Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Compliance13 services in this practice area

Add Privacy to Your ISMS

ISO 27701 Privacy Information Management Certification

ISO 27701 turns your security management system into a privacy one. If you already run ISO 27001, this is how you prove you manage personal data with the same rigour.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

ISO/IEC 27701 extends ISO 27001 into a privacy information management system, or PIMS. It adds controls for handling personal data as a controller and a processor, and maps cleanly to laws like the DPDP Act and GDPR. It matters because customers increasingly ask how you protect personal data, not just company data. We help you bolt privacy controls onto your existing ISMS so you get one integrated system, not two overlapping ones.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the ISO 27701 engagement, 6 phases in order, each one selectable. Phase 1, PIMS Scoping and Role Mapping. We confirm where you act as a controller and where as a processor, then set the scope of your privacy management system. Activities: Inventory processing activities across the business; Classify each activity as controller or processor; Align the PIMS scope with the existing ISMS scope; Identify applicable privacy laws and contracts. Hands over PIMS Scope Statement and Role Map. Phase 2, Privacy Gap Assessment. We measure your current practices against the ISO 27701 controls and the privacy laws you must meet. You see exactly what is missing. Activities: Assess practices against clause 5 to 8 requirements; Test the Annex A and Annex B control sets; Check alignment with the DPDP Act and GDPR duties; Rank privacy gaps by legal exposure and effort. Hands over Privacy Gap Assessment Report. Phase 3, Privacy Control Design. We design controls for consent, data subject rights, retention, and processor agreements, all linked to your existing ISMS. Activities: Draft consent and purpose limitation controls; Design the data subject rights handling process; Set retention and deletion schedules; Update processor and sub-processor agreements. Hands over PIMS Control Set and Policy Updates. Phase 4, Implementation and Records. We help you build records of processing and embed privacy into day-to-day operations. Evidence starts flowing as the controls go live. Activities: Build records of processing activities; Embed privacy checks into change and onboarding flows; Train teams on the new privacy procedures; Start collecting evidence in the compliance platform. Hands over Records of Processing Activities and Evidence Trail. Phase 5, Internal Audit. We audit the PIMS against the standard and your legal obligations, then log and prioritise any findings. Activities: Plan the PIMS internal audit alongside the ISMS audit; Sample data subject requests and consent records; Log nonconformities against ISO 27701 controls; Agree corrective actions with control owners. Hands over PIMS Internal Audit Report. Phase 6, Certification Support. We stand with you through the certification audit, which usually runs alongside your ISO 27001 surveillance. Activities: Prepare the evidence pack for the certification body; Coordinate the extension audit with ISO 27001 surveillance; Support interviews with privacy control owners; Close findings raised during the audit. Hands over ISO 27701 Certificate. Each phase begins from the artefact the phase before it produced.

Phase 01 PIMS Scoping and Role Mapping

We confirm where you act as a controller and where as a processor, then set the scope of your privacy management system.

What Happens In This Phase

  • Inventory processing activities across the business
  • Classify each activity as controller or processor
  • Align the PIMS scope with the existing ISMS scope
  • Identify applicable privacy laws and contracts

The Handover

PIMS Scope Statement and Role Map

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    PIMS Scoping and Role Mapping

    We confirm where you act as a controller and where as a processor, then set the scope of your privacy management system.

    OutputPIMS Scope Statement and Role Map

    Activities

    • Inventory processing activities across the business
    • Classify each activity as controller or processor
    • Align the PIMS scope with the existing ISMS scope
    • Identify applicable privacy laws and contracts
  2. 02

    Privacy Gap Assessment

    We measure your current practices against the ISO 27701 controls and the privacy laws you must meet. You see exactly what is missing.

    OutputPrivacy Gap Assessment Report

    Activities

    • Assess practices against clause 5 to 8 requirements
    • Test the Annex A and Annex B control sets
    • Check alignment with the DPDP Act and GDPR duties
    • Rank privacy gaps by legal exposure and effort
  3. 03

    Privacy Control Design

    We design controls for consent, data subject rights, retention, and processor agreements, all linked to your existing ISMS.

    OutputPIMS Control Set and Policy Updates

    Activities

    • Draft consent and purpose limitation controls
    • Design the data subject rights handling process
    • Set retention and deletion schedules
    • Update processor and sub-processor agreements
  4. 04

    Implementation and Records

    We help you build records of processing and embed privacy into day-to-day operations. Evidence starts flowing as the controls go live.

    OutputRecords of Processing Activities and Evidence Trail

    Activities

    • Build records of processing activities
    • Embed privacy checks into change and onboarding flows
    • Train teams on the new privacy procedures
    • Start collecting evidence in the compliance platform
  5. 05

    Internal Audit

    We audit the PIMS against the standard and your legal obligations, then log and prioritise any findings.

    OutputPIMS Internal Audit Report

    Activities

    • Plan the PIMS internal audit alongside the ISMS audit
    • Sample data subject requests and consent records
    • Log nonconformities against ISO 27701 controls
    • Agree corrective actions with control owners
  6. 06

    Certification Support

    We stand with you through the certification audit, which usually runs alongside your ISO 27001 surveillance.

    OutputISO 27701 Certificate

    Activities

    • Prepare the evidence pack for the certification body
    • Coordinate the extension audit with ISO 27001 surveillance
    • Support interviews with privacy control owners
    • Close findings raised during the audit

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the ISO 27701 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: OneTrust, Vanta, Sprinto, Scrut, Microsoft Purview, Jira, Confluence, TrustArc. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: ISO/IEC 27701:2019, ISO/IEC 27001:2022, Digital Personal Data Protection Act 2023, GDPR, NIST Privacy Framework.

What We Run

8 tools

  • OneTrust
  • Vanta
  • Sprinto
  • Scrut
  • Microsoft Purview
  • Jira
  • Confluence
  • TrustArc

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • ISO/IEC 27701:2019
  • ISO/IEC 27001:2022
  • Digital Personal Data Protection Act 2023
  • GDPR
  • NIST Privacy Framework
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Privacy gap assessment report
  • Records of processing activities
  • PIMS policy set
  • Controller and processor control mapping
  • Certification audit support

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Do I need ISO 27001 before ISO 27701?

Yes. ISO 27701 is an extension, so you need a certified or in-progress ISMS as its foundation. We often run both together to save time.

Does ISO 27701 make me compliant with the DPDP Act?

It gets you most of the way. The controls map closely to the DPDP Act and GDPR, but we always check your specific legal obligations on top.

What is the difference between a controller and a processor here?

A controller decides why and how personal data is used. A processor handles it on someone else's instructions. ISO 27701 has separate controls for each role.

Keep Moving Through Compliance

Service 2 of 13 in this practice area