Back to Framework

Privacy

Control statements and requirements for privacy.

Privacy by Design and GovernancePR-1

The organisation shall implement privacy by design principles in all AI systems, ensuring privacy considerations are embedded from initial planning through system retirement. This includes establishing and maintaining comprehensive privacy policies, conducting privacy impact assessments, defining clear privacy roles and responsibilities, and integrating privacy requirements into project management processes. The organisation shall establish privacy governance structures, maintain documentation of privacy decisions, regularly review privacy controls for effectiveness, and ensure special categories of personal data are processed only when strictly necessary and with appropriate safeguards. Senior management shall demonstrate commitment to privacy through resource allocation and oversight of privacy initiatives.

ISO27701:6.1.1 6.1.2 6.2.1-6.2.4 7.2.1-7.2.3 7.2.5 7.2.7 12.2.1 A.7.4.1-A.7.4.9 B.8.4
EU AI ACT:10.5 26.9 27.4
SOC2:P1.1 P1.2 P1.3

Personal Data ManagementPR-2

The organisation shall implement operational processes for the responsible collection, use, storage, and disposal of personal data in AI systems. This includes maintaining data inventories, implementing data classification schemes, managing data retention schedules, and ensuring appropriate data handling throughout the information lifecycle. The organisation shall obtain and maintain records of consent for data processing, provide individuals with access to their data, implement processes for handling data subject requests, and ensure data quality standards are maintained. Clear procedures for data minimisation, purpose limitation, and secure disposal shall be established and followed.

ISO27701:8.2.1-8.2.4 8.3.1-8.3.3 A.7.2.1-A.7.2.8 A.7.3.1-A.7.3.10 7.4.5 A.7.5.1-A.7.5.4 B.8.2 B.8.3 B.8.4.2 B.8.5
SOC2:P2.1 P2.2 P3.1-P3.3 P4.1-P4.3

Privacy Compliance and MonitoringPR-3

The organisation shall establish processes to monitor compliance with privacy requirements, detect and respond to privacy incidents, and ensure continuous improvement of privacy controls. This includes conducting regular privacy audits, monitoring data processing activities, managing privacy incidents, ensuring supplier compliance with privacy requirements, and maintaining business continuity plans that address privacy considerations. The organisation shall implement privacy metrics, conduct regular assessments, comply with breach notification requirements, and demonstrate ongoing compliance with applicable privacy regulations through documented evidence.

ISO27701:12.2.2 15.2.1 16.2.1 16.2.2 17.2.1 18.2.1 18.2.2 A.7.2.5-A.7.2.7 A.7.3.6 B.8.2.4 B.8.2.5
SOC2:P6.1 P6.2 P6.3 P6.4 P6.5

Privacy-Enhancing Technologies and MechanismsPR-4

The organisation shall implement appropriate technical mechanisms and privacy-enhancing technologies in AI systems to protect personal data and ensure privacy by default. This includes implementing encryption for data at rest and in transit, role-based access control mechanisms, data minimisation techniques, anonymisation and pseudonymisation methods, and secure deletion capabilities. The organisation shall ensure these mechanisms are appropriate for the sensitivity of the data, regularly tested for effectiveness, and updated as privacy-enhancing technologies evolve. This includes how technical controls are documented, validated, and integrated into the system architecture to provide defense in depth for privacy protection.

ISO27701:9.2.1-9.2.4 10.2.1-10.2.2 11.2.1-11.2.2 13.2.1 14.2.1-14.2.2 A.7.4.5 A.7.4.9 B.8.4.3
SOC2:P5.1 P5.2 P5.3 P5.4 P5.5 P5.6