Phone: (011) 7541-421, 3409-301, 3409-335, 6547-293, 3409-310
E-mail: Standards sales: prodaja@iss.rs Education: iss-edukacija@iss.rs Information about standards: infocentar@iss.rs
Stevana Brakusa 2, 11030 Beograd
Main menu

ISO/IEC 29151:2026

Information security, cybersecurity and privacy protection — Controls, requirements, and guidance for personally identifiable information protection

Jul 24, 2026

General information

60.60     Jul 24, 2026

ISO/IEC

ISO/IEC JTC 1/SC 27

International Standard

35.030  

English   French  

Buying

Published

Language in which you want to receive the document.

Scope

This document specifies controls, purpose, and guidance for implementing controls, to meet the requirements identified by a risk and impact assessment related to the protection of personally identifiable information (PII).
In particular, this document specifies requirements and guidance based on ISO/IEC 27002, taking into consideration the controls for processing PII that can be applicable within the context of an organization's information security risk environment(s).
This document is applicable to all types and sizes of organizations acting as PII controllers (as defined in ISO/IEC 29100), including public and private companies, government entities and not-for-profit organizations that process PII, in particular, organizations that do not establish or operate a privacy information management system.

Life cycle

PREVIOUSLY

WITHDRAWN
ISO/IEC 29151:2017

NOW

PUBLISHED
ISO/IEC 29151:2026
60.60 Standard published
Jul 24, 2026

National adoptions

Information security, cybersecurity and privacy protection - Controls, requirements, and guidance for personally identifiable information protection (ISO/IEC FDIS 29151:2025)

50.60   Close of voting. Proof returned by secretariat

I224 more