Skip to main content
Category: Privacy Governance & Design

ISO/IEC 29100 Privacy Framework

Also known as: ISO/IEC 29100, ISO 29100, Privacy Framework (ISO/IEC 29100)
Simply put

ISO/IEC 29100 is an international standard that provides a high-level framework for protecting personal information within information and communication technology (ICT) systems. It sets out a common vocabulary for privacy, identifies the different actors involved in handling personal data and their roles, and helps organizations work out what privacy safeguards they need. It is a voluntary framework rather than a law, so following it does not by itself establish legal compliance under regimes such as the GDPR.

Formal definition

ISO/IEC 29100 (originally published in 2011, with a second edition published in 2024) specifies a high-level privacy framework for the protection of personally identifiable information (PII) within an ICT environment. According to the standard, it specifies a common privacy terminology, defines the actors and their roles in processing PII, and is intended to help organizations define their privacy safeguarding requirements related to PII. As a framework standard it operates at a conceptual and organizational level rather than prescribing detailed technical controls, and it uses the terminology of PII and PII actors, which differs from the GDPR's controller/processor and personal data terminology; practitioners should map its concepts to applicable legal frameworks rather than treat conformance as legal compliance. The specific structural contents and any changes between the 2011 and 2024 editions should be verified against the current official ISO/IEC text.

Why it matters

ISO/IEC 29100 matters because it establishes a shared vocabulary for privacy across international boundaries and technical disciplines. Privacy work frequently breaks down when engineers, lawyers, and business stakeholders use terms inconsistently, or when organizations operating across multiple jurisdictions lack a neutral reference point. By specifying a common privacy terminology and defining the actors and their roles in processing personally identifiable information (PII), the framework gives multinational and cross-functional teams a stable conceptual foundation on which to build more detailed privacy programs.

Equally important is understanding what the framework does not do. ISO/IEC 29100 is a voluntary international standard, not a law, and conformance with it does not by itself establish legal compliance under regimes such as the GDPR. It also uses the terminology of PII and PII actors, which does not map one-to-one onto the GDPR's concepts of personal data, controllers, and processors. Treating adherence to the framework as equivalent to legal compliance would be a mistake; the framework is best understood as a structuring and communication tool that must be mapped to the applicable legal requirements in each jurisdiction.

Because the framework operates at a high, conceptual level rather than prescribing detailed technical controls, its value is typically realized when it is used alongside more specific standards, guidance, and legal analysis. Practitioners should also note that a second edition was published in 2024 following the original 2011 edition; the specific structural contents and any changes between editions should be verified against the current official ISO/IEC text rather than assumed.

Who it's relevant to

Data protection officers and privacy program leads
DPOs and privacy leads can use the framework's common terminology and role definitions to structure privacy governance consistently across teams and jurisdictions. It is most useful as an organizing reference, but it should be mapped to the specific legal obligations that apply, since conformance does not by itself demonstrate compliance with regimes such as the GDPR.
Engineers and systems architects
Because the framework addresses PII within an ICT environment, engineers can draw on it to align on shared privacy concepts and actor roles when designing systems. It operates at a conceptual level rather than prescribing detailed technical controls, so teams will typically pair it with more specific standards and internal requirements to implement concrete safeguards.
Compliance and standards teams in multinational organizations
Organizations operating across jurisdictions can use the neutral, internationally recognized vocabulary of ISO/IEC 29100 to create a common baseline for privacy discussions. Teams should treat it as a foundation to be mapped onto applicable national and regional laws, and should verify current framework contents against the official ISO/IEC text, noting that a second edition was published in 2024 after the 2011 original.
Legal advisers and counsel
Counsel advising on privacy can reference the framework's terminology and role concepts when translating technical and organizational arrangements into legal analysis. It is important to distinguish the framework's PII and PII-actor concepts from the distinct controller, processor, and personal data concepts under the GDPR, and to avoid presenting conformance as legal compliance.

Inside ISO/IEC 29100

Privacy Principles
ISO/IEC 29100 sets out a set of privacy principles intended to guide the design, implementation, and operation of information and communication technology systems that process personally identifiable information (PII). These principles are framework-level and technology-neutral; they inform practice rather than impose legal obligations. Practitioners should verify the current published text of the standard for the exact enumeration and wording of the principles.
PII (Personally Identifiable Information) Terminology
The framework uses the term PII, which is broadly comparable in intent to the GDPR concept of personal data but is defined within the ISO standard's own terminology and should not be assumed to be identical in scope. Where the standard's definitions and the GDPR's Article 4 definitions differ, the applicable legal definition governs for compliance purposes.
Actor Roles (PII Principal, PII Controller, PII Processor, Third Party)
ISO/IEC 29100 describes actors involved in PII processing using its own role vocabulary. These roles are conceptually related to, but distinct from, the GDPR roles of data subject, controller, and processor. The standard's roles are descriptive for framework purposes and do not by themselves determine legal accountability under the GDPR, which is assessed against the Regulation and applicable guidance.
Privacy Safeguarding Requirements
The framework addresses the identification of privacy safeguarding requirements arising from factors such as legal and regulatory obligations, business needs, and risk. It positions these requirements as inputs to system design and to the selection of controls, without prescribing specific technical measures.
Framework and Reference Nature
ISO/IEC 29100 functions as a high-level privacy framework rather than a certifiable management system standard or a legal instrument. It is intended to provide common terminology and a structured approach that can be used alongside, and mapped to, other standards and applicable law.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 29100.

Does implementing ISO/IEC 29100 make an organization GDPR compliant?
No. ISO/IEC 29100 is a voluntary international standard providing a privacy framework and common terminology; it is not a legal instrument and does not itself confer compliance with the GDPR or any other data protection law. Legal compliance depends on satisfying the specific obligations of the applicable regime (for example, identifying a valid Article 6 basis, meeting transparency and data subject rights requirements, and any additional conditions for special category data). The framework can support a compliance program by structuring privacy governance, but conformity with the standard and legal compliance are distinct questions that should be assessed separately.
Is ISO/IEC 29100 the same as a certification an organization can be audited against?
Not in the way some certifiable management-system standards are. ISO/IEC 29100 sets out privacy principles and a framework rather than a set of certifiable requirements on its own. Organizations often use it alongside related standards in the same family for management systems or controls. Whether and how conformity can be formally certified depends on the specific standard and the certification scheme involved, so readers should verify the current scope and status of any certification claim against the official standards and the relevant scheme documentation.
How does ISO/IEC 29100 relate to the roles and terminology used in the GDPR?
ISO/IEC 29100 uses its own defined terminology, which does not map one-to-one onto GDPR concepts. For example, the framework's actor terminology and its use of the term for identifiable individuals differ from the GDPR's defined roles of controller and processor and its concept of the data subject. When applying the framework in an EU context, organizations typically need to translate the framework's terms into the applicable legal definitions to avoid conflating distinct roles or obligations. Treat the standard's vocabulary as a common reference point rather than a substitute for the legal definitions that govern your obligations.
How can an organization use the privacy principles in ISO/IEC 29100 within an existing compliance program?
The principles can generally be used as a structuring layer to organize privacy governance, inform internal policies, and provide a shared vocabulary across legal, compliance, and engineering teams. In most cases organizations map the framework's principles to their existing legal obligations and internal controls, so that each principle is supported by a documented control and, where required, a lawful basis under the applicable regime. The framework does not replace the need to perform legally mandated activities such as any required impact assessments; it can help organize the surrounding process. Confirm alignment against the current official standard text.
Can ISO/IEC 29100 help with cross-border transfer decisions?
Only indirectly. The framework can help organizations describe and document privacy considerations, but it is not a transfer mechanism and does not authorize international data transfers. Under the GDPR, transfers depend on tools such as adequacy decisions, standard contractual clauses, binding corporate rules, or other recognized mechanisms, often accompanied by a case-by-case transfer risk assessment and any supplementary measures. These mechanisms and their status evolve over time. The standard may support internal governance around transfers, but transfer legality should be assessed against the current legal requirements rather than the framework itself.
How does ISO/IEC 29100 fit with other standards in the same family?
It is commonly used as a foundational reference that other privacy-related standards build upon, providing shared concepts and terminology. Organizations frequently combine it with related standards addressing management systems or specific controls, using the framework's principles as an organizing structure while relying on the more detailed standards for implementable requirements. Because the composition and current versions of these standards can change, readers should verify the specific standards they intend to use and how they interrelate against the current official publications.

Common misconceptions

Adopting ISO/IEC 29100 makes an organisation GDPR compliant.
The framework is voluntary guidance that can support privacy governance, but it does not establish GDPR compliance. Compliance is assessed against the GDPR text, applicable national implementing law, and regulator guidance, and is context and risk dependent. Alignment with the framework should be treated as one input to a compliance programme, not as a substitute for it.
The framework's terms (PII, PII controller, PII processor) mean exactly the same as the GDPR's defined terms.
The ISO standard defines its own terminology, which overlaps in intent with GDPR concepts but is not necessarily coextensive. For legal purposes the GDPR's own definitions apply, and roles and accountability under the Regulation are determined independently of the framework's descriptive vocabulary.
ISO/IEC 29100 is a certification against which an organisation can be audited for compliance.
It is a framework providing terminology and principles rather than a certifiable management system specification. Practitioners should verify the current status, scope, and any related standards in the ISO/IEC 29100 family against the official published texts, as the standards landscape can evolve.

Best practices

Map the framework's actor roles and PII terminology to the applicable legal definitions (for example GDPR Article 4 roles) so that legal accountability is determined against the Regulation rather than assumed from the framework's vocabulary.
Use ISO/IEC 29100 as a structuring aid for privacy governance while maintaining a separate, documented assessment of legal obligations under the GDPR and any relevant national implementing law.
Verify the current published text of ISO/IEC 29100 and any related standards before relying on specific principles or definitions, as the wording and scope may have been updated.
Treat the framework's privacy safeguarding requirements as inputs to design decisions, and record how each requirement was derived from legal, business, and risk considerations to support accountability.
Avoid presenting alignment with the framework as evidence of full compliance in internal or external communications; describe it qualitatively as one supporting element of the wider compliance programme.
Where the framework's guidance and applicable law appear to diverge, document the difference and ensure the legal position governs the outcome, seeking specialist advice where the boundary is unclear.