ISO standard for protecting personal data

September 2019 News & Events, Information Security

We are more connected than ever, bringing with it the joys, and risks, of our digital world. Cybersecurity is a growing concern, with attacks against business almost doubling over the last few years ( www.securitysa.com/*wf18a – redirects to http://reports.weforum.org/global-risks-2018/executive-summary/) and is an increasingly significant threat to global stability.

Unsurprisingly, laws and regulations are rapidly being put in place to reduce these risks and protect our digital privacy. How can organisations keep on top of these requirements and protect themselves at the same time? The world’s first international standard to help organisations manage privacy information and meet regulatory requirements has just been published.

Protecting our digital privacy is a significant business concern. According to IBM the average cost of a data breach is USD 3.6 million, and legal obligations are increasingly stringent ( www.securitysa.com/*ibm1 – redirects to https://www.ibm.com/downloads/cas/ZYKLN2E3).

As we get more connected, governments all over the world are introducing various privacy regulations, such as the European Union’s General Data Protection Regulation (GDPR), which organisations must adhere to. The new ISO standards will help businesses meet such requirements, whatever jurisdiction they work in.

ISO/IEC 27701, Security Techniques – Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management – Requirements and Guidelines, specifies the requirements for establishing, implementing, maintaining and continually improving a privacy-specific information security management system. In other words, a management system for protecting personal data (PIMS).

Formerly referred to as ISO/IEC 27552 during its development, it builds on ISO/IEC 27001, Information Technology – Security Techniques – Information Security Management Systems – Requirements, providing the necessary extra requirements when it comes to privacy.

Dr Andreas Wolf, Chair of the ISO technical committee that developed the standard, said almost every organisation processes personally identifiable information (PII), and protecting it is not only a legal requirement but a societal need.

“ISO/IEC 27701 defines processes and provides guidance for protecting PII on an ongoing, ever evolving basis. Because being a management system, it defines processes for continuous improvement on data protection, particularly important in a world where technology doesn’t stand still.”

ISO/IEC 27701 was developed by Working Group 5 of ISO technical committee ISO/IEC JTC1/SC 27, Information Security, Cybersecurity and Privacy Protection (the secretariat of which is held by DIN, ISO’s member for Germany), which is made up of experts from all over the world from data protection authorities, security agencies, academia and industry.

Matthieu Grall of the Commission Nationale de l’Informatique et des Libertés, the French independent watchdog for the protection of personal data, was an active participant of SC 27 and a contributor to the development of the standard. With increasingly stringent data protection requirements and laws, he said there is a real need for this standard.

“Despite the risks of not complying to these regulations, we know that many organisations are simply not ready and need guidance. With the number of complaints and fines related to privacy and data protection on the rise, the need for this standard is now obvious.

“Moreover, organisations need to bring trust to their authorities, partners, customers and employers. Such a standard will contribute strongly to this trust.”

For more information, go to www.iso.org





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

DeepAlert appoints Howard Harrison as CEO
DeepAlert News & Events AI & Data Analytics
DeepAlert has appointed Howard Harrison as chief executive officer. DeepAlert’s founder and CEO of the past six years, Dr Jasper Horrell, will transition into a newly created role as chief innovation officer.

Read more...
AI agent suite for control rooms
Milestone Systems News & Events Surveillance AI & Data Analytics
Visionplatform.ai announced the public launch of its new visionplatform.ai Agent Suite for Milestone XProtect, adding reasoning, context and assisted decision-making on top of existing video analytics and events — without sending video to the cloud.

Read more...
The global state of physical security
Genetec News & Events Infrastructure
Physical security has become a strategic business function, improving IT collaboration and decision-making. Moreover, interest in AI has more than doubled among users, and organisations seek flexibility to deploy workloads on-premises, in the cloud, or hybrid.

Read more...
AI cybersecurity predictions for 2026
AI & Data Analytics Information Security
The rapid development of AI is reshaping the cybersecurity landscape in 2026, for both individual users and businesses. Large language models (LLMs) are influencing defensive capabilities while simultaneously expanding opportunities for threat actors.

Read more...
SMARTpod Talks to Check Point Technologies about the African Perspectives on Cybersecurity report
SMART Security Solutions News & Events Information Security Videos
SMART Security Solutions spoke with Check Point's Hendrik de Bruin about the report, the risks African organisations face, and some mitigation measures.

Read more...
Beagle Watch named best security company in Johannesburg
News & Events Security Services & Risk Management
Beagle Watch Armed Response has been named Johannesburg’s Best Security Company in the 2025 Best of Joburg Awards, surpassing about 26 nominated private security firms in the greater Johannesburg region, thanks to overwhelming public support.

Read more...
Entries for the 2026 Southern Africa OSPAs now open
News & Events
Entries are now open through to 1 April 2026 for the Southern Africa Outstanding Security Performance Awards (OSPAs). This year, the awards are open to a broader range of countries in southern Africa than ever before.

Read more...
Grand theft telematics
News & Events
At its Security Analyst Summit 2025, Kaspersky presented the results of a security audit that exposed a significant security flaw enabling unauthorised access to all connected vehicles of one automotive manufacturer.

Read more...
Who are you?
Access Control & Identity Management Information Security
Who are you? This question may seem strange, but it can only be answered accurately by implementing an Identity and Access Management (IAM) system, a crucial component of any company’s security strategy.

Read more...
Check Point launches African Perspectives on Cybersecurity report
News & Events Information Security
Check Point Software Technologies released its African Perspectives on Cybersecurity Report 2025, revealing a sharp rise in attacks across the continent and a major shift in attacker tactics driven by artificial intelligence

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.