ISO/IEC 27701
ISO 27701 is an extension to ISO 27001 for privacy. It sets requirements and controls for a Privacy Information Management System (PIMS), aligned with GDPR and other privacy regimes. You must have ISO 27001 (or implement it in parallel) to certify to 27701.
Who it applies to
Organisations that hold ISO 27001 and want a structured Privacy Information Management System — controllers, processors, or both.
How ISO-STANDARD.app helps with ISO 27701
10 in-depth articles
How ISO 27701 supports GDPR compliance
27701 doesn't replace GDPR — it gives you an audit-ready management system that evidences GDPR practices.
Alignment, not substitution
27701 controls map to GDPR articles. Achieving 27701 makes GDPR audits smoother; it doesn't grant legal compliance in itself.
Controller and processor scoping
27701 has separate control sets for controllers and processors. Most organisations are both, for different processing activities.
Evidence pack
The 27701 audit produces exactly the kind of evidence GDPR regulators want to see.
Cross-border
27701 explicitly addresses cross-border transfers, aligning with GDPR Chapter V and UK IDTA.
How ISO-STANDARD.app helps with ISO 27701
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.
ISO 27701 controller vs processor requirements
The two control sets look similar but ask different questions. Get the classification right per processing activity.
Controller (Annex A)
Purposes and lawful basis, consent management, data subject rights, DPIA, records of processing, cross-border transfers, breach notification.
Processor (Annex B)
Processing on documented instructions, security, sub-processors, assistance to controller, return/deletion, cooperation with regulators.
Mixed roles
You can be a controller for HR data and a processor for customer-hosted data. The PIMS must handle both cleanly.
Contractual clarity
For each processing activity, the role and the contractual counterparts must be documented. Auditors probe here.
How ISO-STANDARD.app helps with ISO 27701
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.
Setting your PIMS scope
The PIMS scope needn't match the ISMS scope — but the boundary needs defending.
ISMS as foundation
You need ISO 27001 in place for the PIMS. Typically PIMS scope sits inside ISMS scope.
Business function scope
Every function handling personal data is in scope. Marketing, sales, HR, finance, product — usually most of the business.
Personal data categories
Include categories, sources, and jurisdictions. This becomes the input to the ROPA.
Justifiable exclusions
Anonymised data is out. Purely internal-only personal data (staff HR) may be in a separated scope for practical reasons — document why.
How ISO-STANDARD.app helps with ISO 27701
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.
Data subject rights under ISO 27701
27701 asks you to implement the rights AND to have the operational shape that makes them repeatable.
The rights
Access, rectification, erasure, restriction, portability, objection, and rights around automated decision-making.
Intake and verification
A defined intake channel, identity verification process, and clock start rules. Documented per jurisdiction because expectations differ.
Response mechanics
Search, redact, deliver, log. Automation reduces both cost and error rate on rectification and access.
Metrics
Volume, average response time, extension use, complaints. Report to management review.
How ISO-STANDARD.app helps with ISO 27701
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.
ISO 27701 and cross-border data transfers
27701 requires you to document transfer basis for every cross-border flow. It's the ROPA one column further right.
Mapping transfers
Every processing activity that crosses borders is captured with jurisdictions, mechanism, and TRA outcome.
Mechanism selection
Adequacy, SCCs, IDTA, UK Addendum, BCRs, derogations. 27701 doesn't specify which — it specifies that you use one.
TRA documentation
For SCC/IDTA transfers, a Transfer Risk Assessment. The audit will sample.
Change control
New service, new supplier, new region = transfer review. Instrument the loop.
How ISO-STANDARD.app helps with ISO 27701
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.
Managing privacy in supplier relationships under ISO 27701
Supplier management is where controller/processor mapping meets contract discipline.
Supplier register with role
Every supplier tagged as controller, processor, joint controller, or independent controller for the processing they do.
Contract clauses
DPA in place. Article 28 clauses for processors. Cross-border mechanisms attached where relevant.
Assurance
Third-party certifications (27001, 27701, 27018) or targeted audits. The register captures currency.
Sub-processor management
Full chain visibility for critical suppliers. Change notification and objection rights.
How ISO-STANDARD.app helps with ISO 27701
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.
Privacy management review under ISO 27701
27701 wants privacy-specific management review inputs — not just a bullet in the ISMS review.
Privacy-specific inputs
DSAR trends, breach summaries, DPIA outcomes, regulatory engagement, training completion.
Cross-standard efficiency
Run alongside ISO 27001 management review. Same governance forum, distinct agenda items.
Actions and improvements
Documented decisions on privacy programme changes. Owners, dates, tracked to closure.
Board-level reporting
For regulated organisations, boards want a privacy dashboard. The management review generates it.
How ISO-STANDARD.app helps with ISO 27701
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.
Privacy training and awareness under ISO 27701
The audit expects specifics: who was trained, on what, when, and how you refreshed.
Role-based training
Different content for developers, marketers, HR, executives. Off-the-shelf general training does not cover the audit expectation.
Frequency
At hire, then annually as a minimum. Ad-hoc after significant changes (new regulation, new tools).
Effectiveness
Attendance is a lagging indicator. Quiz results, incident recognition rates, DPIA completion quality are leading indicators.
Records
Attendance logs, materials, refresh cycles. Not a spreadsheet an admin owns alone — instrumented in your LMS or PIMS.
How ISO-STANDARD.app helps with ISO 27701
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.
Privacy-by-design controls in the PIMS
27701 pushes privacy from a legal checklist to an engineering practice.
Design-time DPIA
DPIA triggers embedded in product development. A new feature that changes data flows opens a DPIA before it ships.
Data minimisation
Collect and retain only what the purpose needs. Retention rules in the schema, not in a policy nobody enforces.
Purpose limitation
Every dataset tagged with lawful basis and purpose. Cross-purpose use flags the reviewer.
Default settings
New user defaults to the higher privacy setting. Consent required to lower.
How ISO-STANDARD.app helps with ISO 27701
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.
Getting ISO 27701 certified: pre-requisites and timeline
27701 is fastest if you already have ISO 27001. Otherwise, tackle both in parallel.
Pre-requisite
ISO 27001 certified or implemented in parallel by the same certification body.
Timeline from ISO 27001
3–6 months typically. Building the PIMS on top of an ISMS is faster than building both from zero.
Timeline from zero
12–15 months for combined ISO 27001 + 27701 programme. Front-load the ISMS work.
Ongoing
Annual surveillance audits with recertification every three years. Continuous evidence collection makes both painless.
How ISO-STANDARD.app helps with ISO 27701
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27701 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27701 shape.
Ready to evidence ISO 27701?
Load the pre-mapped controls, capture evidence continuously, and publish your ISO 27701 posture to buyers on demand.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.