SIST EN ISO/IEC 29134:2020/oprA1:2022
(Amendment)Information technology - Security techniques - Guidelines for privacy impact assessment - Amendment 1 (ISO/IEC 29134:2017/DAM 1:2022)
Information technology - Security techniques - Guidelines for privacy impact assessment - Amendment 1 (ISO/IEC 29134:2017/DAM 1:2022)
2022-11-08: WI abandoned to follow cancellation of WI in ISO (notification from ISO to dataservice on 2022-11-08
Informationstechnik - Sicherheitsverfahren - Leitlinien für die Datenschutz-Folgenabschätzung - Änderung 1 (ISO/IEC 29134:2017/DAM 1:2022)
Technologies de l'information - Techniques de sécurité - Lignes directrices pour l'étude d'impacts sur la vie privée - Amendement 1 (ISO/IEC 29134:2017/DAM 1:2022)
Informacijska tehnologija - Varnostne tehnike - Smernice za ocenjevanje vpliva na zasebnost - Dopolnilo A1 (ISO/IEC 29134:2017/DAM 1:2022)
General Information
- Status
- Not Published
- Public Enquiry End Date
- 07-Jul-2022
- Technical Committee
- ITC - Information technology
- Current Stage
- 98 - Abandoned project (Adopted Project)
- Start Date
- 16-Jan-2023
- Due Date
- 21-Jan-2023
- Completion Date
- 16-Jan-2023
Relations
- Effective Date
- 08-Dec-2021
Overview
SIST EN ISO/IEC 29134:2020/oprA1:2022 is an important amendment to the international standard ISO/IEC 29134:2017, titled Information technology - Security techniques - Guidelines for privacy impact assessment. This draft amendment 1 (DAM 1:2022) provides updated guidance on conducting privacy impact assessments (PIAs), which are vital for organizations to evaluate and mitigate privacy risks associated with their information systems. Although the work item was ultimately abandoned following cancellation at the ISO level, the document outlines key refinements intended to support privacy risk management under evolving regulatory and technological environments.
Key Topics
This amendment addresses several specific enhancements to existing PIA guidelines:
- Clarification of Terms: Revisions in terminology such as replacing “PII” (Personally Identifiable Information) with “PIA” in the context of scope and scale improve clarity in privacy documentation.
- Implementation Guidance Updates: Modifications in sections like stakeholder identification and privacy risk treatment better reflect organizational responsibilities and processes.
- Privacy Documentation: Adjusted references emphasize the use of user-facing privacy policies and notices rather than generic statements, aligning with best practices for transparency.
- Role Specification: Explicit inclusion of both privacy officers and data protection officers ensures accountability structures accommodate varying organizational setups.
- Textual Corrections: Minor textual edits, for example, changing “intents” to “intends,” enhance the overall precision of the standard.
These updates are intended to enhance the practical utility of the PIA guidance, fostering more consistent and effective privacy impact assessments.
Applications
Organizations implementing privacy impact assessments benefit from this amendment by gaining:
- Improved Privacy Risk Management: Clearer guidance helps companies systematically identify, evaluate, and treat privacy risks throughout the data lifecycle.
- Enhanced Compliance Readiness: Aligning PIA processes with updated standards supports compliance with data protection regulations such as GDPR, which emphasize accountability and transparency.
- Better Stakeholder Engagement: Refinements on identifying and involving stakeholders aid in comprehensive privacy evaluations, increasing trust among users and regulators.
- Tailored Privacy Communications: Focusing on user-facing privacy notices ensures that data subjects receive clear, accessible information about how their data is handled.
- Robust Organizational Roles: Defining responsibilities involving privacy officers contributes to effective governance and oversight of privacy practices.
These practical applications are crucial for sectors handling sensitive or personal data, including IT services, healthcare, finance, and governmental agencies.
Related Standards
SIST EN ISO/IEC 29134:2020/oprA1:2022 relates closely to other privacy and security standards, including:
- ISO/IEC 27001 - Information security management systems: Provides a framework for managing security risks which complements privacy impact assessments.
- ISO/IEC 27552 - Privacy Information Management System: Focuses on privacy governance and management aligned with PIA guidelines.
- GDPR and other data protection laws: The amendment’s guidance supports compliance by ensuring privacy impacts are systematically considered and addressed.
- ISO/IEC 29100 - Privacy framework: Offers high-level principles that underpin detailed PIA methodologies.
Together, these standards form an integrated approach to protecting personal data and supporting organizational privacy commitments.
Keywords: privacy impact assessment, PIA guidelines, ISO/IEC 29134 amendment, data protection, privacy risk treatment, privacy policies, information security, privacy officer, GDPR compliance
Frequently Asked Questions
SIST EN ISO/IEC 29134:2020/oprA1:2022 is a draft published by the Slovenian Institute for Standardization (SIST). Its full title is "Information technology - Security techniques - Guidelines for privacy impact assessment - Amendment 1 (ISO/IEC 29134:2017/DAM 1:2022)". This standard covers: 2022-11-08: WI abandoned to follow cancellation of WI in ISO (notification from ISO to dataservice on 2022-11-08
2022-11-08: WI abandoned to follow cancellation of WI in ISO (notification from ISO to dataservice on 2022-11-08
SIST EN ISO/IEC 29134:2020/oprA1:2022 is classified under the following ICS (International Classification for Standards) categories: 35.030 - IT Security. The ICS classification helps identify the subject area and facilitates finding related standards.
SIST EN ISO/IEC 29134:2020/oprA1:2022 has the following relationships with other standards: It is inter standard links to SIST EN ISO/IEC 29134:2020. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.
You can purchase SIST EN ISO/IEC 29134:2020/oprA1:2022 directly from iTeh Standards. The document is available in PDF format and is delivered instantly after payment. Add the standard to your cart and complete the secure checkout process. iTeh Standards is an authorized distributor of SIST standards.
Standards Content (Sample)
SLOVENSKI STANDARD
01-julij-2022
Informacijska tehnologija - Varnostne tehnike - Smernice za ocenjevanje vpliva na
zasebnost - Dopolnilo A1 (ISO/IEC 29134:2017/DAM 1:2022)
Information technology - Security techniques - Guidelines for privacy impact assessment
- Amendment 1 (ISO/IEC 29134:2017/DAM 1:2022)
Informationstechnik - Sicherheitsverfahren - Leitlinien für die Datenschutz-
Folgenabschätzung - Änderung 1 (ISO/IEC 29134:2017/DAM 1:2022)
Technologies de l'information - Techniques de sécurité - Lignes directrices pour l'étude
d'impacts sur la vie privée - Amendement 1 (ISO/IEC 29134:2017/DAM 1:2022)
Ta slovenski standard je istoveten z: EN ISO/IEC 29134:2020/prA1
ICS:
35.030 Informacijska varnost IT Security
SIST EN ISO/IEC en,fr,de
29134:2020/oprA1:2022
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
DRAFT AMENDMENT
ISO/IEC 29134:2017/DAM 1
ISO/IEC JTC 1/SC 27 Secretariat: DIN
Voting begins on: Voting terminates on:
2022-04-18 2022-07-11
Information technology — Security techniques —
Guidelines for privacy impact assessment
AMENDMENT 1
Technologies de l'information — Techniques de sécurité — Lignes directrices pour l'étude d'impacts sur la
vie privée
AMENDEMENT 1
ICS: 35.030
This document is circulated as received from the committee secretariat.
THIS DOCUMENT IS A DRAFT CIRCULATED
FOR COMMENT AND APPROVAL. IT IS
ISO/CEN PARALLEL PROCESSING
THEREFORE SUBJECT TO CHANGE AND MAY
NOT BE REFERRED TO AS AN INTERNATIONAL
STANDARD UNTIL PUBLISHED AS SUCH.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL,
TECHNOLOGICAL, COMMERCIAL AND
USER PURPOSES, DRAFT INTERNATIONAL
STANDARDS MAY ON OCCASION HAVE TO
BE CONSIDERED IN THE LIGHT OF THEIR
POTENTIAL TO BECOME STANDARDS TO
WHICH REFERENCE MAY BE MADE IN
Reference number
NATIONAL REGULATIONS.
ISO/IEC 29134:2017/DAM 1:2022(E)
RECIPIENTS OF THIS DRAFT AR
...










Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.
Loading comments...