📋

ISO/IEC 29134

Information technology - Security techniques - Guidelines for privacy impact assessment

Organization: ISO/IEC Category: Privacy Assessment
2
Related Articles
4
Articles with Obligations
6
Key Sections
8
Coverage Areas

Overview

Provides guidelines for a process to assess privacy impacts and treat privacy risks. Directly supports GDPR Article 35 DPIA requirements with methodology for identifying and mitigating privacy risks in processing operations.

Applicability

Data Protection Impact Assessments (DPIAs) required by GDPR Article 35

Relevance to General Data Protection Regulation (GDPR)

Essential for GDPR Article 35 DPIA compliance - provides methodology and documentation framework

Key Coverage Areas

1
Privacy impact assessment methodology
2
Risk identification for personal data processing
3
Privacy risk assessment and evaluation
4
Risk treatment and mitigation
5
DPIA documentation requirements
6
Consultation with data protection authorities
7
High-risk processing identification
8
Privacy-preserving measures

Standard Sections & Chapters

6

Privacy impact assessment process

7

Privacy risk identification

8

Privacy risk assessment

9

Privacy risk treatment

Annex A

DPIA report template

Annex B

Examples of processing requiring DPIA

Related General Data Protection Regulation (GDPR) Articles

Article 25: Data protection by design and by default

View Article →
Sections: 6, 7

Privacy impact assessment in design phase

Implementation Guidance:

Conduct DPIA during system design to identify and mitigate privacy risks

Article 35: Data protection impact assessment

View Article →
Sections: 6, 7, 8, 9, Annex A

DPIA methodology and process

Implementation Guidance:

Conduct DPIAs for high-risk processing using ISO 29134 methodology including risk assessment, treatment, and documentation

Mapped Obligations:

  • Conduct a Data Protection Impact Assessment (DPIA) before high-risk processing activities
  • Perform DPIA for automated decision-making, large-scale processing of sensitive data, or systematic monitoring of public areas
  • Follow supervisory authority lists of processing requiring or not requiring DPIAs
  • Review and update the DPIA when risks change

Quick Information

Organization
ISO/IEC
Category
Privacy Assessment
Certification
Not available

🤝 Still Feeling Overwhelmed?

EU cybersecurity laws can be complex. Our free tools and guides work great for most people, but if you're dealing with something particularly challenging or have tight deadlines, we're here to help.