Skip to content

One of the provisions in the ISO 29100 privacy framework is that the top management of an organization should “establish a privacy policy” that, among other things:

  • Provides an internal organizational framework for setting objectives,
  • Includes a commitment to satisfy applicable privacy safeguarding requirements,
  • Includes a commitment to continual improvement.

The privacy policy envisioned under the ISO 29100 is not the same as public-facing privacy notices that are posted on company websites that explain to the public how personal information is collected, shared, and processed. Instead, it would be an internal company policy that is communicated within an organization and governs how the organization will handle personal information. The privacy policy is designed to be supplemented by more detailed rules and obligations, created by various stakeholders internally.

About Greenberg Traurig

Greenberg Traurig, LLP has more than 3,200 lawyers across 51 locations in the United States, Europe, the Middle East, Latin America, and Asia. The firm’s broad geographic and practice range enables the delivery of innovative and strategic legal services across borders and industries. Recognized as a 2025 BTI “Best of the Best Recommended Law Firm” by general counsel for trust and relationship management, Greenberg Traurig is consistently ranked among the top firms on the Am Law Global 100, NLJ 500, and Law360 400. Greenberg Traurig is also known for its philanthropic giving, culture, innovation, and pro bono work. Web: www.gtlaw.com.

Law blog design & platform by LexBlog