Skip to main content
Category: Breach and Risk Assessment

ISO/IEC 29134

Also known as: ISO/IEC 29134:2023, ISO/IEC 29134:2017
Simply put

ISO/IEC 29134 is an international standard that offers guidance on how to carry out a privacy impact assessment, which is a structured review of how a project or system might affect people's privacy. It also describes what a privacy impact assessment report should contain and how it should be organized. It is a guidance document rather than a certifiable set of requirements, so following it does not by itself demonstrate legal compliance in any jurisdiction.

Formal definition

ISO/IEC 29134 provides guidelines for a process to conduct privacy impact assessments (PIAs) and for the structure and content of a PIA report. In its 2017 edition, it is intended for use where the privacy impact on personally identifiable information (PII) principals arises from processes, information systems, or programmes. As an ISO/IEC guidance standard it describes recommended practice and does not establish auditable requirements or confer certification; practitioners should note that it does not map directly onto the specific obligations of any given legal regime, such as the data protection impact assessment provisions found in EU or UK GDPR, and that whether a PIA or DPIA is legally mandated is determined by the applicable law rather than by this standard. This entry does not address cross-border transfer mechanisms, retention rules, enforcement, or the interaction of PIAs with other instruments such as ISO/IEC 27701.

Why it matters

Privacy impact assessments are a cornerstone of demonstrable accountability, and ISO/IEC 29134 gives organisations a recognised, internationally developed reference for how such an assessment can be conducted and documented. Because it addresses both the process of assessing privacy impacts on PII principals and the structure and content of the resulting report, it helps organisations move from ad hoc or inconsistent reviews toward a repeatable, comparable practice that a reviewer or stakeholder can follow and challenge.

It is important to be precise about what the standard does and does not do. ISO/IEC 29134 is a guidance document, not a set of auditable requirements, and it does not confer certification. Following it does not by itself demonstrate legal compliance in any jurisdiction. In particular, whether an organisation is legally obliged to carry out a privacy impact assessment, or a data protection impact assessment under the EU or UK GDPR, is determined by the applicable law and the specifics of the processing, not by this standard. A data protection impact assessment is not always mandatory, and the standard's structure does not map directly onto the specific obligations of any given legal regime.

Its value therefore lies in supporting good practice and consistency rather than in guaranteeing an outcome. Organisations that adopt it should treat it as one input into their broader accountability and governance approach, recognising that demonstrable accountability generally requires evidence of the assessment actually performed and the decisions taken, not merely the adoption of a standard's framework.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy leads can use ISO/IEC 29134 as a reference for designing and documenting a consistent PIA process. They should, however, separately confirm whether a DPIA is legally mandated for a given processing activity under the applicable regime, since the standard does not determine that and does not map directly onto GDPR obligations.
Privacy engineers and project teams
Teams building processes, information systems, or programmes that affect PII principals can draw on the standard's guidance for how to assess privacy impacts and how to structure the resulting report. It offers a repeatable format but does not replace legal analysis or organisation-specific policy requirements.
Information governance and compliance functions
Governance and compliance teams seeking to demonstrate accountability can adopt the standard's process and report structure as part of their evidence base. They should note that following guidance is not the same as demonstrating legal compliance, which depends on jurisdiction, context, and evidence of the assessment actually carried out.
Auditors and assurance reviewers
Reviewers assessing an organisation's PIA practice may use ISO/IEC 29134 as a benchmark for good practice, while recognising that it is a guidance standard that does not confer certification and does not establish auditable requirements against which formal conformity can be certified.

Inside ISO/IEC 29134

Privacy Impact Assessment (PIA) guidelines
ISO/IEC 29134 provides guidelines for conducting a privacy impact assessment, offering a structured process and methodology for identifying, analyzing, and evaluating privacy risks arising from the processing of personally identifiable information (PII). It is a guidance standard rather than a certifiable requirements standard.
Process orientation
The standard describes the PIA as a process spanning preparation, performance, and follow-up, typically including scoping the assessment, identifying stakeholders, analyzing information flows, assessing risks to individuals, and identifying treatment measures. It frames the PIA as iterative rather than a one-time exercise.
Risk to individuals (data subjects)
ISO/IEC 29134 orients its risk analysis toward potential impacts on the individuals whose PII is processed, which is a distinct emphasis from information security risk frameworks that primarily consider risk to the organization. This focus on impact to natural persons aligns conceptually with regulatory risk assessment expectations, though the standard itself is not a legal instrument.
Relationship to a data protection impact assessment (DPIA)
The PIA methodology in ISO/IEC 29134 can support, but is not the same as, a DPIA required under the EU GDPR or UK GDPR. A DPIA is a specific regulatory obligation with its own triggering criteria and content requirements; following ISO/IEC 29134 does not by itself satisfy any particular statutory requirement.
Reporting and documentation
The standard addresses the structure and content of a PIA report, supporting the ability to demonstrate that privacy risks were considered. This contributes to accountability evidence within a governance program but does not replace an organization's own legally mandated records.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 29134.

Does following ISO/IEC 29134 mean a data protection impact assessment is always required?
No. ISO/IEC 29134 provides guidelines for conducting a privacy impact assessment, but it does not by itself determine when one is legally mandatory. Whether an assessment is required depends on the applicable regime and the specific processing context. Under the EU GDPR, for example, an impact assessment is generally required only where processing is likely to result in a high risk to individuals, and the criteria differ across jurisdictions such as the UK GDPR or other frameworks. The standard can support how you perform an assessment, but it does not replace the legal triggering analysis, which remains a context-dependent obligation.
Is a privacy impact assessment under ISO/IEC 29134 the same as a records of processing activities obligation?
No, these are distinct. A privacy impact assessment as described in ISO/IEC 29134 is a risk assessment process focused on identifying and mitigating privacy risks arising from a specific processing operation or system. A records of processing activities obligation, by contrast, is a separate accountability requirement in certain regimes to document processing activities, and it is not the same as running an impact assessment. They may draw on overlapping information, but completing one does not discharge the other, and neither should be equated with simply deploying an inventory tool.
At what point in a project should we apply ISO/IEC 29134 guidance?
The guidance generally supports assessing privacy risk early, ideally before processing begins or before a new system or change is deployed, so that identified risks can influence design decisions. In practice, assessments are often revisited when processing purposes, data flows, or risk factors change materially. The standard describes an assessment process rather than dictating precise timing under any specific law, so alignment with the timing requirements of your applicable regime remains a separate consideration and is out of scope for the standard itself.
Who should be involved in an assessment conducted using ISO/IEC 29134?
The guidance generally contemplates input from those who understand the processing, the data flows, and the associated risks, which typically involves collaboration across roles such as the party accountable for the processing, privacy or data protection functions, security functions, and relevant business or technical owners. Where a controller and a processor are both involved, responsibilities for contributing to and acting on the assessment should be clearly allocated. Accountability generally requires demonstrable evidence of who performed which steps, not merely stated intent. The standard does not assign specific legal roles, which are defined by the applicable regime.
What kind of documentation or evidence should an assessment produce?
A privacy impact assessment following this guidance typically results in a documented record of the processing considered, the privacy risks identified, the assessment of those risks, and the measures selected to address them. Because accountability under governance frameworks generally requires demonstrable evidence rather than stated intent, retaining a clear, dated, and reviewable record is advisable. The standard focuses on the assessment process and its outputs; it does not prescribe retention periods for that documentation or enforcement consequences, which fall outside its scope and depend on the applicable regime.
How does ISO/IEC 29134 relate to information security controls we already have in place?
The guidance addresses privacy risk assessment, which overlaps with but is not the same as information security. Security controls typically address confidentiality, integrity, and availability, whereas a privacy impact assessment considers risks to individuals arising from the processing of personal data more broadly, including risks that may persist even where security controls are strong. The two are complementary: existing security measures can inform the risk analysis and mitigation choices, but implementing security controls does not by itself constitute a privacy impact assessment. Note also that measures such as encryption or tokenization generally do not render data non-personal.

Common misconceptions

Following ISO/IEC 29134 automatically satisfies the DPIA obligation under the GDPR.
ISO/IEC 29134 is a guidance standard that can inform a DPIA methodology, but a DPIA under the EU GDPR or UK GDPR is a distinct regulatory requirement with its own triggering conditions and content criteria. A DPIA is not always mandatory; it is generally required only where processing is likely to result in a high risk to individuals. Conformance with the standard does not, on its own, establish compliance with any specific legal regime.
ISO/IEC 29134 is a certifiable requirements standard against which an organization can be audited for conformance.
It provides guidelines and a recommended methodology rather than mandatory requirements. Organizations use it to structure their assessment approach, but it functions as guidance and should not be treated as equivalent to a certification standard such as those written in requirements ('shall') language.
A privacy impact assessment is the same as an information security risk assessment.
The PIA methodology in ISO/IEC 29134 focuses on risks to individuals arising from PII processing, which is a governance-and-privacy orientation, whereas a security risk assessment focuses on confidentiality, integrity, and availability risks to the organization's assets. The two overlap where security controls mitigate privacy risks, but they address different subjects and should not be collapsed into one another.

Best practices

Treat ISO/IEC 29134 as a methodology to structure a privacy impact assessment, and separately confirm whether a legally mandated DPIA is triggered under the applicable regime, since the standard does not determine statutory obligations.
Scope each PIA explicitly, documenting the processing activities, information flows, and stakeholders covered, so that the assessment's boundaries and any out-of-scope areas are clear and defensible.
Center the risk analysis on potential impacts to the individuals whose PII is processed, keeping this distinct from organizational information security risk while noting where security controls mitigate privacy risk.
Produce and retain a documented PIA report to support demonstrable accountability, recognizing that this evidence supplements rather than replaces any legally required records the organization must maintain.
Revisit the PIA iteratively when processing purposes, data flows, or risk profiles change, rather than treating it as a one-time deliverable.
Coordinate the PIA process with the parties accountable for the processing so that risk treatment decisions and their ownership are recorded and can be evidenced, not merely stated as intent.