ISO 27701
Process
27701
The protection of personal data is now not only a legal obligation but also a business requirement. Both customers, partners and authorities expect organisations to manage personal data safely, transparent and in accordance with relevant data protection standards. ISO/IEC 27701: 2019 is the world's first international standard for privacy Information Management System (PIMS). In addition to ISO/IEC 27001 and ISO/IEC 27002, the standard helps organisations to regulate and continuously develop personal data processing processes. The ISO/IEC 27701 certification demonstrates that your organisation does not only pay particular attention to information security but also to the management of personal data in accordance with internationally recognized management systems.
What is ISO/IEC 27701?
ISO/IEC 27701 is the data protection extension of ISO/IEC 27001.
The purpose of the standard is to make organisations
treat personal data properly
support compliance with GDPR and other data protection legislation
develop clear responsibilities
reduce the risk of data protection incidents
increase the confidence of their customers and partners
continuously develop their data protection processes.
It is important to emphasise that ISO/IEC 27701 does not replace GDPR, but provides a management system that helps to apply it in practice and maintain compliance.
What is PIMS (Privacy Information Management System)?
The Privacy Information Management System (PIMS) is a management system that regulates how the organisation manages personal data throughout their life cycle.
This includes, inter alia:
collection of personal data
storage
use
transmission
Keep
delete
and management of the risks associated with data management.
PIMS ensures that the organisation's data management practices are consistent, documented and continuously improved.
Who is recommended for ISO/IEC 27701 certification?
ISO/IEC 27701 is recommended for all organisations handling personal data.
In particular recommended:
IT providers
cloud service providers
SaaS service providers
software development enterprises
Financial institutions
insurance organisations
healthcare providers
HR service providers
call centers
to commercial enterprises
marketing agencies
for data processing companies
public bodies
and to any organisation which manages the personal data of customers, employees or partners.
Why is the privacy management system important?
Errors in the processing of personal data may have significant consequences.
These may include:
Data protection incident
unauthorised access
Data leak
fine
breach of contract
reputation injury
client loss.
Benefits of ISO/IEC 27701 certification
For customers and business partners it is clear that the organisation pays particular attention to the protection of personal data.
The standard provides a structured framework for the practical implementation of the number of requirements required in GDPR.
The organisation shall regularly assess the risks associated with data management and introduce appropriate protection measures.
Every step of data processing is documented and verifiable.
More and more clients and international partners are expecting proof of compliance with data protection.
Data protection processes become more uniform, transparent and easier to control.
One of the greatest advantages of ISO/IEC 27701 is to support the practical implementation of the GDPR requirements.
The standard provides assistance, inter alia:
For customers and business partners it is clear that the organisation pays particular attention to the protection of personal data.
The standard provides a structured framework for the practical implementation of the number of requirements required in GDPR.
The organisation shall regularly assess the risks associated with data management and introduce appropriate protection measures.
Every step of data processing is documented and verifiable.
More and more clients and international partners are expecting proof of compliance with data protection.
Data protection processes become more uniform, transparent and easier to control.
More trust
For customers and business partners it is clear that the organisation pays particular attention to the protection of personal data.
Support for GDPR requirements
The standard provides a structured framework for the practical implementation of the number of requirements required in GDPR.
Reduced data protection risks
The organisation shall regularly assess the risks associated with data management and introduce appropriate protection measures.
Transparent processes
Every step of data processing is documented and verifiable.
Competition advantage
More and more clients and international partners are expecting proof of compliance with data protection.
More efficient management
Data protection processes become more uniform, transparent and easier to control.
Are you interested in a detailed offer?
Request a Quote →ISO/IEC 27701 and GDPR
One of the greatest advantages of ISO/IEC 27701 is to support the practical implementation of the GDPR requirements. The standard provides assistance, among other things: It is important, however, that ISO/IEC 27701 does not automatically mean full compliance with GDPR, but provides a management system that significantly facilitates its maintenance.
in the definition of data management roles
in the management of data management records
in the management of relevant rights
in the management of data protection incidents
supervising processors
in the management of data management risks
the update of the data protection documentation.
Are you interested in a detailed offer?
ISO/IEC 27701 relationship with ISO/IEC 27001
ISO/IEC 27701 does not apply alone.
The standard is based on the ISO/IEC 27001 information security management system and is therefore a functioning ISMS for the implementation of PIMS.
The two standards shall ensure together:
protecting information
adequate processing of personal data
systematic management of risks
Continual improvement
a management system that meets international standards.
Key requirements of ISO/IEC 27701
ISO/IEC 27701 provides for a management system to ensure that personal data are handled in a transparent, regulated and continuously developed manner.
The standard is based on ISO/IEC 27001 requirements and adds data protection aspects.
The organisation shall, inter alia:
specify data management processes
assess data protection risks
to regulate the processing of personal data
ensure the enforcement of data subjects' rights
It shall regularly review the functioning of the data protection management system.
Data Controller (PII Controller) and Controller (PII Processor)
ISO/IEC 27701 handles the two most important roles separately.
PII Controller
The controller shall determine:
which personal data are handled
for which purpose the processing takes place
on which legal basis the processing takes place
how long data are kept
who have access to the data.
The controller shall be responsible for ensuring compliance with the relevant legislation.
PII Processor
The processor shall manage personal data on behalf of the controller.
For example:
cloud service providers
accounting companies
HR service providers
payroll companies
Data centres
IT operators.
The standard also sets specific requirements for processors, including contractual obligations, information security measures and incident management.
Data protection risk management
One of the basic requirements of ISO/IEC 27701 is the regular assessment of data protection risks.
The organisation shall examine, for example:
which personal data are handled
who have access to the data
which systems are used for data processing
what threats may be due to data
the consequences of a data protection incident.
Based on these risks, appropriate technical and organisational measures should be introduced.
Management of data subjects' rights
The standard supports the practical management of the rights concerned.
This includes, inter alia:
right of access
Right to rectification
Right to delete ("oblivion")
restriction of data processing
data portability
right of protest
rights to automated decision-making.
The organisation shall have documented procedures for the handling of such applications.
Data protection incident management
Rapid and appropriate handling of personal data incidents is a priority requirement.
The organisation shall regulate:
recognition of incidents
notification
Investigations
documentation
corrective actions
notify the authorities and data subjects where necessary.
Experience shall be used for the continual improvement of the management system.
Management of suppliers and processors
Many organisations use external partners to handle personal data.
Therefore, ISO/IEC 27701 provides, inter alia:
regulation of the selection of processors
definition of contractual requirements
recording data protection obligations
regular reviews of suppliers.
This is particularly important for cloud services, outsourcing and SaaS services.
Documentation
The standard requires appropriate documentation of the data protection management system.
Typical documented information:
Data protection policy
Data management objectives
roles and responsibilities
data management records
Data protection risk assessments
incident management procedures
processing contracts
educational records
internal audits
management audits
corrective measures.
Education and awareness
Protection of personal data is not a purely technical issue.
ISO/IEC 27701 expects workers to:
knowledge of data protection rules
be aware of their own responsibilities
identify data protection risks
properly handle personal data.
Regular education can significantly reduce the number of incidents resulting from human error.
Internal audit and management audit
ISO/IEC 27701, like ISO/IEC 27001, requires:
Internal audit
The organisation shall regularly verify that the data protection management system complies with the requirements of the standard and with its own rules.
Management screening
The senior management shall regularly assess:
compliance with data protection objectives
incidents
risks
results of internal audits
development opportunities.
This ensures the continual improvement of the system.
Process of ISO/IEC 27701 certification
01
How long does ISO/IEC 27701 hold an audit?
The duration of the audit shall always be determined on the basis of the accreditation rules. The number of audit days required shall be influenced by several factors, including:
08
Number of employees
09
Number of sites
10
the extent to which personal data are processed;
11
complexity of processing and processing processes
12
% of outsourced processes
13
IT infrastructure
14
existing management systems (e.g. ISO/IEC 27001)
15
and the possibility of integrated audit.
audit day for small and medium-sized enterprises
How much for ISO/IEC 27701 certification?
In each case, the fee for certification shall be determined on the basis of a specific offer.
It affects the price:
the place of certification.
Why choose Clearlake Consulting Kft?
Benefits
support during the whole certification process.
internationally recognized accredited certificate
more than 10 years of audit experience
Hungarian-language contact person
fast quotation
competitive prices
Flexible appointment
on-site and remote audit options
integrated audits with ISO/IEC 27001 and other standards
support during the whole certification process.
Are you interested in a detailed offer?
Are you interested in a detailed offer?
Request a Quote →Frequently Asked Questions
Yes. ISO/IEC 27701 is an extension of ISO/IEC 27001 and cannot therefore be independently certified. The organisation shall have an information security management system in place.
No. The standard does not replace GDPR but provides an internationally recognized management system that supports the practical implementation and maintenance of GDPR requirements.
What organisations is ISO/IEC 27701 recommended?
For all organisations which manage personal data, in particular:
Can the audit be conducted remotely?
Yes. Part of the audit or, where the accreditation rules allow it, the whole audit may be conducted online.
Can it be integrated with other ISO standards?
Yes. ISO/IEC 27701 is ideal for integration including:
ISO 9001
Integrated audit may reduce audit time and certification costs.
How long is the certificate valid?
The certificate shall be valid for three years. During this period, an annual surveillance audit is required, followed by a recertification audit at the end of the third year.
How long will it take to get the certificate?
Depending on the organisation's preparedness, the certification process can be completed within a few weeks.
What benefit is ISO/IEC 27701 certification?
Certification increases the confidence of customers and business partners, promotes data protection compliance, reduces data protection risks and may give rise to competitive advantages in applications, tenders and international business relations. Ask for ISO/IEC 27701 certification.
Would you like to regulate the processing of personal data in your organisation according to an internationally recognized management system and to justify your commitment to data protection to your partners?
Clearlake Consulting Kft. will help you find your best accredited certification partner and accompany you through the entire certification process. Whether it is a first certification, an existing ISO/IEC 27001 system or an integrated audit, our expert team provides fast, flexible and professional support. Contact us today, ask for a personalised offer and obtain ISO/IEC 27701 certificate that strengthens your clients' confidence, supports data protection compliance and increases their competitiveness!
Request a Quote
Get in touch with us and request an individual, no-obligation quote.
Request a Detailed Quote
Fill in our detailed quote request form — we prepare an individual offer based on your company data, the standards you select and a few questions about your processes.
Continue to tender →No obligation · Our reply within 1 working day