ISO 27701:2019
The global standard for privacy. Extend your information security to cover personal data protection and GDPR compliance.
Safeguarding Personally Identifiable Information.
Maps to GDPR, CCPA, and other privacy laws.
Clear processes for data subject rights and consent.
Built on top of your existing ISMS framework.
ISO 27701 is a privacy extension to ISO 27001. It outlines the requirements for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS).
It provides guidance for PII controllers and PII processors to manage privacy controls, reducing the risk to the privacy rights of individuals and helping organizations comply with regulations like GDPR, CCPA, and LGPD.
Demonstrate your commitment to privacy and build trust with your stakeholders.
Show customers and partners that their personal data is safe with you.
Simplify compliance with multiple privacy regulations worldwide.
Identify and mitigate risks associated with processing personal data.
Clarify your role as a PII Controller or Processor.
Integrate privacy audits with your existing security audits.
Facilitate business agreements where privacy is a key requirement.
The standard extends ISO 27001 clauses and adds PIMS-specific guidance.
Specific PIMS extensions to ISO 27001 clauses 4-10.
Privacy-specific guidance for ISO 27002 controls.
Additional guidance for organizations acting as PII Controllers.
Additional guidance for organizations acting as PII Processors.
List of controls applicable to PII Controllers.
List of controls applicable to PII Processors.
We help you integrate privacy into your existing security framework seamlessly.
Assess current privacy practices against ISO 27701 and GDPR.
Identify PII flows and determine your role (Controller/Processor).
Update ISMS policies and procedures to include privacy controls.
Roll out privacy notices, consent forms, and DSR processes.
Verify PIMS effectiveness and compliance.
Achieve ISO 27701 certification alongside or after ISO 27001.
Any organization that processes Personally Identifiable Information (PII), regardless of size or sector, especially those subject to privacy regulations like GDPR.
Contact us to extend your ISMS with ISO 27701 certification.