What is ISO 27701?
ISO 27701 is an international standard that extends ISO 27001 and ISO 27002 to include privacy-specific requirements for establishing, implementing, maintaining, and improving a Privacy Information Management System (PIMS).
ISO 27701, published in August 2019, is an international standard that provides guidance for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS). It extends the requirements and guidance of ISO 27001 (information security management systems) and ISO 27002 (security controls) to include privacy-specific considerations. Organizations must first implement ISO 27001 before they can adopt ISO 27701.
The standard provides a framework for managing personal information that can be used by both data controllers (referred to as PII controllers) and data processors (referred to as PII processors). It includes specific control sets for each role, covering areas such as conditions for collection and processing, obligations to PII principals, privacy by design, PII sharing and transfer, and data handling throughout the information lifecycle. ISO 27701 also maps its requirements to GDPR provisions, making it useful for demonstrating GDPR compliance.
Certification to ISO 27701 is available through accredited certification bodies and is increasingly recognized as evidence of robust privacy management practices. It provides a structured approach that can satisfy requirements across multiple jurisdictions simultaneously. ComplyIQ helps organizations track and manage ISO 27701 control implementation, while the broader IQWorks platform supports the technical controls required for PIMS certification.
Relevant Regulations
Related Terms
GDPR (General Data Protection Regulation)
The General Data Protection Regulation is the European Union's comprehensive data protection law that sets strict rules for how organizations collect, store, and process personal data of EU residents, with fines up to 4% of annual global turnover.
Data Protection Certification
Data protection certification is a formal attestation by an accredited body that an organization's data processing operations comply with specific data protection standards or regulatory requirements.
Privacy Program
A privacy program is a comprehensive organizational framework encompassing the policies, procedures, people, and technologies that manage an organization's data protection obligations and privacy risks.