Add Privacy to Your ISMS
ISO 27701 Privacy Information Management Certification
ISO 27701 turns your security management system into a privacy one. If you already run ISO 27001, this is how you prove you manage personal data with the same rigour.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
ISO/IEC 27701 extends ISO 27001 into a privacy information management system, or PIMS. It adds controls for handling personal data as a controller and a processor, and maps cleanly to laws like the DPDP Act and GDPR. It matters because customers increasingly ask how you protect personal data, not just company data. We help you bolt privacy controls onto your existing ISMS so you get one integrated system, not two overlapping ones.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the ISO 27701 engagement, 6 phases in order, each one selectable. Phase 1, PIMS Scoping and Role Mapping. We confirm where you act as a controller and where as a processor, then set the scope of your privacy management system. Activities: Inventory processing activities across the business; Classify each activity as controller or processor; Align the PIMS scope with the existing ISMS scope; Identify applicable privacy laws and contracts. Hands over PIMS Scope Statement and Role Map. Phase 2, Privacy Gap Assessment. We measure your current practices against the ISO 27701 controls and the privacy laws you must meet. You see exactly what is missing. Activities: Assess practices against clause 5 to 8 requirements; Test the Annex A and Annex B control sets; Check alignment with the DPDP Act and GDPR duties; Rank privacy gaps by legal exposure and effort. Hands over Privacy Gap Assessment Report. Phase 3, Privacy Control Design. We design controls for consent, data subject rights, retention, and processor agreements, all linked to your existing ISMS. Activities: Draft consent and purpose limitation controls; Design the data subject rights handling process; Set retention and deletion schedules; Update processor and sub-processor agreements. Hands over PIMS Control Set and Policy Updates. Phase 4, Implementation and Records. We help you build records of processing and embed privacy into day-to-day operations. Evidence starts flowing as the controls go live. Activities: Build records of processing activities; Embed privacy checks into change and onboarding flows; Train teams on the new privacy procedures; Start collecting evidence in the compliance platform. Hands over Records of Processing Activities and Evidence Trail. Phase 5, Internal Audit. We audit the PIMS against the standard and your legal obligations, then log and prioritise any findings. Activities: Plan the PIMS internal audit alongside the ISMS audit; Sample data subject requests and consent records; Log nonconformities against ISO 27701 controls; Agree corrective actions with control owners. Hands over PIMS Internal Audit Report. Phase 6, Certification Support. We stand with you through the certification audit, which usually runs alongside your ISO 27001 surveillance. Activities: Prepare the evidence pack for the certification body; Coordinate the extension audit with ISO 27001 surveillance; Support interviews with privacy control owners; Close findings raised during the audit. Hands over ISO 27701 Certificate. Each phase begins from the artefact the phase before it produced.
Phase 01 PIMS Scoping and Role Mapping
We confirm where you act as a controller and where as a processor, then set the scope of your privacy management system.
What Happens In This Phase
- Inventory processing activities across the business
- Classify each activity as controller or processor
- Align the PIMS scope with the existing ISMS scope
- Identify applicable privacy laws and contracts
The Handover
PIMS Scope Statement and Role Map
The next phase starts from this.
Phase 01 PIMS Scoping and Role Mapping
We confirm where you act as a controller and where as a processor, then set the scope of your privacy management system.
What Happens In This Phase
- Inventory processing activities across the business
- Classify each activity as controller or processor
- Align the PIMS scope with the existing ISMS scope
- Identify applicable privacy laws and contracts
The Handover
PIMS Scope Statement and Role Map
The next phase starts from this.
- 01
PIMS Scoping and Role Mapping
We confirm where you act as a controller and where as a processor, then set the scope of your privacy management system.
OutputPIMS Scope Statement and Role MapActivities
- Inventory processing activities across the business
- Classify each activity as controller or processor
- Align the PIMS scope with the existing ISMS scope
- Identify applicable privacy laws and contracts
- 02
Privacy Gap Assessment
We measure your current practices against the ISO 27701 controls and the privacy laws you must meet. You see exactly what is missing.
OutputPrivacy Gap Assessment ReportActivities
- Assess practices against clause 5 to 8 requirements
- Test the Annex A and Annex B control sets
- Check alignment with the DPDP Act and GDPR duties
- Rank privacy gaps by legal exposure and effort
- 03
Privacy Control Design
We design controls for consent, data subject rights, retention, and processor agreements, all linked to your existing ISMS.
OutputPIMS Control Set and Policy UpdatesActivities
- Draft consent and purpose limitation controls
- Design the data subject rights handling process
- Set retention and deletion schedules
- Update processor and sub-processor agreements
- 04
Implementation and Records
We help you build records of processing and embed privacy into day-to-day operations. Evidence starts flowing as the controls go live.
OutputRecords of Processing Activities and Evidence TrailActivities
- Build records of processing activities
- Embed privacy checks into change and onboarding flows
- Train teams on the new privacy procedures
- Start collecting evidence in the compliance platform
- 05
Internal Audit
We audit the PIMS against the standard and your legal obligations, then log and prioritise any findings.
OutputPIMS Internal Audit ReportActivities
- Plan the PIMS internal audit alongside the ISMS audit
- Sample data subject requests and consent records
- Log nonconformities against ISO 27701 controls
- Agree corrective actions with control owners
- 06
Certification Support
We stand with you through the certification audit, which usually runs alongside your ISO 27001 surveillance.
OutputISO 27701 CertificateActivities
- Prepare the evidence pack for the certification body
- Coordinate the extension audit with ISO 27001 surveillance
- Support interviews with privacy control owners
- Close findings raised during the audit
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
What Is Examined, and What it Is Measured Against
Map
Map of the ISO 27701 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: OneTrust, Vanta, Sprinto, Scrut, Microsoft Purview, Jira, Confluence, TrustArc. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: ISO/IEC 27701:2019, ISO/IEC 27001:2022, Digital Personal Data Protection Act 2023, GDPR, NIST Privacy Framework.
What We Run
8 tools
- Sprinto
- Microsoft Purview
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
Deliverables
What You Receive
- Privacy gap assessment report
- Records of processing activities
- PIMS policy set
- Controller and processor control mapping
- Certification audit support
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Do I need ISO 27001 before ISO 27701?
Yes. ISO 27701 is an extension, so you need a certified or in-progress ISMS as its foundation. We often run both together to save time.
Does ISO 27701 make me compliant with the DPDP Act?
It gets you most of the way. The controls map closely to the DPDP Act and GDPR, but we always check your specific legal obligations on top.
What is the difference between a controller and a processor here?
A controller decides why and how personal data is used. A processor handles it on someone else's instructions. ISO 27701 has separate controls for each role.
Keep Moving Through Compliance
Service 2 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.