August 7, 2024

ISO 27001:2022 Annex A Control 5.34: Privacy and Protection of PII

Annex A control 5.34 of the 2022 version of the ISO 27001 standard can be mapped to ISO 27001:2013 Annex A 18.1.4

By
Full name
Share this post
A woman smiles while using a tablet, surrounded by digital notifications and a data chart.

Control 5.34 covers the protection of Personal Identifiable Information, otherwise known as PII. In particular, it focuses on three key areas: privacy, protection, and preservation.

The control is designed as a preventative measure to help keep risks at bay, outlining guidelines and procedures to meet legal, regulatory, statutory and contractual obligations surrounding the storage, privacy, and protection of PII in all forms.

What is PII?

PII is a term used to describe any data which can be used to identify a person or persons. This may include a driver’s licence, medical records, address, financial information such as bank accounts, and a National Insurance Number or Social Security Number.

Any data oversight plan conducted by an organisation must take the protection of PII into account, considering the vast array of regulatory, legislative and contractual dangers attached to shared PII.

Guidelines for Annex A Control 5.34

PII protection is a specialised business practice and requires distinct policies to cover the kinds of PII most commonly encountered in the organisation on a day-to-day basis. Control 5.34 describes how organisations must compile, formulate and execute policies dedicated to protecting PII. They must also ensure that all staff working with PII are made aware of these policies and stick to them.

Policies should take into account individual roles, responsibilities and data controls across the organisation, offering a top-down approach in which a dedicated Privacy Officer guides employees and third-party organisations through the process of complying with PII obligations.

In order to effectively manage PII while within the business, organisations must adhere to legislative, regulatory and contractual regulations.

Overseas use of control 5.34

It’s important to research relevant legislation concerning PII, as it can change from one country, region, or sector to another. Organisations must review their PII handling requirements, especially when it comes to data shared across different countries.

ISO 27001:2022 does not contain any specific information on how to handle this, but other ISO documents do, including ISO/IEC 29100, ISO/IEC 27701, and ISO/IEC 27018.

What’s changed since 2013?

Annex A control 5.34 replaces ISO 27001:2013 18.1.4 and is almost identical bar two key differences. The first of these is that control 5.34 recommends organisations contemplate a subject-specific policy when developing and implementing PII policies and procedures. The second is that control 5.34 puts greater emphasis on safeguarding PII alongside standard privacy and protection regulations.

Risk Management
Compliance Reporting
Policy Management
Incident Management
Audits and Assessments

Ready to Take Control of Your Privacy Compliance?

See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.

Risk Management

Identify, assess, and mitigate security risks with an integrated risk register.Hicomply’s automated risk management software maps controls across ISO 27001, SOC 2, and NIST frameworks — helping teams track risk treatment plans, assign ownership, and monitor real-time compliance status.Build a resilient ISMS that reduces audit findings and demonstrates continuous improvement.

Compliance Reporting

Generate instant, audit-ready compliance reports across multiple frameworks — from ISO 27001 and SOC 2 to GDPR, DORA, and NHS DSPT.Automated evidence collection and built-in dashboards provide a single source of truth for your compliance posture, saving weeks of manual work during audits.

Policy Management

Centralise, version, and publish all your information security policies in one place.Hicomply automates approvals, reminders, and distribution, ensuring your ISMS documentation stays current and aligned with frameworks like ISO 42001 and NIST CSF.Say goodbye to outdated PDFs — manage policies dynamically and maintain full traceability.

Incident Management

Capture, investigate, and resolve security incidents with structured workflows and automated evidence trails.Hicomply integrates with ticketing tools like Jira, Zendesk, and Azure DevOps to streamline incident response and link findings to risk and control updates — a key step for SOC 2 Type II readiness.

Audits and Assessments

Simplify internal and external audit preparation with built-in audit templates and automated task assignments.
Hicomply’s audit management platform aligns with ISO 27001, ISO 9001, and ISO 14001, giving teams a clear overview of control effectiveness, audit evidence, and corrective actions — all from one dashboard.

Getting Started
Health care
IT and Services
Legal Services
Financial Services
Growth