Skip to content

ISO 27701 · Data protection information management

ISO/IEC 27701 Certification

Home

ISO 27701

Process

Process

01

27701

The protection of personal data is now not only a legal obligation but also a business requirement. Both customers, partners and authorities expect organisations to manage personal data safely, transparent and in accordance with relevant data protection standards. ISO/IEC 27701: 2019 is the world's first international standard for privacy Information Management System (PIMS). In addition to ISO/IEC 27001 and ISO/IEC 27002, the standard helps organisations to regulate and continuously develop personal data processing processes. The ISO/IEC 27701 certification demonstrates that your organisation does not only pay particular attention to information security but also to the management of personal data in accordance with internationally recognized management systems.

What is ISO/IEC 27701?

ISO/IEC 27701 is the data protection extension of ISO/IEC 27001.

The purpose of the standard is to make organisations

treat personal data properly

support compliance with GDPR and other data protection legislation

develop clear responsibilities

reduce the risk of data protection incidents

increase the confidence of their customers and partners

continuously develop their data protection processes.

It is important to emphasise that ISO/IEC 27701 does not replace GDPR, but provides a management system that helps to apply it in practice and maintain compliance.

What is PIMS (Privacy Information Management System)?

The Privacy Information Management System (PIMS) is a management system that regulates how the organisation manages personal data throughout their life cycle.

This includes, inter alia:

collection of personal data

storage

use

transmission

Keep

delete

and management of the risks associated with data management.

PIMS ensures that the organisation's data management practices are consistent, documented and continuously improved.

Who It Is For

Who is recommended for ISO/IEC 27701 certification?

ISO/IEC 27701 is recommended for all organisations handling personal data.

In particular recommended:

IT providers

cloud service providers

SaaS service providers

software development enterprises

Financial institutions

insurance organisations

healthcare providers

HR service providers

call centers

to commercial enterprises

marketing agencies

for data processing companies

public bodies

and to any organisation which manages the personal data of customers, employees or partners.

Why is the privacy management system important?

Errors in the processing of personal data may have significant consequences.

These may include:

Data protection incident

unauthorised access

Data leak

fine

breach of contract

reputation injury

client loss.

Benefits

Benefits of ISO/IEC 27701 certification

For customers and business partners it is clear that the organisation pays particular attention to the protection of personal data.

The standard provides a structured framework for the practical implementation of the number of requirements required in GDPR.

The organisation shall regularly assess the risks associated with data management and introduce appropriate protection measures.

Every step of data processing is documented and verifiable.

More and more clients and international partners are expecting proof of compliance with data protection.

Data protection processes become more uniform, transparent and easier to control.

One of the greatest advantages of ISO/IEC 27701 is to support the practical implementation of the GDPR requirements.

The standard provides assistance, inter alia:

For customers and business partners it is clear that the organisation pays particular attention to the protection of personal data.

The standard provides a structured framework for the practical implementation of the number of requirements required in GDPR.

The organisation shall regularly assess the risks associated with data management and introduce appropriate protection measures.

Every step of data processing is documented and verifiable.

More and more clients and international partners are expecting proof of compliance with data protection.

Data protection processes become more uniform, transparent and easier to control.

More trust

For customers and business partners it is clear that the organisation pays particular attention to the protection of personal data.

Support for GDPR requirements

The standard provides a structured framework for the practical implementation of the number of requirements required in GDPR.

Reduced data protection risks

The organisation shall regularly assess the risks associated with data management and introduce appropriate protection measures.

Transparent processes

Every step of data processing is documented and verifiable.

Competition advantage

More and more clients and international partners are expecting proof of compliance with data protection.

More efficient management

Data protection processes become more uniform, transparent and easier to control.

Are you interested in a detailed offer?

Request a Quote →

ISO/IEC 27701 and GDPR

One of the greatest advantages of ISO/IEC 27701 is to support the practical implementation of the GDPR requirements. The standard provides assistance, among other things: It is important, however, that ISO/IEC 27701 does not automatically mean full compliance with GDPR, but provides a management system that significantly facilitates its maintenance.

in the definition of data management roles

in the management of data management records

in the management of relevant rights

in the management of data protection incidents

supervising processors

in the management of data management risks

the update of the data protection documentation.

Are you interested in a detailed offer?

ISO/IEC 27701 relationship with ISO/IEC 27001

ISO/IEC 27701 does not apply alone.

The standard is based on the ISO/IEC 27001 information security management system and is therefore a functioning ISMS for the implementation of PIMS.

The two standards shall ensure together:

protecting information

adequate processing of personal data

systematic management of risks

Continual improvement

a management system that meets international standards.

Key requirements of ISO/IEC 27701

ISO/IEC 27701 provides for a management system to ensure that personal data are handled in a transparent, regulated and continuously developed manner.

The standard is based on ISO/IEC 27001 requirements and adds data protection aspects.

The organisation shall, inter alia:

specify data management processes

assess data protection risks

to regulate the processing of personal data

ensure the enforcement of data subjects' rights

It shall regularly review the functioning of the data protection management system.

Data Controller (PII Controller) and Controller (PII Processor)

ISO/IEC 27701 handles the two most important roles separately.

PII Controller

The controller shall determine:

which personal data are handled

for which purpose the processing takes place

on which legal basis the processing takes place

how long data are kept

who have access to the data.

The controller shall be responsible for ensuring compliance with the relevant legislation.

PII Processor

The processor shall manage personal data on behalf of the controller.

For example:

cloud service providers

accounting companies

HR service providers

payroll companies

Data centres

IT operators.

The standard also sets specific requirements for processors, including contractual obligations, information security measures and incident management.

Data protection risk management

One of the basic requirements of ISO/IEC 27701 is the regular assessment of data protection risks.

The organisation shall examine, for example:

which personal data are handled

who have access to the data

which systems are used for data processing

what threats may be due to data

the consequences of a data protection incident.

Based on these risks, appropriate technical and organisational measures should be introduced.

Management of data subjects' rights

The standard supports the practical management of the rights concerned.

This includes, inter alia:

right of access

Right to rectification

Right to delete ("oblivion")

restriction of data processing

data portability

right of protest

rights to automated decision-making.

The organisation shall have documented procedures for the handling of such applications.

Data protection incident management

Rapid and appropriate handling of personal data incidents is a priority requirement.

The organisation shall regulate:

recognition of incidents

notification

Investigations

documentation

corrective actions

notify the authorities and data subjects where necessary.

Experience shall be used for the continual improvement of the management system.

Management of suppliers and processors

Many organisations use external partners to handle personal data.

Therefore, ISO/IEC 27701 provides, inter alia:

regulation of the selection of processors

definition of contractual requirements

recording data protection obligations

regular reviews of suppliers.

This is particularly important for cloud services, outsourcing and SaaS services.

Documentation

The standard requires appropriate documentation of the data protection management system.

Typical documented information:

Data protection policy

Data management objectives

roles and responsibilities

data management records

Data protection risk assessments

incident management procedures

processing contracts

educational records

internal audits

management audits

corrective measures.

Education and awareness

Protection of personal data is not a purely technical issue.

ISO/IEC 27701 expects workers to:

knowledge of data protection rules

be aware of their own responsibilities

identify data protection risks

properly handle personal data.

Regular education can significantly reduce the number of incidents resulting from human error.

Internal audit and management audit

ISO/IEC 27701, like ISO/IEC 27001, requires:

Internal audit

The organisation shall regularly verify that the data protection management system complies with the requirements of the standard and with its own rules.

Management screening

The senior management shall regularly assess:

compliance with data protection objectives

incidents

risks

results of internal audits

development opportunities.

This ensures the continual improvement of the system.

Process

Process of ISO/IEC 27701 certification

01

01

How long does ISO/IEC 27701 hold an audit?

The duration of the audit shall always be determined on the basis of the accreditation rules. The number of audit days required shall be influenced by several factors, including:

08

Number of employees

09

Number of sites

10

the extent to which personal data are processed;

11

complexity of processing and processing processes

12

% of outsourced processes

13

IT infrastructure

14

existing management systems (e.g. ISO/IEC 27001)

15

and the possibility of integrated audit.

1-3

audit day for small and medium-sized enterprises

How much for ISO/IEC 27701 certification?

In each case, the fee for certification shall be determined on the basis of a specific offer.

It affects the price:

the place of certification.

Why choose Clearlake Consulting Kft?

Benefits

Benefits

support during the whole certification process.

internationally recognized accredited certificate

more than 10 years of audit experience

Hungarian-language contact person

fast quotation

competitive prices

Flexible appointment

on-site and remote audit options

integrated audits with ISO/IEC 27001 and other standards

support during the whole certification process.

Are you interested in a detailed offer?

Are you interested in a detailed offer?

Request a Quote →
FAQ

Frequently Asked Questions

Yes. ISO/IEC 27701 is an extension of ISO/IEC 27001 and cannot therefore be independently certified. The organisation shall have an information security management system in place.

No. The standard does not replace GDPR but provides an internationally recognized management system that supports the practical implementation and maintenance of GDPR requirements.

Who It Is For

What organisations is ISO/IEC 27701 recommended?

For all organisations which manage personal data, in particular:

Can the audit be conducted remotely?

Yes. Part of the audit or, where the accreditation rules allow it, the whole audit may be conducted online.

Can it be integrated with other ISO standards?

Yes. ISO/IEC 27701 is ideal for integration including:

ISO 9001

Integrated audit may reduce audit time and certification costs.

How long is the certificate valid?

The certificate shall be valid for three years. During this period, an annual surveillance audit is required, followed by a recertification audit at the end of the third year.

How long will it take to get the certificate?

Depending on the organisation's preparedness, the certification process can be completed within a few weeks.

What benefit is ISO/IEC 27701 certification?

Certification increases the confidence of customers and business partners, promotes data protection compliance, reduces data protection risks and may give rise to competitive advantages in applications, tenders and international business relations. Ask for ISO/IEC 27701 certification.

Would you like to regulate the processing of personal data in your organisation according to an internationally recognized management system and to justify your commitment to data protection to your partners?

Clearlake Consulting Kft. will help you find your best accredited certification partner and accompany you through the entire certification process. Whether it is a first certification, an existing ISO/IEC 27001 system or an integrated audit, our expert team provides fast, flexible and professional support. Contact us today, ask for a personalised offer and obtain ISO/IEC 27701 certificate that strengthens your clients' confidence, supports data protection compliance and increases their competitiveness!

Contact

Request a Quote

Get in touch with us and request an individual, no-obligation quote.

Telephone
+36 30 5036549

Request a Detailed Quote

Fill in our detailed quote request form — we prepare an individual offer based on your company data, the standards you select and a few questions about your processes.

Continue to tender →

No obligation · Our reply within 1 working day