ISO/IEC 29100:2024
Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Application
Identify privacy safeguarding requirements from legal, regulatory, contractual, and business sources.
- requirements register by source
- legal interpretation memos
- contract privacy clauses
- business privacy goals
- contractual obligations from customers not captured
- requirements register stale
- conflicting requirements unresolved
Assess privacy risk factors including PII categories, processing operations, technology, and PII principal context.
- risk factor catalogue
- DPIAs for high risk processing
- context analysis per processing activity
- technology risk assessments
- risk factors generic not contextual
- PII principal vulnerabilities ignored (minors, employees)
- tech risk assessed only at deployment
Select and implement privacy controls that operationalise principles considering risk factors and requirements.
- control catalogue mapped to principles
- implementation evidence per control
- control testing results
- exceptions register
- controls map to security only not privacy principles
- implementation evidence stale
- exceptions never reviewed
Embed privacy into design of systems, services, and processes with privacy protective defaults.
- privacy by design checklists
- default settings documentation
- design review records
- PIA at design phase
- defaults favour data sharing
- design reviews skip privacy
- privacy bolted on post launch
Apply appropriate controls and legal mechanisms for cross border PII transfers including transfer impact assessments.
- transfer register
- SCCs or adequacy assessments
- transfer impact assessments
- supplementary measures documentation
- TIA not performed post Schrems II
- supplementary measures generic
- onward transfers from processor not tracked
Establish PII breach detection, assessment, notification, and remediation procedures.
- breach response plan
- notification templates
- regulator and PII principal notification logs
- post incident reviews
- 72 hour notification capability untested
- PII principal notification thresholds unclear
- no breach simulations
Govern PII processors and third parties through contracts, due diligence, and ongoing oversight.
- processor due diligence records
- DPAs
- ongoing assurance reports
- subprocessor approval workflow
- DPAs missing required clauses
- no ongoing oversight after onboarding
- subprocessor changes not approved
Clause 1-3: Framework Introduction
Defines the scope of the privacy framework for protection of PII within ICT systems
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
References to supporting standards and guidelines
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Common privacy terminology including PII, PII principal, PII controller, and PII processor
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Clause 4: Privacy Framework Components
Defines four main actors: PII principals, PII controllers, PII processors, and third parties and their roles
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Describes how actors interact in the processing of personally identifiable information
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Privacy safeguarding considerations for organizations processing PII in ICT systems
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Clause 5: Privacy Safeguarding Considerations
Guidance on recognizing and identifying personally identifiable information in ICT systems
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Consideration of legal, regulatory, and contractual factors affecting privacy safeguarding
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Identifying and assessing privacy risk factors in ICT systems and services
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Clause 6: Privacy Principles - Foundational (Principles 1-4)
Presenting PII principals with clear choice and obtaining consent for processing their PII
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Ensuring processing purposes are legitimate, specified, and communicated to PII principals
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Limiting the collection of PII to what is within the bounds of applicable law and strictly necessary
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Minimizing PII processing to what is adequate, relevant, and not excessive for the specified purposes
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Clause 6: Privacy Principles - Governance (Principles 9-11)
Protecting PII under the organization's authority with appropriate security safeguards
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Verifying and demonstrating compliance with privacy requirements through auditing and assessment
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Assigning accountability for PII processing and demonstrating compliance with privacy principles
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Clause 6: Privacy Principles - Operational (Principles 5-8)
Limiting the use, retention, and disclosure of PII to what is necessary for specified purposes
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Ensuring PII is accurate, complete, and kept up-to-date for the purposes of use
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Providing clear and accessible information about privacy policies, procedures, and practices
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Giving PII principals the ability to access and review their PII and challenge its accuracy
- Privacy framework policy
- PII inventory and classification register
- Consent records and notices
- Roles matrix for PII controllers and processors
- Privacy compliance evidence file
- PII inventory missing third-party data flows
- Consent records cannot be linked to processing purpose
- Accountability roles not assigned per principle
- No mapping from principles to operational controls
Foundation
Identify the nine PII actors including principals, controllers, processors, and third parties for each processing activity.
- actor register per processing activity
- controller and processor designations
- joint controller arrangements
- third party register
- sub processor chain incomplete
- joint controllership undocumented
- PII principal categories not segmented
Categorise PII and sensitive PII with definitions appropriate to jurisdictions and processing context.
- PII classification scheme
- sensitive PII inventory
- jurisdictional definitions table
- data dictionary
- sensitive PII definition uses only GDPR special categories
- biometric and genetic data not flagged for all jurisdictions
- inferred data not classified
Principles
Provide PII principals with clear, prominent, freely given consent options and meaningful choice over processing.
- consent capture records
- consent management platform logs
- withdrawal workflows
- consent UI screenshots
- bundled consent across purposes
- withdrawal harder than granting
- no granular choice for non essential processing
Protect PII with appropriate technical and organisational security controls proportionate to risk.
- security control register
- encryption inventory
- access control records
- incident response plan
- controls selected without privacy risk reference
- encryption gaps for backups
- access reviews infrequent
Verify and demonstrate compliance with privacy obligations through controls, audits, and corrective action.
- compliance assessment reports
- regulatory inventory
- corrective action plans
- external audit certificates
- compliance assessed only against home jurisdiction
- corrective actions not tracked to closure
- no independent assurance
Specify purposes for PII processing at or before collection with legitimate basis aligned to law and context.
- purpose register
- lawful basis assessments
- purpose specification in notices
- secondary use approvals
- purposes too broad (improving services)
- secondary use without compatibility test
- lawful basis missing for legitimate interests
Limit collection of PII to that which is necessary for specified purposes within legal bounds.
- data minimisation reviews
- form field justifications
- collection audits
- necessity assessments
- legacy form fields collected without purpose review
- voluntary fields not labelled optional
- no periodic minimisation review
Minimise PII processing, retention, and disclosure to the strict minimum necessary for the specified purpose.
- retention schedules
- deletion logs
- access on need to know matrix
- anonymisation evidence
- retention indefinite (just in case)
- deletion logs absent or unverifiable
- access not need to know
Limit use, retention, and disclosure of PII to specified purposes with retention periods defined and enforced.
- use restriction policy
- retention schedule with legal basis
- disclosure register
- automated deletion evidence
- retention legal basis not documented
- disclosures to law enforcement not logged
- automated deletion broken
Ensure PII is accurate, complete, up to date, adequate, and relevant for the purpose throughout the lifecycle.
- data quality metrics
- correction workflows
- validation rules
- rectification request logs
- accuracy assumed for self reported data
- no proactive verification cadence
- rectification requests not propagated to all systems
Provide clear, accessible information to PII principals about processing including purposes, recipients, and rights.
- privacy notice
- layered notice design
- just in time notices
- readability assessments
- notice not layered
- just in time notices missing at collection points
- third party recipients not named
Enable PII principals to access, correct, and challenge processing of their PII through documented procedures.
- rights request workflow
- identity verification procedures
- response time metrics
- appeal mechanism
- identity verification overly burdensome
- response times exceed legal deadlines
- no appeal route for denials
Demonstrate accountability through documented policies, training, audits, and assignment of responsibility.
- privacy management programme document
- training completion records
- audit reports
- RACI for privacy
- accountability documentation incomplete
- no internal audit cycle
- training generic not role based
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.