A.5.34
    Organizational Controls

    Privacy and protection of personal information

    The organization should identify and meet the requirements regarding the preservation of privacy and protection of personal information according to applicable laws and regulations and where applicable, contractual requirements.

    Purpose

    To ensure privacy and protection of personal information as required by law and organizational policy.

    Implementation Guidance

    Identify and comply with applicable privacy laws (GDPR, CCPA, etc.)

    Implement privacy by design principles

    Conduct data protection impact assessments

    Provide privacy notices and obtain consent where required

    Enable data subject rights (access, deletion, portability)

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.34 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.34 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.34 Privacy and protection of personal information. Built for compliance professionals.

    Try ISMS Copilot free