ISO/IEC 29134
ISO/IEC 29134 is an international standard that offers guidance on how to carry out a privacy impact assessment, which is a structured review of how a project or system might affect people's privacy. It also describes what a privacy impact assessment report should contain and how it should be organized. It is a guidance document rather than a certifiable set of requirements, so following it does not by itself demonstrate legal compliance in any jurisdiction.
ISO/IEC 29134 provides guidelines for a process to conduct privacy impact assessments (PIAs) and for the structure and content of a PIA report. In its 2017 edition, it is intended for use where the privacy impact on personally identifiable information (PII) principals arises from processes, information systems, or programmes. As an ISO/IEC guidance standard it describes recommended practice and does not establish auditable requirements or confer certification; practitioners should note that it does not map directly onto the specific obligations of any given legal regime, such as the data protection impact assessment provisions found in EU or UK GDPR, and that whether a PIA or DPIA is legally mandated is determined by the applicable law rather than by this standard. This entry does not address cross-border transfer mechanisms, retention rules, enforcement, or the interaction of PIAs with other instruments such as ISO/IEC 27701.
Why it matters
Privacy impact assessments are a cornerstone of demonstrable accountability, and ISO/IEC 29134 gives organisations a recognised, internationally developed reference for how such an assessment can be conducted and documented. Because it addresses both the process of assessing privacy impacts on PII principals and the structure and content of the resulting report, it helps organisations move from ad hoc or inconsistent reviews toward a repeatable, comparable practice that a reviewer or stakeholder can follow and challenge.
It is important to be precise about what the standard does and does not do. ISO/IEC 29134 is a guidance document, not a set of auditable requirements, and it does not confer certification. Following it does not by itself demonstrate legal compliance in any jurisdiction. In particular, whether an organisation is legally obliged to carry out a privacy impact assessment, or a data protection impact assessment under the EU or UK GDPR, is determined by the applicable law and the specifics of the processing, not by this standard. A data protection impact assessment is not always mandatory, and the standard's structure does not map directly onto the specific obligations of any given legal regime.
Its value therefore lies in supporting good practice and consistency rather than in guaranteeing an outcome. Organisations that adopt it should treat it as one input into their broader accountability and governance approach, recognising that demonstrable accountability generally requires evidence of the assessment actually performed and the decisions taken, not merely the adoption of a standard's framework.
Who it's relevant to
Inside ISO/IEC 29134
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 29134.