ISO/IEC 29100
ISO/IEC 29100 is an international standard that sets out a high-level framework for protecting personally identifiable information (PII) in information and communication technology systems. It establishes a shared vocabulary for privacy and describes the different actors involved in handling PII and the roles they play. It is a foundational reference document rather than a certifiable or prescriptive control set.
ISO/IEC 29100 is an International Standard (originally published as ISO/IEC 29100:2011 and revised as ISO/IEC 29100:2024) that provides a high-level privacy framework for the protection of personally identifiable information (PII) within information and communication technology environments. It specifies common privacy terminology, defines the actors and their roles in processing PII, describes privacy safeguarding considerations, and provides references to known privacy principles. As a framework and terminology standard, it is intended to be foundational and is commonly used alongside other standards in the ISO/IEC privacy family; it does not itself constitute a certifiable management system, nor does it prescribe specific technical or organizational controls, mandate particular lawful bases, or address the mechanics of cross-border transfers, retention rules, or enforcement. Note that ISO/IEC 29100 uses the term PII, which is defined within the standard's own terminology and should not be assumed identical to definitions of personal data or special category data under instruments such as the EU GDPR or UK GDPR. This entry covers scope and purpose only and is not a substitute for reading the standard text.
Why it matters
ISO/IEC 29100 matters because privacy work across organizations, jurisdictions, and disciplines frequently breaks down over inconsistent vocabulary. When legal, security, engineering, and governance teams use the same word to mean different things, controls are misapplied and accountability becomes ambiguous. By specifying a common privacy terminology and defining the actors involved in processing personally identifiable information (PII) and the roles they play, the standard provides a shared reference point that other documents in the ISO/IEC privacy family can build upon.
Because it is a high-level framework and terminology standard rather than a certifiable management system, its value is foundational rather than operational. It does not prescribe specific technical or organizational controls, does not mandate a lawful basis for processing, and does not address the mechanics of cross-border transfers, retention, or enforcement. Organizations should therefore treat it as a starting vocabulary and conceptual scaffold, not as a compliance deliverable in itself. Adopting its terminology does not, on its own, demonstrate compliance with any particular regulation.
A further point of caution for expert readers: ISO/IEC 29100 uses the term PII, which is defined within the standard's own terminology and should not be assumed identical to the definitions of personal data or special category data under instruments such as the EU GDPR or UK GDPR. Mapping the standard's concepts onto a specific legal regime requires deliberate interpretation rather than one-to-one substitution.
Who it's relevant to
Inside ISO/IEC 29100
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 29100.