.3 | 6.3 Preparation of the PIA | 0 |
6.3.1 | 6.3.1 Set up the PIA team and provide it with direction | 0 |
6.3.2 | 6.3.2 Prepare a PIA plan and determine the necessary resources for conducting the PIA | 0 |
6.3.3 | 6.3.3 Describe what is being assessed | 0 |
6.3.4 | 6.3.4 Stakeholder engagement | 0 |
6.4 | 6.4 Perform the PIA | 0 |
6.4.1 | 6.4.1 Identify information flows of PII | 0 |
6.4.2 | 6.4.2 Analyse the implications of the use case | 0 |
6.4.3 | 6.4.3 Determine the relevant privacy safeguarding requirements | 0 |
6.4.4 | 6.4.4 Assess privacy risk | 0 |
6.4.5 | 6.4.5 Prepare for treating privacy risks | 0 |
6.5 | 6.5 Follow up the PIA | 0 |
6.5.1 | 6.5.1 Prepare the report | 0 |
6.5.2 | 6.5.2 Publication | 0 |
6.5.3 | 6.5.3 Implement privacy risk treatment plans | 0 |
6.5.4 | 6.5.4 Review and/or audit of the PIA | 0 |
6.5.5 | 6.5.5 Reflect changes to the process | 0 |
7 | 7 PIA report | 0 |
7.2 | 7.2 Report structure | 0 |
7.3 | 7.3 Scope of PIA | 0 |
7.3.1 | 7.3.1 Process under evaluation | 0 |
7.3.2 | 7.3.2 Risk criteria | 0 |
7.3.3 | 7.3.3 Resources and people involved | 0 |
7.3.4 | 7.3.4 Stakeholder consultation | 0 |
7.4 | 7.4 Privacy requirements | 0 |
7.5 | 7.5 Risk assessment | 0 |
7.5.1 | 7.5.1 Risk sources | 0 |
7.5.2 | 7.5.2 Threats and their likelihood | 0 |
7.5.3 | 7.5.3 Consequences and their level of impact | 0 |
7.5.4 | 7.5.4 Risk evaluation | 0 |
7.5.5 | 7.5.5 Compliance analysis | 0 |
7.6 | 7.6 Risk treatment plan | 0 |
7.7 | 7.7 Conclusion and decisions | 0 |
7.8 | 7.8 PIA public summary | 0 |
ANNEXES | Annexes A to D (informative) | 0 |
STANDARD | ISO/IEC 29134:2023: the standard, its scope and what is held | 0 |
STATUS | Edition status: the 2023 second edition is current and editorially identical to 2017 | 0 |