Skip to main content
Category: Privacy Principles

ISO/IEC 29100

Also known as: ISO/IEC 29100 Privacy Framework, Privacy framework
Simply put

ISO/IEC 29100 is an international standard that sets out a high-level framework for protecting personally identifiable information (PII) in information and communication technology systems. It establishes a shared vocabulary for privacy and describes the different actors involved in handling PII and the roles they play. It is a foundational reference document rather than a certifiable or prescriptive control set.

Formal definition

ISO/IEC 29100 is an International Standard (originally published as ISO/IEC 29100:2011 and revised as ISO/IEC 29100:2024) that provides a high-level privacy framework for the protection of personally identifiable information (PII) within information and communication technology environments. It specifies common privacy terminology, defines the actors and their roles in processing PII, describes privacy safeguarding considerations, and provides references to known privacy principles. As a framework and terminology standard, it is intended to be foundational and is commonly used alongside other standards in the ISO/IEC privacy family; it does not itself constitute a certifiable management system, nor does it prescribe specific technical or organizational controls, mandate particular lawful bases, or address the mechanics of cross-border transfers, retention rules, or enforcement. Note that ISO/IEC 29100 uses the term PII, which is defined within the standard's own terminology and should not be assumed identical to definitions of personal data or special category data under instruments such as the EU GDPR or UK GDPR. This entry covers scope and purpose only and is not a substitute for reading the standard text.

Why it matters

ISO/IEC 29100 matters because privacy work across organizations, jurisdictions, and disciplines frequently breaks down over inconsistent vocabulary. When legal, security, engineering, and governance teams use the same word to mean different things, controls are misapplied and accountability becomes ambiguous. By specifying a common privacy terminology and defining the actors involved in processing personally identifiable information (PII) and the roles they play, the standard provides a shared reference point that other documents in the ISO/IEC privacy family can build upon.

Because it is a high-level framework and terminology standard rather than a certifiable management system, its value is foundational rather than operational. It does not prescribe specific technical or organizational controls, does not mandate a lawful basis for processing, and does not address the mechanics of cross-border transfers, retention, or enforcement. Organizations should therefore treat it as a starting vocabulary and conceptual scaffold, not as a compliance deliverable in itself. Adopting its terminology does not, on its own, demonstrate compliance with any particular regulation.

A further point of caution for expert readers: ISO/IEC 29100 uses the term PII, which is defined within the standard's own terminology and should not be assumed identical to the definitions of personal data or special category data under instruments such as the EU GDPR or UK GDPR. Mapping the standard's concepts onto a specific legal regime requires deliberate interpretation rather than one-to-one substitution.

Who it's relevant to

Privacy and data protection officers
Practitioners responsible for privacy programs can use ISO/IEC 29100 as a shared vocabulary and a description of actors and roles in PII processing, giving cross-functional teams a common conceptual baseline. They should note, however, that the standard does not map directly onto legal definitions such as personal data or special category data under the EU or UK GDPR, and that adopting its terms does not by itself demonstrate compliance.
Privacy engineers and systems architects
Those designing information and communication technology systems benefit from the standard's high-level framework and its description of privacy safeguarding considerations when structuring how PII is handled. Because the standard does not prescribe specific technical or organizational controls, engineers must look to more prescriptive standards and internal requirements to select and implement actual safeguards.
Governance and standards leads
Information governance and standards teams use ISO/IEC 29100 as a foundational reference that sits alongside other documents in the ISO/IEC privacy family, aligning terminology across policies and frameworks. They should treat it as a terminology and framework standard rather than a certifiable management system, and pair it with instruments that address controls, retention, transfers, and enforcement.
Legal and compliance professionals
Legal and compliance staff can reference the standard's common terminology and defined roles to structure discussions with technical teams, while remaining aware that its PII concept is defined within the standard and is not interchangeable with statutory definitions. It does not address lawful bases, cross-border transfer mechanics, retention rules, or enforcement, so it cannot substitute for jurisdiction-specific legal analysis.

Inside ISO/IEC 29100

Privacy Framework Scope
ISO/IEC 29100 is an international standard that provides a high-level privacy framework, establishing common privacy terminology and defining the actors and roles involved in the processing of personally identifiable information (PII). It is a foundational, non-certifiable standard that other standards in the ISO/IEC 2910x family build upon.
Privacy Principles
The standard sets out a set of privacy principles intended to guide the design, development, and operation of information and communication technology systems that handle PII. These principles are framing guidance rather than legal obligations, and they do not by themselves establish a lawful basis for processing under any specific regulation such as the EU GDPR.
Actor and Role Definitions
It defines actors such as the PII principal (the individual to whom the PII relates), the PII controller, the PII processor, and third parties. These role definitions are conceptually related to, but not identical to, the controller and processor concepts under the EU GDPR or UK GDPR, and obligations attached to each role differ across legal regimes.
Terminology for PII
The standard defines personally identifiable information and related concepts to support consistent usage across privacy standards. Its terminology is not automatically interchangeable with statutory definitions of personal data, special category data, or sensitive data found in specific laws.
Relationship to Other Standards
ISO/IEC 29100 provides the conceptual vocabulary and principles that underpin management-oriented standards such as ISO/IEC 27701. It supports governance framing but does not itself define management system requirements or security controls.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 29100.

Is ISO/IEC 29100 a certifiable standard that proves my organization is compliant?
No. ISO/IEC 29100 is a privacy framework standard that establishes terminology, actors, and a set of privacy principles; it is generally not itself a certification standard in the way a management system standard is. Adopting its vocabulary and principles does not by itself demonstrate compliance with any specific law such as the EU GDPR, the UK GDPR, or the CCPA and CPRA. Demonstrable compliance depends on the applicable legal regime, your implementation, and evidence you can produce, not on aligning with a framework document alone.
Does following ISO/IEC 29100 mean I have satisfied my GDPR or other legal obligations?
Not necessarily. ISO/IEC 29100 provides a common conceptual foundation and privacy principles, but it is a standards instrument rather than a law. Legal obligations under regimes such as the EU GDPR, the UK GDPR, HIPAA, or the CCPA and CPRA are defined by those instruments and are not interchangeable with the framework. Alignment with the standard may support a privacy program, but statutory duties, lawful bases, and enforcement expectations must be assessed separately under each applicable jurisdiction.
How does ISO/IEC 29100 relate to other privacy standards we may already use?
ISO/IEC 29100 is generally positioned as a foundational framework that establishes shared terminology, actors, and privacy principles which other privacy standards in the same family can build upon. Organizations typically use it to create a consistent vocabulary across teams before layering more operational or management-oriented standards on top. This entry does not detail the specific relationships or requirements of those other standards, which should be reviewed directly.
Which roles and actors does ISO/IEC 29100 define, and how should we map them internally?
The standard defines privacy-related actors and roles as part of its conceptual model. When mapping internally, take care not to assume these labels align exactly with legal roles such as data controller and data processor under the EU or UK GDPR, since the standard's terminology and statutory role definitions are distinct. Map framework actors to your legal roles deliberately, and document the reasoning so accountability can be evidenced rather than merely asserted.
How can we use the privacy principles in ISO/IEC 29100 within our governance program?
The privacy principles in ISO/IEC 29100 are typically used to structure policy, guide design decisions, and provide a common reference for privacy discussions across governance and engineering functions. Because governance concerns ownership, stewardship, and policy while security addresses confidentiality, integrity, and availability, the principles can inform governance without replacing distinct security controls. Any use should be supported by demonstrable evidence, as accountability generally requires records rather than stated intent.
What does ISO/IEC 29100 not cover that we still need to address separately?
As a foundational framework, ISO/IEC 29100 generally does not resolve jurisdiction-specific obligations, cross-border transfer mechanics, retention rules, lawful bases for processing, or enforcement penalties. It also does not, on its own, determine whether a data protection impact assessment is required or provide operational security controls. These matters must be addressed under the applicable laws and standards for your context, and this entry does not describe those specifics.

Common misconceptions

Adopting ISO/IEC 29100 makes an organization compliant with the GDPR or other privacy laws.
ISO/IEC 29100 is a framework and terminology standard, not a legal instrument. Aligning with it does not, on its own, satisfy the requirements of the EU GDPR, UK GDPR, CCPA/CPRA, HIPAA, or any other regime. Compliance depends on jurisdiction, context, and demonstrable implementation of applicable legal obligations.
The PII controller and PII processor roles in ISO/IEC 29100 are the same as the data controller and data processor under the GDPR.
The roles are conceptually similar but defined within the standard's own framework. The specific obligations, accountability, and liability attached to controllers and processors are set by applicable law and differ across regimes, so the standard's definitions should not be treated as a substitute for statutory roles.
ISO/IEC 29100 is a certifiable standard against which an organization can be audited.
ISO/IEC 29100 is a foundational framework standard rather than a management system specification. Certification is generally pursued against management-oriented standards that build on it, not against ISO/IEC 29100 itself.

Best practices

Use ISO/IEC 29100 for its common privacy terminology and role definitions to promote consistent internal language, but map those terms back to the statutory definitions that apply in your jurisdiction rather than assuming equivalence.
Treat the standard's privacy principles as design and governance guidance that informs system development, while separately identifying and documenting the lawful basis and legal obligations required by applicable regulation.
When applying the PII controller and PII processor roles, explicitly reconcile them with the controller and processor obligations under the relevant law so that accountability for each party is clearly assigned and demonstrable with evidence.
Position ISO/IEC 29100 as the conceptual foundation for management-oriented standards such as ISO/IEC 27701, and pursue certification or assurance against those specifications rather than against 29100 itself.
Do not represent alignment with ISO/IEC 29100 as evidence of compliance; maintain separate, jurisdiction-specific records that demonstrate how legal requirements are met.
Recognize the standard's scope limits: it does not address cross-border transfer mechanics, retention rules, enforcement penalties, or specific security control implementation, so supplement it with instruments that cover those areas.