ISO/IEC 29134:2023
Evidence request list. 43 controls, 43 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Analysis
Describe processing systematically including purposes, lawful basis, PII categories, recipients, retention, and transfers.
- systematic processing description
- data flow diagrams
- retention schedule extract
- transfer mechanisms list
- lawful basis described as legitimate interests without LIA
- retention generic across PII categories
- transfers not enumerated
Assess necessity and proportionality of processing including alternatives considered and rejected.
- necessity analysis
- proportionality assessment
- alternatives considered log
- minimisation outcomes
- proportionality assumed not assessed
- no alternatives documented
- less intrusive options not analysed
Consult with internal stakeholders, PII principals or their representatives, and other relevant parties.
- consultation plan
- consultation records
- feedback log
- incorporation decisions
- PII principals not consulted (only internal)
- consultations not documented
- feedback not addressed in PIA
Clause 1-4: Introduction and Context
Defines the scope of guidance on concepts, objectives, and processes for governance of information security
- Scope statement
- Concept reference
- Definitions glossary
- Governance charter
- Scope unclear
- Concepts not adopted
- Glossary outdated
- Charter inactive
Key terms including governance, governing body, information security, and management
- Scope statement
- Concept reference
- Definitions glossary
- Governance charter
- Scope unclear
- Concepts not adopted
- Glossary outdated
- Charter inactive
Fundamental concepts of information security governance and its relationship to organizational governance
- Scope statement
- Concept reference
- Definitions glossary
- Governance charter
- Scope unclear
- Concepts not adopted
- Glossary outdated
- Charter inactive
Guidelines for a process on privacy impact assessments and structure and content of a PIA report
- PIA template
- DPIA report
- Privacy risk register
- Mitigation plan
- PIA skipped at design
- DPIA shallow
- Risk catalogue incomplete
- Mitigations not tracked
Privacy impact assessment terminology including PII, privacy risk, and PIA report
- PIA template
- DPIA report
- Privacy risk register
- Mitigation plan
- PIA skipped at design
- DPIA shallow
- Risk catalogue incomplete
- Mitigations not tracked
General overview of PIA process, its purpose, and relationship to other privacy management activities
- PIA template
- DPIA report
- Privacy risk register
- Mitigation plan
- PIA skipped at design
- DPIA shallow
- Risk catalogue incomplete
- Mitigations not tracked
Clause 5: PIA Initiation and Scope
Criteria and thresholds for determining when a privacy impact assessment is necessary
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Defining the scope of the assessment including systems, processes, and data flows to be assessed
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Identifying relevant stakeholders including data subjects, controllers, processors, and regulators
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Clause 6: Data Flow and Processing Analysis
Identifying and describing information flows and data processing activities involving PII
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Describing the nature, scope, context, and purposes of PII processing activities
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Analysing the legal basis and legitimacy of PII processing activities
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Clause 7: Privacy Risk Assessment
Identifying potential privacy risks to PII principals arising from the processing activities
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Assessing the potential impact and severity of identified privacy risks on individuals
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Assessing the likelihood of identified privacy risks materializing
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Evaluating identified risks against defined criteria to determine risk levels
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Clause 8: Privacy Risk Treatment
Selecting and implementing measures to mitigate, transfer, accept, or avoid identified privacy risks
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Selecting privacy controls and safeguards appropriate to the identified risk levels
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Assessing residual privacy risks after implementation of treatment measures
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Clause 9: PIA Report
Structure and content requirements for the privacy impact assessment report
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Documenting PIA findings, recommendations, and planned remediation actions
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Requirements for reviewing and updating the PIA when processing activities change
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Guidance on publishing PIA reports and communicating results to stakeholders
- Privacy impact assessment report
- Data flow diagrams and processing description
- PIA risk register and treatment plan
- Stakeholder consultation records
- Residual risk acceptance memo
- PIAs triggered late in project lifecycle
- Risk likelihood scoring is subjective and inconsistent
- Residual risk not formally accepted by accountable owner
- PIA outputs not refreshed when processing changes
Documentation
Produce a PIA report capturing process, findings, risks, treatments, residual risks, and conclusions.
- PIA report following template
- executive summary
- appendices with workshops and analyses
- version control
- report skips executive summary for non technical readers
- analyses not retained
- report not version controlled
Obtain formal approval from accountable parties including business owner, DPO, and where required senior management.
- sign off records
- approval workflow
- dissenting opinions log
- escalation evidence
- DPO sign off treated as approval rather than opinion
- no record of dissent or conditions
- approval before treatment commitments
Share PIA outcomes with stakeholders including, where appropriate, publication of summaries to support transparency.
- sharing decisions document
- published summaries
- stakeholder distribution log
- redaction rationale
- PIAs treated as confidential by default
- no summary for PII principals
- redaction not justified
Implementation
Track implementation of PIA action plan with status reporting and exception management.
- implementation status reports
- milestone evidence
- exception requests and approvals
- completion confirmations
- status reporting stops before completion
- exceptions granted without DPO consultation
- completion not verified
Review and update the PIA periodically and on trigger events such as processing changes, new risks, or incidents.
- review schedule
- trigger event register
- PIA version history
- update justification documents
- reviews skipped after initial PIA
- minor changes not triggering review
- no version history retained
Where residual high risk remains, consult with the supervisory authority prior to processing.
- prior consultation submissions
- regulator responses
- implementation of regulator advice
- consultation decision criteria
- high residual risk processed without consultation
- regulator advice not implemented
- decision criteria undocumented
Initiation
Identify processing activities requiring a PIA based on threshold criteria including new technology, large scale processing, or special categories.
- PIA threshold criteria document
- screening questionnaires
- triggered PIA register
- exemption justifications
- screening only at project gate (not for changes)
- criteria narrower than GDPR Article 35
- exemptions without DPO sign off
Define PIA scope including processing operations, PII categories, actors, lifecycle phases, and jurisdictions.
- scope statement
- in scope and out of scope documentation
- boundary diagrams
- stakeholder list
- scope limited to data fields not full lifecycle
- third party processing excluded
- stakeholders not identified
Compose PIA team with privacy, legal, security, business, and technical expertise plus DPO involvement.
- team charter
- role assignments
- DPO advisory record
- skills coverage matrix
- security expertise absent
- DPO consulted at end only
- business owner not engaged
Programme
Establish a PIA programme with templates, training, tooling, and continuous improvement to scale across the organisation.
- PIA programme charter
- templates and tooling
- training completion records
- maturity self assessments
- PIAs ad hoc per project (no programme)
- templates inconsistent across business units
- no maturity tracking
Risk Assessment
Identify privacy risks to PII principals across the processing lifecycle using systematic methods.
- risk identification workshops
- threat scenarios specific to PII principals
- risk catalogue
- feared events list
- risks framed from organisation view not individual harm
- feared events not enumerated
- scenarios miss insider threats
Assess likelihood of risks materialising considering threat sources, vulnerabilities, and existing controls.
- likelihood scale
- threat source analysis
- vulnerability inventory
- control coverage assessment
- likelihood scale only qualitative without descriptors
- external threat sources omitted
- control effectiveness assumed
Assess severity of risks to PII principals considering tangible and intangible harms and vulnerability of individuals.
- severity scale with harm types
- vulnerability factors (minors, employees, patients)
- harm scenarios
- severity calibration
- severity only considers data sensitivity not consequence
- vulnerable populations not flagged
- intangible harms (discrimination, distress) ignored
Evaluate risks against documented criteria distinguishing high risks requiring prior consultation with supervisory authority.
- risk evaluation criteria
- risk register with ratings
- high risk determinations
- supervisory authority consultation triggers
- criteria not approved by accountable owner
- high risk threshold inconsistent with regulator guidance
- consultations not triggered
Treatment
Identify measures to address identified risks including controls, design changes, and process modifications.
- treatment measures register
- design change specifications
- control implementations
- responsibility assignments
- measures generic (encryption, training)
- design changes not specific
- responsibility assignments missing deadlines
Recalculate and document residual risks after planned treatment measures with formal acceptance.
- residual risk register
- before and after risk ratings
- acceptance records
- DPO opinion
- residual ratings assumed equal to inherent minus 1
- acceptance signer lacks authority
- DPO opinion not solicited
Document an action plan for treatment measures with owners, deadlines, dependencies, and success indicators.
- action plan with owners and dates
- dependency map
- success indicators
- tracking dashboard
- plans lack success indicators
- dependencies not mapped
- no tracking beyond initial assignment
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.