ISO/IEC 29100 Privacy Framework
ISO/IEC 29100 is an international standard that provides a high-level framework for protecting personal information within information and communication technology (ICT) systems. It sets out a common vocabulary for privacy, identifies the different actors involved in handling personal data and their roles, and helps organizations work out what privacy safeguards they need. It is a voluntary framework rather than a law, so following it does not by itself establish legal compliance under regimes such as the GDPR.
ISO/IEC 29100 (originally published in 2011, with a second edition published in 2024) specifies a high-level privacy framework for the protection of personally identifiable information (PII) within an ICT environment. According to the standard, it specifies a common privacy terminology, defines the actors and their roles in processing PII, and is intended to help organizations define their privacy safeguarding requirements related to PII. As a framework standard it operates at a conceptual and organizational level rather than prescribing detailed technical controls, and it uses the terminology of PII and PII actors, which differs from the GDPR's controller/processor and personal data terminology; practitioners should map its concepts to applicable legal frameworks rather than treat conformance as legal compliance. The specific structural contents and any changes between the 2011 and 2024 editions should be verified against the current official ISO/IEC text.
Why it matters
ISO/IEC 29100 matters because it establishes a shared vocabulary for privacy across international boundaries and technical disciplines. Privacy work frequently breaks down when engineers, lawyers, and business stakeholders use terms inconsistently, or when organizations operating across multiple jurisdictions lack a neutral reference point. By specifying a common privacy terminology and defining the actors and their roles in processing personally identifiable information (PII), the framework gives multinational and cross-functional teams a stable conceptual foundation on which to build more detailed privacy programs.
Equally important is understanding what the framework does not do. ISO/IEC 29100 is a voluntary international standard, not a law, and conformance with it does not by itself establish legal compliance under regimes such as the GDPR. It also uses the terminology of PII and PII actors, which does not map one-to-one onto the GDPR's concepts of personal data, controllers, and processors. Treating adherence to the framework as equivalent to legal compliance would be a mistake; the framework is best understood as a structuring and communication tool that must be mapped to the applicable legal requirements in each jurisdiction.
Because the framework operates at a high, conceptual level rather than prescribing detailed technical controls, its value is typically realized when it is used alongside more specific standards, guidance, and legal analysis. Practitioners should also note that a second edition was published in 2024 following the original 2011 edition; the specific structural contents and any changes between editions should be verified against the current official ISO/IEC text rather than assumed.
Who it's relevant to
Inside ISO/IEC 29100
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 29100.