EN ISO/IEC 29134:2020/prA1
(Amendment)Information technology - Security techniques - Guidelines for privacy impact assessment - Amendment 1 (ISO/IEC 29134:2017/DAM 1:2022)
Information technology - Security techniques - Guidelines for privacy impact assessment - Amendment 1 (ISO/IEC 29134:2017/DAM 1:2022)
2022-11-08: WI abandoned to follow cancellation of WI in ISO (notification from ISO to dataservice on 2022-11-08
Informationstechnik - Sicherheitsverfahren - Leitlinien für die Datenschutz-Folgenabschätzung - Änderung 1 (ISO/IEC 29134:2017/DAM 1:2022)
Technologies de l'information - Techniques de sécurité - Lignes directrices pour l'étude d'impacts sur la vie privée - Amendement 1 (ISO/IEC 29134:2017/DAM 1:2022)
Informacijska tehnologija - Varnostne tehnike - Smernice za ocenjevanje vpliva na zasebnost - Dopolnilo A1 (ISO/IEC 29134:2017/DAM 1:2022)
General Information
- Status
- Not Published
- Publication Date
- 10-Mar-2024
- Technical Committee
- CEN/CLC/TC 13 - Cybersecurity and Data Protection
- Drafting Committee
- CEN/CLC/JTC 13/WG 5 - Data Protection, Privacy and Identity Management
- Current Stage
- 4098 - Decision to abandon - Enquiry
- Start Date
- 08-Nov-2022
- Completion Date
- 11-Feb-2026
Relations
- Effective Date
- 08-Dec-2021
Overview
EN ISO/IEC 29134:2020/prA1 is a draft amendment to the established international standard providing guidelines for privacy impact assessment (PIA) in information technology and security techniques. Issued by CEN and developed in alignment with ISO/IEC 29134:2017, this document proposes updates and clarifications for organizations implementing privacy risk assessments. While development of this amendment was eventually discontinued following ISO's cancellation notice in November 2022, the guidance and improvements captured in this draft remain relevant to professionals managing privacy compliance and personal data protection in IT systems.
Key Topics
This amendment addresses several key areas in the context of privacy impact assessments:
- Stakeholder Identification: Refining guidance to clarify the scope and scale relevant to PIAs, supporting better engagement with impacted parties.
- Privacy Risk Treatment Options: Updates to language for greater clarity in making organizational decisions about privacy risk management.
- Implementation of Privacy Risk Treatment: Adds precision around documentation such as user-facing privacy policies and privacy notices, emphasizing the importance of transparent communication with users.
- Privacy Roles: Expands references to organizational roles to include both privacy officers and data protection officers, reflecting diverse practices in privacy governance.
- PIA Public Summaries: Introduces editorial improvements to standardize public reporting of privacy impact assessments.
Applications
EN ISO/IEC 29134:2020/prA1 is intended for professionals responsible for privacy, information security, and data protection across industries that handle personally identifiable information (PII). The guidance supports:
- Privacy Engineering: Streamlining the integration of privacy considerations in IT project lifecycles from planning to deployment.
- Compliance Planning: Assisting in meeting regulatory requirements such as the GDPR and other global data protection laws through structured PIA processes.
- Transparency: Enabling organizations to provide clearer, user-facing documentation about privacy practices and risk mitigation strategies.
- Risk Management: Enhancing an organization’s ability to recognize, evaluate, and treat risks related to the collection, processing, and storage of personal data.
Organizations that conduct PIAs using the updated guidance from this draft can further improve risk communication, stakeholder trust, and compliance readiness.
Related Standards
Professionals applying EN ISO/IEC 29134:2020/prA1 should also consult the following standards for comprehensive privacy and security management:
- ISO/IEC 29100: Information technology - Security techniques - Privacy framework
- ISO/IEC 27001: Information security management systems - Requirements
- ISO/IEC 27701: Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management
- ISO/IEC 29151: Code of practice for personally identifiable information protection
By aligning with these international best practices and the refinements suggested in this draft amendment, organizations can optimize their approach to privacy impact assessments and data protection strategies.
Keywords: EN ISO/IEC 29134, privacy impact assessment, PIA, information technology, security techniques, privacy risk, compliance, data protection, privacy officer, user-facing privacy policy, international standards, CEN, ISO, PII, GDPR compliance
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

Bureau Veritas
Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

DNV
DNV is an independent assurance and risk management provider.
Sponsored listings
Frequently Asked Questions
EN ISO/IEC 29134:2020/prA1 is a draft published by the European Committee for Standardization (CEN). Its full title is "Information technology - Security techniques - Guidelines for privacy impact assessment - Amendment 1 (ISO/IEC 29134:2017/DAM 1:2022)". This standard covers: 2022-11-08: WI abandoned to follow cancellation of WI in ISO (notification from ISO to dataservice on 2022-11-08
2022-11-08: WI abandoned to follow cancellation of WI in ISO (notification from ISO to dataservice on 2022-11-08
EN ISO/IEC 29134:2020/prA1 is classified under the following ICS (International Classification for Standards) categories: 35.030 - IT Security. The ICS classification helps identify the subject area and facilitates finding related standards.
EN ISO/IEC 29134:2020/prA1 has the following relationships with other standards: It is inter standard links to EN ISO/IEC 29134:2020. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.
EN ISO/IEC 29134:2020/prA1 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
SLOVENSKI STANDARD
01-julij-2022
Informacijska tehnologija - Varnostne tehnike - Smernice za ocenjevanje vpliva na
zasebnost - Dopolnilo A1 (ISO/IEC 29134:2017/DAM 1:2022)
Information technology - Security techniques - Guidelines for privacy impact assessment
- Amendment 1 (ISO/IEC 29134:2017/DAM 1:2022)
Informationstechnik - Sicherheitsverfahren - Leitlinien für die Datenschutz-
Folgenabschätzung - Änderung 1 (ISO/IEC 29134:2017/DAM 1:2022)
Technologies de l'information - Techniques de sécurité - Lignes directrices pour l'étude
d'impacts sur la vie privée - Amendement 1 (ISO/IEC 29134:2017/DAM 1:2022)
Ta slovenski standard je istoveten z: EN ISO/IEC 29134:2020/prA1
ICS:
35.030 Informacijska varnost IT Security
SIST EN ISO/IEC en,fr,de
29134:2020/oprA1:2022
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
DRAFT AMENDMENT
ISO/IEC 29134:2017/DAM 1
ISO/IEC JTC 1/SC 27 Secretariat: DIN
Voting begins on: Voting terminates on:
2022-04-18 2022-07-11
Information technology — Security techniques —
Guidelines for privacy impact assessment
AMENDMENT 1
Technologies de l'information — Techniques de sécurité — Lignes directrices pour l'étude d'impacts sur la
vie privée
AMENDEMENT 1
ICS: 35.030
This document is circulated as received from the committee secretariat.
THIS DOCUMENT IS A DRAFT CIRCULATED
FOR COMMENT AND APPROVAL. IT IS
ISO/CEN PARALLEL PROCESSING
THEREFORE SUBJECT TO CHANGE AND MAY
NOT BE REFERRED TO AS AN INTERNATIONAL
STANDARD UNTIL PUBLISHED AS SUCH.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL,
TECHNOLOGICAL, COMMERCIAL AND
USER PURPOSES, DRAFT INTERNATIONAL
STANDARDS MAY ON OCCASION HAVE TO
BE CONSIDERED IN THE LIGHT OF THEIR
POTENTIAL TO BECOME STANDARDS TO
WHICH REFERENCE MAY BE MADE IN
Reference number
NATIONAL REGULATIONS.
ISO/IEC 29134:2017/DAM 1:2022(E)
RECIPIENTS OF THIS DRAFT AR
...




Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.
Loading comments...