International (ISO/IEC JTC 1/SC 27); adopted as CSA ISO/IEC 29134:24 and nationally

ISO/IEC 29134:2023

83 controls. 236 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

83 controls 236 frameworks share controls with it International (ISO/IEC JTC 1/SC 27); adopted as CSA ISO/IEC 29134:24 and nationally verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
29134-4General overview0
29134-5.1Determining PIA necessity0
29134-5.2Defining PIA scope0
29134-5.3Stakeholder identification0
29134-6.1Information flow identification0
29134-6.2PII processing description0
29134-6.3Legal basis analysis0
29134-7.1Risk identification2
29134-7.2Impact assessment0
29134-7.3Likelihood assessment0
29134-7.4Risk evaluation2
29134-8.1Treatment options0
29134-8.2Control selection0
29134-8.3Residual risk assessment0
29134-9.1PIA report structure206
29134-9.2Report findings and recommendations64
29134-9.3PIA review and update0
29134-9.4Publication and communication0
ISO29134-10.1PIA Implementation Tracking0
ISO29134-10.2PIA Review and Update0
ISO29134-10.3Prior Consultation with Supervisory Authority0
ISO29134-11.1PIA Programme Maturity0
ISO29134-5.1PIA Trigger Identification0
ISO29134-5.2PIA Scope Definition0
ISO29134-5.3PIA Team Composition0
ISO29134-6.1Processing Description0
ISO29134-6.2Necessity and Proportionality Assessment0
ISO29134-6.3Stakeholder Consultation0
ISO29134-7.1Privacy Risk Identification0
ISO29134-7.2Likelihood Assessment0
ISO29134-7.3Severity Assessment0
ISO29134-7.4Risk Evaluation Against Criteria2
ISO29134-8.1Risk Treatment Measures3
ISO29134-8.2Residual Risk Documentation0
ISO29134-8.3Action Plan0
ISO29134-9.1PIA Report Documentation0
ISO29134-9.2PIA Approval and Sign Off0
ISO29134-9.3PIA Publication and Sharing0
55 Preparing the grounds for PIA0
5.15.1 Benefits of carrying out a PIA0
5.25.2 Objectives of PIA reporting0
5.35.3 Accountability to conduct a PIA0
5.45.4 Scale of a PIA0
66 Guidance on the process for conducting a PIA0
6.16.1 Guidance on the process: general0
6.26.2 Determine whether a PIA is necessary (threshold analysis)0
6.36.3 Preparation of the PIA0
6.3.16.3.1 Set up the PIA team and provide it with direction0
6.3.26.3.2 Prepare a PIA plan and determine the necessary resources for conducting the PIA0
6.3.36.3.3 Describe what is being assessed0
6.3.46.3.4 Stakeholder engagement0
6.46.4 Perform the PIA0
6.4.16.4.1 Identify information flows of PII0
6.4.26.4.2 Analyse the implications of the use case0
6.4.36.4.3 Determine the relevant privacy safeguarding requirements0
6.4.46.4.4 Assess privacy risk0
6.4.56.4.5 Prepare for treating privacy risks0
6.56.5 Follow up the PIA0
6.5.16.5.1 Prepare the report0
6.5.26.5.2 Publication0
6.5.36.5.3 Implement privacy risk treatment plans0
6.5.46.5.4 Review and/or audit of the PIA0
6.5.56.5.5 Reflect changes to the process0
77 PIA report0
7.27.2 Report structure0
7.37.3 Scope of PIA0
7.3.17.3.1 Process under evaluation0
7.3.27.3.2 Risk criteria0
7.3.37.3.3 Resources and people involved0
7.3.47.3.4 Stakeholder consultation0
7.47.4 Privacy requirements0
7.57.5 Risk assessment0
7.5.17.5.1 Risk sources0
7.5.27.5.2 Threats and their likelihood0
7.5.37.5.3 Consequences and their level of impact0
7.5.47.5.4 Risk evaluation0
7.5.57.5.5 Compliance analysis0
7.67.6 Risk treatment plan0
7.77.7 Conclusion and decisions0
7.87.8 PIA public summary0
ANNEXESAnnexes A to D (informative)0
STANDARDISO/IEC 29134:2023: the standard, its scope and what is held0
STATUSEdition status: the 2023 second edition is current and editorially identical to 20170

Tell me when ISO/IEC 29134:2023 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ISO/IEC 29134:2023, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition