Skip to main content
Promotional banner for the pentest readiness checklist
Category: Laws and Regulations

ISO/IEC 29151

Also known as: ISO/IEC 29151:2017, ISO/IEC 29151:2026
Simply put

ISO/IEC 29151 is an international standard that offers guidance to organizations that decide how and why personal data is handled (known as PII controllers) on protecting that data. It sets out a broad range of information security and privacy protection controls, along with guidance on how to put them in place. It is intended to help organizations address risks to personally identifiable information rather than to serve as a specific cookie consent requirement.

Formal definition

ISO/IEC 29151 is a standard within the ISO/IEC 27000 family that establishes control objectives, controls, and implementation guidance for PII controllers to protect personally identifiable information. According to the evidence, it specifies controls, their purpose, and guidance for implementation to meet requirements identified through a risk and impact assessment, building on the information security management system foundation set out in ISO/IEC 27001. The standard exists in a 2017 edition, with a 2026 edition also referenced in the evidence; the precise differences between editions and the full scope of its controls are not detailed here. As a voluntary international standard, it supports organizational information security and privacy governance but is distinct from, and does not by itself satisfy, statutory obligations under regimes such as the GDPR, the ePrivacy Directive, or US state privacy laws.

Why it matters

For privacy and compliance teams, ISO/IEC 29151 offers a structured, internationally recognized set of information security and privacy protection controls aimed specifically at PII controllers, the organizations that decide how and why personal data is handled. Because it builds on the risk-based approach familiar from the wider ISO/IEC 27000 family, it can help organizations translate abstract privacy principles into concrete, documented controls and implementation guidance. This is valuable for demonstrating a mature approach to protecting personally identifiable information and for aligning security and privacy governance under a common framework.

It is important, however, not to overstate the standard's role in the cookie consent context. ISO/IEC 29151 is a voluntary international standard offering guidance on protecting PII; it is not a cookie consent requirement and does not, by itself, satisfy statutory obligations such as those under the GDPR, the ePrivacy Directive and its national implementations, or US state privacy laws. Consent for placing or accessing information on a user's device, and for any subsequent processing of personal data, is governed by those legal regimes rather than by adherence to this standard. Conformance with ISO/IEC 29151 may support and evidence good privacy governance, but it does not replace the legal analysis needed to determine whether a given cookie or tracking practice is lawful in a particular jurisdiction.

Used appropriately, the standard can complement a consent management program by strengthening the underlying controls that protect the personal data collected once consent (or another lawful basis) is established. Organizations should treat it as one input into a broader compliance posture, understanding that requirements differ across the EU, the UK, and individual US states, and that the standard does not resolve those jurisdiction-specific obligations.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for privacy governance can use ISO/IEC 29151 as a reference set of controls for protecting personally identifiable information within a risk-based framework. It may help structure and document privacy protections, but it should be understood as guidance that complements, rather than replaces, statutory obligations under regimes such as the GDPR and applicable national or state laws.
Information security teams
Because the standard builds on the ISO/IEC 27001 information security management system foundation, security teams already working within the ISO/IEC 27000 family may find it a natural extension for aligning security controls with PII protection objectives identified through risk and impact assessment.
Legal and compliance counsel
Counsel advising on data protection can consider conformance with ISO/IEC 29151 as one element of an organization's overall privacy posture. It is important to note that the standard is voluntary and does not by itself satisfy cookie consent or other legal requirements, which vary between the EU, the UK, and individual US states and require separate legal analysis.
PII controllers
Organizations that decide how and why personal data is handled are the primary audience the standard addresses. They can use its control objectives and implementation guidance to help protect the personal data they collect, including data gathered through cookies and similar technologies once a valid lawful basis has been established under the relevant regime.

Inside ISO/IEC 29151

Code of practice for PII protection
ISO/IEC 29151 is an international standard providing a code of practice for the protection of personally identifiable information (PII), offering guidance on controls and objectives that organizations acting as PII controllers may adopt.
Alignment with ISO/IEC 27002 structure
The standard builds upon the information security controls framework, extending and supplementing general security control guidance with privacy-specific enhancements and additional controls oriented toward PII.
Privacy-specific control guidance
It sets out control objectives and implementation guidance addressing the handling of PII, intended to help organizations meet privacy principles and obligations they may be subject to under applicable law.
Applicability to PII controllers
The guidance is generally framed for organizations that determine the purposes and means of processing PII, and is intended to be adaptable to an organization's specific regulatory and operational context.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 29151.

Does implementing ISO/IEC 29151 make my organization compliant with the GDPR or the ePrivacy Directive?
No. ISO/IEC 29151 is a code of practice offering guidance and control objectives for protecting personally identifiable information, but it is not a legal instrument and adopting it does not, by itself, establish compliance with the GDPR, national ePrivacy implementations, or any other law. Compliance obligations arise from the applicable legal regimes, and demonstrating adherence to a standard is at most one supporting element of an overall accountability approach. Legal judgment remains necessary to assess whether specific processing and cookie-related practices meet statutory requirements, which differ across the EU, the UK, individual US states, and other jurisdictions.
Is ISO/IEC 29151 a certifiable standard that regulators recognize as proof of good practice?
ISO/IEC 29151 is generally positioned as a code of practice providing guidance rather than a set of auditable certification requirements in the way some other standards are structured. You should not assume that following it produces a certification or that any data protection authority treats it as formal evidence of compliance. Regulatory recognition of standards and certification schemes varies by jurisdiction and evolves over time, so any claim that a standard is 'recognized' should be checked against current guidance from the relevant authority rather than presumed.
How does ISO/IEC 29151 relate to consent management for cookies and similar technologies?
The standard addresses PII protection controls at an organizational and technical level and can inform how you design governance, documentation, and record-keeping practices that may support consent management. However, it does not prescribe the specific consent mechanics required for cookies, pixels, SDKs, local storage, or fingerprinting under EU or UK ePrivacy rules, nor the opt-out models common under US state laws. You would still need to map its general controls onto the concrete consent standards and technical implementations that apply in your jurisdictions, typically using a consent management platform and appropriate legal review.
Can ISO/IEC 29151 controls help with consent logging and record-keeping obligations?
The standard's emphasis on documented controls and accountability can help structure internal processes for maintaining records, which may in turn support consent logging practices. That said, the specific record-keeping expectations for cookie consent derive from the applicable legal frameworks and any relevant DPA guidance, not from the standard itself. Treat ISO/IEC 29151 as a way to organize and evidence your controls, while separately confirming what your applicable regime requires you to retain and for how long.
Where does ISO/IEC 29151 fit alongside other tools like CMPs, the IAB TCF, or Global Privacy Control signals?
ISO/IEC 29151 operates at the level of organizational and technical controls and does not replace operational tools such as consent management platforms, participation in frameworks like the IAB Transparency and Consent Framework, or handling of signals such as Global Privacy Control. These tools support specific consent and preference-handling functions, whereas the standard offers broader guidance on PII protection governance. None of these components, individually or together, guarantees compliance, so they should be combined with legal judgment appropriate to each jurisdiction.
What are the limitations of relying on ISO/IEC 29151 for a cookie compliance program?
Because it is a general code of practice rather than a jurisdiction-specific rulebook, ISO/IEC 29151 does not resolve contested questions such as how consent requirements apply to particular categories of cookies, whether cookie walls are acceptable, or how opt-out versus opt-in models should be implemented in different regions. It also does not track evolving enforcement positions. Organizations should therefore treat it as a supporting framework for controls and accountability, while addressing the specific and sometimes unsettled legal requirements of the EU, the UK, US states, and other applicable regimes separately.

Common misconceptions

Adopting ISO/IEC 29151 automatically makes an organization compliant with cookie consent laws such as the ePrivacy rules or the GDPR.
The standard is guidance that supports good privacy practice, but it does not by itself satisfy specific legal obligations. Cookie consent requirements under the ePrivacy Directive's national implementations and processing requirements under the GDPR must be assessed separately, and legal judgment remains necessary. Enforcement positions and guidance from data protection authorities can also evolve.
ISO/IEC 29151 is a law or a regulatory framework that applies of its own force.
It is a voluntary international standard, not legislation. It does not confer legal obligations by itself; obligations arise from applicable statutes and regulations, which differ across the EU, the UK, individual US states, and other regimes.
ISO/IEC 29151 provides detailed technical rules specific to cookies, pixels, or consent management platforms.
The standard addresses the protection of PII at a general control and code-of-practice level rather than prescribing the mechanics of cookie consent, CMPs, or signals such as Global Privacy Control. Operational cookie consent implementation falls outside its direct scope and depends on facts and jurisdictions not addressed by the standard.

Best practices

Treat ISO/IEC 29151 as a supporting framework for PII protection rather than as evidence of legal compliance, and pair its adoption with a separate legal analysis of applicable cookie consent and data protection obligations.
Map the standard's control guidance to the specific requirements of the jurisdictions you operate in, recognizing that EU, UK, and US state rules differ and that consent standards vary between opt-in and opt-out regimes.
Use the standard alongside, rather than in place of, your consent management processes such as CMP configuration, consent logging, and record-keeping, since tooling and standards support but do not replace compliance.
Document how any adopted controls relate to your handling of tracking technologies, noting that pixels, local storage, SDKs, and fingerprinting may fall within the same legal rules as cookies even though the standard does not detail them.
Involve legal or data protection professionals when interpreting how the standard's control objectives interact with evolving regulatory guidance, and avoid treating certification or adoption as a definitive statement of lawfulness.
Review your implementation periodically, since privacy guidance, enforcement positions, and the legal landscape can change over time.
Application Security Isn’t Optional Anymore.