ISO/IEC 27701

ISO 27701 is an extension to ISO 27001 for privacy. It sets requirements and controls for a Privacy Information Management System (PIMS), aligned with GDPR and other privacy regimes. You must have ISO 27001 (or implement it in parallel) to certify to 27701.

Who it applies to

Organisations that hold ISO 27001 and want a structured Privacy Information Management System — controllers, processors, or both.

How ISO-STANDARD.app helps with ISO 27701

Pre-loaded ISO 27701 control mapping crosswalked to ISO 27001 Annex A so you don't duplicate work.

Evidence Vault stores signed, versioned artefacts (screenshots, logs, attestations) auditors and buyers accept.

Trust Center publishes your current ISO 27701 posture to prospects on demand — no PDF chase.

Internal Audit, CAPA and Management Review workflows built in, mapped to ISO 27701 clauses.

Policy templates with attestation, review cycles and change history that satisfy assessor sampling.

10 in-depth articles

How ISO 27701 supports GDPR compliance

27701 doesn't replace GDPR — it gives you an audit-ready management system that evidences GDPR practices.

Alignment, not substitution

27701 controls map to GDPR articles. Achieving 27701 makes GDPR audits smoother; it doesn't grant legal compliance in itself.

Controller and processor scoping

27701 has separate control sets for controllers and processors. Most organisations are both, for different processing activities.

Evidence pack

The 27701 audit produces exactly the kind of evidence GDPR regulators want to see.

Cross-border

27701 explicitly addresses cross-border transfers, aligning with GDPR Chapter V and UK IDTA.

How ISO-STANDARD.app helps with ISO 27701

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.

ISO 27701 controller vs processor requirements

The two control sets look similar but ask different questions. Get the classification right per processing activity.

Controller (Annex A)

Purposes and lawful basis, consent management, data subject rights, DPIA, records of processing, cross-border transfers, breach notification.

Processor (Annex B)

Processing on documented instructions, security, sub-processors, assistance to controller, return/deletion, cooperation with regulators.

Mixed roles

You can be a controller for HR data and a processor for customer-hosted data. The PIMS must handle both cleanly.

Contractual clarity

For each processing activity, the role and the contractual counterparts must be documented. Auditors probe here.

How ISO-STANDARD.app helps with ISO 27701

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.

Setting your PIMS scope

The PIMS scope needn't match the ISMS scope — but the boundary needs defending.

ISMS as foundation

You need ISO 27001 in place for the PIMS. Typically PIMS scope sits inside ISMS scope.

Business function scope

Every function handling personal data is in scope. Marketing, sales, HR, finance, product — usually most of the business.

Personal data categories

Include categories, sources, and jurisdictions. This becomes the input to the ROPA.

Justifiable exclusions

Anonymised data is out. Purely internal-only personal data (staff HR) may be in a separated scope for practical reasons — document why.

How ISO-STANDARD.app helps with ISO 27701

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.

Data subject rights under ISO 27701

27701 asks you to implement the rights AND to have the operational shape that makes them repeatable.

The rights

Access, rectification, erasure, restriction, portability, objection, and rights around automated decision-making.

Intake and verification

A defined intake channel, identity verification process, and clock start rules. Documented per jurisdiction because expectations differ.

Response mechanics

Search, redact, deliver, log. Automation reduces both cost and error rate on rectification and access.

Metrics

Volume, average response time, extension use, complaints. Report to management review.

How ISO-STANDARD.app helps with ISO 27701

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.

ISO 27701 and cross-border data transfers

27701 requires you to document transfer basis for every cross-border flow. It's the ROPA one column further right.

Mapping transfers

Every processing activity that crosses borders is captured with jurisdictions, mechanism, and TRA outcome.

Mechanism selection

Adequacy, SCCs, IDTA, UK Addendum, BCRs, derogations. 27701 doesn't specify which — it specifies that you use one.

TRA documentation

For SCC/IDTA transfers, a Transfer Risk Assessment. The audit will sample.

Change control

New service, new supplier, new region = transfer review. Instrument the loop.

How ISO-STANDARD.app helps with ISO 27701

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.

Managing privacy in supplier relationships under ISO 27701

Supplier management is where controller/processor mapping meets contract discipline.

Supplier register with role

Every supplier tagged as controller, processor, joint controller, or independent controller for the processing they do.

Contract clauses

DPA in place. Article 28 clauses for processors. Cross-border mechanisms attached where relevant.

Assurance

Third-party certifications (27001, 27701, 27018) or targeted audits. The register captures currency.

Sub-processor management

Full chain visibility for critical suppliers. Change notification and objection rights.

How ISO-STANDARD.app helps with ISO 27701

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.

Privacy management review under ISO 27701

27701 wants privacy-specific management review inputs — not just a bullet in the ISMS review.

Privacy-specific inputs

DSAR trends, breach summaries, DPIA outcomes, regulatory engagement, training completion.

Cross-standard efficiency

Run alongside ISO 27001 management review. Same governance forum, distinct agenda items.

Actions and improvements

Documented decisions on privacy programme changes. Owners, dates, tracked to closure.

Board-level reporting

For regulated organisations, boards want a privacy dashboard. The management review generates it.

How ISO-STANDARD.app helps with ISO 27701

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.

Privacy training and awareness under ISO 27701

The audit expects specifics: who was trained, on what, when, and how you refreshed.

Role-based training

Different content for developers, marketers, HR, executives. Off-the-shelf general training does not cover the audit expectation.

Frequency

At hire, then annually as a minimum. Ad-hoc after significant changes (new regulation, new tools).

Effectiveness

Attendance is a lagging indicator. Quiz results, incident recognition rates, DPIA completion quality are leading indicators.

Records

Attendance logs, materials, refresh cycles. Not a spreadsheet an admin owns alone — instrumented in your LMS or PIMS.

How ISO-STANDARD.app helps with ISO 27701

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.

Privacy-by-design controls in the PIMS

27701 pushes privacy from a legal checklist to an engineering practice.

Design-time DPIA

DPIA triggers embedded in product development. A new feature that changes data flows opens a DPIA before it ships.

Data minimisation

Collect and retain only what the purpose needs. Retention rules in the schema, not in a policy nobody enforces.

Purpose limitation

Every dataset tagged with lawful basis and purpose. Cross-purpose use flags the reviewer.

Default settings

New user defaults to the higher privacy setting. Consent required to lower.

How ISO-STANDARD.app helps with ISO 27701

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.

Getting ISO 27701 certified: pre-requisites and timeline

27701 is fastest if you already have ISO 27001. Otherwise, tackle both in parallel.

Pre-requisite

ISO 27001 certified or implemented in parallel by the same certification body.

Timeline from ISO 27001

3–6 months typically. Building the PIMS on top of an ISMS is faster than building both from zero.

Timeline from zero

12–15 months for combined ISO 27001 + 27701 programme. Front-load the ISMS work.

Ongoing

Annual surveillance audits with recertification every three years. Continuous evidence collection makes both painless.

How ISO-STANDARD.app helps with ISO 27701

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.

Ready to evidence ISO 27701?

Load the pre-mapped controls, capture evidence continuously, and publish your ISO 27701 posture to buyers on demand.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.