Privacy and protection of PII
Purpose
Identify and meet the requirements for preserving privacy and protecting PII under applicable laws, regulations and contracts.
How to meet this control
In short: Identify and meet requirements for the protection of personal data.
- Step 01Publish a privacy and PII protection policy and appoint a responsible person such as a privacy officer
- Step 02Map where PII lives across systems and SaaS and align handling with the Privacy Act and Australian Privacy Principles (and GDPR where relevant)
- Step 03Implement technical and organisational measures (access control, encryption, minimisation) to protect PII
- Step 04Document procedures for data subject rights, consent and breach notification
- Step 05Account for legal restrictions on collecting, processing, transferring and deleting PII, including cross-border transfer
Tip: Map where PII lives and align with your privacy law (e.g. the Privacy Act / GDPR).
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Establish and communicate a topic-specific policy on privacy and PII protection
- ›Develop procedures for preserving privacy and share them with everyone involved in processing PII
- ›Appoint a responsible person, such as a privacy officer, to guide staff and partners
- ›Define responsibilities for handling PII in light of relevant legislation
- ›Implement appropriate technical and organisational measures to protect PII
- ›Account for national laws that restrict collecting, processing, transferring or deleting PII
- ›Consider restrictions on transferring PII to other countries
Audit evidence to keep
- - Privacy policy and a named privacy officer or accountable person
- - Data map or PII inventory showing where personal data is held
- - Procedures for data subject requests, consent and breach notification
- - Evidence of technical measures protecting PII (access controls, encryption)
Common mistakes
- - Classifying data once and never reviewing it
- - Allowing sensitive data into test or AI tools without approval
- - Keeping data after the business or legal need has expired
Owner, cadence, and proof
Assign one accountable owner for A.5.34. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.