SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.34Privacy and protection of personal identifiable information (PII)

Identify and meet your obligations to protect personal data, in line with applicable privacy laws and regulations. Mishandling personal data carries both legal and reputational cost.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0018Regulatory compliance · TechnicalrelatedSystem configuration that satisfies regulatory requirements automatically applies broadly, and privacy settings are one concrete case this control depends on being enforced technically.RCF-0043Data inventory · PolicyenablesRequiring that all personal and sensitive data be identified, located and owned gives a privacy program the starting inventory this control depends on.RCF-0355Privacy risk assessments (DPIA) · PolicysupportsA written commitment to assess privacy risk before new processing begins covers the DPIA trigger piece of this control, not the full range of PII protections A.5.34 requires, such as consent, transfers or rights handling.RCF-0356Privacy risk assessments (DPIA) · ProcesssupportsRunning a DPIA whenever the trigger is met, and letting its findings change the project's design before launch, turns the written commitment to assess privacy risk into a working practice.RCF-0357Privacy risk assessments (DPIA) · TechnicalenablesA structured template library standardises how privacy assessments are produced and kept current, making the assessments this control requires easier to run consistently.RCF-0358Consent & preference mgmt · PolicysupportsDefining in writing when consent is the legal basis, how it must be captured, and how withdrawal works as easily as giving it sets the policy A.5.34 needs for protecting personal data, though consent capture and enforcement still have to happen in practice.RCF-0359Consent & preference mgmt · ProcesssupportsCapturing recorded consent before processing starts, and honouring withdrawals everywhere the data flows, is what makes the consent policy's promise operate in daily practice rather than stay on paper.RCF-0360Consent & preference mgmt · TechnicalsupportsCentralised storage of consent preferences, checked automatically by every outbound channel, is what keeps consent enforcement from depending on someone remembering the rules.RCF-0361Data subject rights · PolicysupportsA written procedure naming who owns each step of an access, correction or deletion request gives staff a clear playbook instead of leaving rights requests to whoever happens to open the email.RCF-0362Data subject rights · ProcesssupportsVerifying identity, logging the request and tracking it against the one-month GDPR deadline is what turns the written rights procedure into requests that get answered on time, not lost in an inbox.RCF-0363Data subject rights · TechnicalenablesSystem capability to find, export, correct and delete an individual's data on request is what makes fulfilling data subject rights practical rather than a manual search.RCF-0364Privacy by design · PolicysupportsRequiring privacy questions to be answered before any new system or vendor goes live builds this control's protections into projects from the start rather than after launch.RCF-0365Privacy by design · ProcesssupportsRunning the privacy check as a routine step in every project keeps privacy by design an actual gate, not a principle stated in policy only.RCF-0366Privacy by design · TechnicalsupportsConfiguring systems so the privacy-protective option is the default, minimal fields, retention limits, opt-in sharing, is what privacy by design looks like at the technical level.RCF-0367Privacy notices · PolicysupportsA complete, plainly written privacy notice covering purposes, lawful bases and rights is the transparency piece of this control's obligations to individuals.RCF-0368Privacy notices · ProcesssupportsReviewing the privacy notice whenever processing changes keeps the published text matching what the company does with personal data.RCF-0369Privacy notices · TechnicalsupportsBuilding the privacy notice into every data collection point technically ensures individuals see it before data is gathered, not after.RCF-0370Cross-border transfers · PolicysupportsA written rule set stating when data may leave the EEA and which safeguard applies extends this control's obligations to international transfers.RCF-0371Cross-border transfers · ProcesssupportsVerifying a valid transfer safeguard at vendor onboarding and periodically after keeps cross-border data flows compliant with this control's requirements over time, not only at signature.RCF-0372Cross-border transfers · TechnicalenablesData residency and sharing settings that keep personal data in approved regions stop staff from casually moving data to unapproved destinations.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Privacy notice and consent records
The privacy information the company shows people before collecting their data (privacy notice / policy) and how consent is captured and respected.
Data subject rights procedure
The procedure for people to exercise their rights over their data (access, correction, deletion) and how those requests are handled on time.
DPIA and cross-border transfer records
The privacy impact assessments done before new data processing and the records of personal-data transfers to other countries.
From the Sekit evidence catalog

In practice

Privacy compliance usually breaks at the handoff points: consent captured on a signup form that the marketing team never checks before sending an email, or a subject access request that sits in an inbox past the GDPR one-month deadline. A working data subject rights procedure names who verifies identity, who pulls the data, and how the deadline is tracked. Privacy by design means answering data minimisation and retention questions before the first line of code, not bolting on a review afterward. Cross-border transfers need a current safeguard, standard contractual clauses or a Data Privacy Framework certification, verified at onboarding and periodically after.

Common gaps

Consent is captured on the signup form but marketing tools send campaigns without checking whether the person opted in.
Data subject access requests are handled informally by whoever receives the email, with no log of the one-month response deadline.
Vendors receiving personal data outside the EEA were never checked for a valid transfer safeguard at onboarding.

Questions your auditor will ask

How do you verify someone's identity before fulfilling a data subject request?
The data subject rights procedure requires identity verification through a defined method before any access, correction or deletion request is actioned.
What happens if a data subject request is not answered within a month?
Requests are logged with their receive date and tracked against the GDPR deadline, with an escalation if a response is at risk of being late.
Is privacy considered before a new tool or process goes live?
A privacy-by-design check runs as a routine step in project or vendor onboarding, producing a completed record before launch.
What safeguard applies when personal data is sent outside the EEA?
Vendors are checked at onboarding, and periodically after, for a current safeguard such as a signed standard contractual clause or a valid Data Privacy Framework certification.

Where regulation demands it

NIS2 2.1 requires a risk management framework, which privacy impact assessments extend to cover personal data processing specifically.
ENS mp.info.1 addresses personal data directly, requiring the protections this control's privacy program is built to deliver.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.34?”
Also via MCP, free with account