Skip to content

Evidence request lists

ISO/IEC 29100:2024

Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Application

ISO29100-6.1
Privacy Safeguarding Requirements Identification

Identify privacy safeguarding requirements from legal, regulatory, contractual, and business sources.

Artefacts an auditor will ask for
  • requirements register by source
  • legal interpretation memos
  • contract privacy clauses
  • business privacy goals
Where this commonly fails
  • contractual obligations from customers not captured
  • requirements register stale
  • conflicting requirements unresolved
ISO29100-6.2
Privacy Risk Factors

Assess privacy risk factors including PII categories, processing operations, technology, and PII principal context.

Artefacts an auditor will ask for
  • risk factor catalogue
  • DPIAs for high risk processing
  • context analysis per processing activity
  • technology risk assessments
Where this commonly fails
  • risk factors generic not contextual
  • PII principal vulnerabilities ignored (minors, employees)
  • tech risk assessed only at deployment
ISO29100-6.3
Controls Selection and Implementation

Select and implement privacy controls that operationalise principles considering risk factors and requirements.

Artefacts an auditor will ask for
  • control catalogue mapped to principles
  • implementation evidence per control
  • control testing results
  • exceptions register
Where this commonly fails
  • controls map to security only not privacy principles
  • implementation evidence stale
  • exceptions never reviewed
ISO29100-6.4
Privacy by Design and Default

Embed privacy into design of systems, services, and processes with privacy protective defaults.

Artefacts an auditor will ask for
  • privacy by design checklists
  • default settings documentation
  • design review records
  • PIA at design phase
Where this commonly fails
  • defaults favour data sharing
  • design reviews skip privacy
  • privacy bolted on post launch
ISO29100-6.5
Cross Border PII Transfer Controls

Apply appropriate controls and legal mechanisms for cross border PII transfers including transfer impact assessments.

Artefacts an auditor will ask for
  • transfer register
  • SCCs or adequacy assessments
  • transfer impact assessments
  • supplementary measures documentation
Where this commonly fails
  • TIA not performed post Schrems II
  • supplementary measures generic
  • onward transfers from processor not tracked
ISO29100-6.6
Breach Management

Establish PII breach detection, assessment, notification, and remediation procedures.

Artefacts an auditor will ask for
  • breach response plan
  • notification templates
  • regulator and PII principal notification logs
  • post incident reviews
Where this commonly fails
  • 72 hour notification capability untested
  • PII principal notification thresholds unclear
  • no breach simulations
ISO29100-6.7
Third Party Privacy Governance

Govern PII processors and third parties through contracts, due diligence, and ongoing oversight.

Artefacts an auditor will ask for
  • processor due diligence records
  • DPAs
  • ongoing assurance reports
  • subprocessor approval workflow
Where this commonly fails
  • DPAs missing required clauses
  • no ongoing oversight after onboarding
  • subprocessor changes not approved

Clause 1-3: Framework Introduction

29100-1
Scope

Defines the scope of the privacy framework for protection of PII within ICT systems

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-2
Normative references

References to supporting standards and guidelines

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-3
Terms and definitions

Common privacy terminology including PII, PII principal, PII controller, and PII processor

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls

Clause 4: Privacy Framework Components

29100-4.1
Actors and roles

Defines four main actors: PII principals, PII controllers, PII processors, and third parties and their roles

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-4.2
Interactions between actors

Describes how actors interact in the processing of personally identifiable information

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-4.3
Privacy safeguarding requirements

Privacy safeguarding considerations for organizations processing PII in ICT systems

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls

Clause 5: Privacy Safeguarding Considerations

29100-5.1
Recognizing PII

Guidance on recognizing and identifying personally identifiable information in ICT systems

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-5.2
Regulatory factors

Consideration of legal, regulatory, and contractual factors affecting privacy safeguarding

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-5.3
Privacy risk factors

Identifying and assessing privacy risk factors in ICT systems and services

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls

Clause 6: Privacy Principles - Foundational (Principles 1-4)

29100-6.1
Consent and choice

Presenting PII principals with clear choice and obtaining consent for processing their PII

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-6.2
Purpose legitimacy and specification

Ensuring processing purposes are legitimate, specified, and communicated to PII principals

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-6.3
Collection limitation

Limiting the collection of PII to what is within the bounds of applicable law and strictly necessary

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-6.4
Data minimization

Minimizing PII processing to what is adequate, relevant, and not excessive for the specified purposes

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls

Clause 6: Privacy Principles - Governance (Principles 9-11)

29100-6.10
Information security

Protecting PII under the organization's authority with appropriate security safeguards

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-6.11
Privacy compliance

Verifying and demonstrating compliance with privacy requirements through auditing and assessment

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-6.9
Accountability

Assigning accountability for PII processing and demonstrating compliance with privacy principles

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls

Clause 6: Privacy Principles - Operational (Principles 5-8)

29100-6.5
Use, retention and disclosure limitation

Limiting the use, retention, and disclosure of PII to what is necessary for specified purposes

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-6.6
Accuracy and quality

Ensuring PII is accurate, complete, and kept up-to-date for the purposes of use

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-6.7
Openness, transparency and notice

Providing clear and accessible information about privacy policies, procedures, and practices

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls
29100-6.8
Individual participation and access

Giving PII principals the ability to access and review their PII and challenge its accuracy

Artefacts an auditor will ask for
  • Privacy framework policy
  • PII inventory and classification register
  • Consent records and notices
  • Roles matrix for PII controllers and processors
  • Privacy compliance evidence file
Where this commonly fails
  • PII inventory missing third-party data flows
  • Consent records cannot be linked to processing purpose
  • Accountability roles not assigned per principle
  • No mapping from principles to operational controls

Foundation

ISO29100-5.1
PII Actor Identification

Identify the nine PII actors including principals, controllers, processors, and third parties for each processing activity.

Artefacts an auditor will ask for
  • actor register per processing activity
  • controller and processor designations
  • joint controller arrangements
  • third party register
Where this commonly fails
  • sub processor chain incomplete
  • joint controllership undocumented
  • PII principal categories not segmented
ISO29100-5.2
PII and Sensitive PII Categorisation

Categorise PII and sensitive PII with definitions appropriate to jurisdictions and processing context.

Artefacts an auditor will ask for
  • PII classification scheme
  • sensitive PII inventory
  • jurisdictional definitions table
  • data dictionary
Where this commonly fails
  • sensitive PII definition uses only GDPR special categories
  • biometric and genetic data not flagged for all jurisdictions
  • inferred data not classified

Principles

ISO29100-5.10.1
Consent and Choice Principle

Provide PII principals with clear, prominent, freely given consent options and meaningful choice over processing.

Artefacts an auditor will ask for
  • consent capture records
  • consent management platform logs
  • withdrawal workflows
  • consent UI screenshots
Where this commonly fails
  • bundled consent across purposes
  • withdrawal harder than granting
  • no granular choice for non essential processing
ISO29100-5.10.10
Information Security

Protect PII with appropriate technical and organisational security controls proportionate to risk.

Artefacts an auditor will ask for
  • security control register
  • encryption inventory
  • access control records
  • incident response plan
Where this commonly fails
  • controls selected without privacy risk reference
  • encryption gaps for backups
  • access reviews infrequent
ISO29100-5.10.11
Privacy Compliance

Verify and demonstrate compliance with privacy obligations through controls, audits, and corrective action.

Artefacts an auditor will ask for
  • compliance assessment reports
  • regulatory inventory
  • corrective action plans
  • external audit certificates
Where this commonly fails
  • compliance assessed only against home jurisdiction
  • corrective actions not tracked to closure
  • no independent assurance
ISO29100-5.10.2
Purpose Legitimacy and Specification

Specify purposes for PII processing at or before collection with legitimate basis aligned to law and context.

Artefacts an auditor will ask for
  • purpose register
  • lawful basis assessments
  • purpose specification in notices
  • secondary use approvals
Where this commonly fails
  • purposes too broad (improving services)
  • secondary use without compatibility test
  • lawful basis missing for legitimate interests
ISO29100-5.10.3
Collection Limitation

Limit collection of PII to that which is necessary for specified purposes within legal bounds.

Artefacts an auditor will ask for
  • data minimisation reviews
  • form field justifications
  • collection audits
  • necessity assessments
Where this commonly fails
  • legacy form fields collected without purpose review
  • voluntary fields not labelled optional
  • no periodic minimisation review
ISO29100-5.10.4
Data Minimisation

Minimise PII processing, retention, and disclosure to the strict minimum necessary for the specified purpose.

Artefacts an auditor will ask for
  • retention schedules
  • deletion logs
  • access on need to know matrix
  • anonymisation evidence
Where this commonly fails
  • retention indefinite (just in case)
  • deletion logs absent or unverifiable
  • access not need to know
ISO29100-5.10.5
Use, Retention, and Disclosure Limitation

Limit use, retention, and disclosure of PII to specified purposes with retention periods defined and enforced.

Artefacts an auditor will ask for
  • use restriction policy
  • retention schedule with legal basis
  • disclosure register
  • automated deletion evidence
Where this commonly fails
  • retention legal basis not documented
  • disclosures to law enforcement not logged
  • automated deletion broken
ISO29100-5.10.6
Accuracy and Quality

Ensure PII is accurate, complete, up to date, adequate, and relevant for the purpose throughout the lifecycle.

Artefacts an auditor will ask for
  • data quality metrics
  • correction workflows
  • validation rules
  • rectification request logs
Where this commonly fails
  • accuracy assumed for self reported data
  • no proactive verification cadence
  • rectification requests not propagated to all systems
ISO29100-5.10.7
Openness, Transparency, and Notice

Provide clear, accessible information to PII principals about processing including purposes, recipients, and rights.

Artefacts an auditor will ask for
  • privacy notice
  • layered notice design
  • just in time notices
  • readability assessments
Where this commonly fails
  • notice not layered
  • just in time notices missing at collection points
  • third party recipients not named
ISO29100-5.10.8
Individual Participation and Access

Enable PII principals to access, correct, and challenge processing of their PII through documented procedures.

Artefacts an auditor will ask for
  • rights request workflow
  • identity verification procedures
  • response time metrics
  • appeal mechanism
Where this commonly fails
  • identity verification overly burdensome
  • response times exceed legal deadlines
  • no appeal route for denials
ISO29100-5.10.9
Accountability

Demonstrate accountability through documented policies, training, audits, and assignment of responsibility.

Artefacts an auditor will ask for
  • privacy management programme document
  • training completion records
  • audit reports
  • RACI for privacy
Where this commonly fails
  • accountability documentation incomplete
  • no internal audit cycle
  • training generic not role based
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.