ISO 27701 - Privacy Information Management
ISO/IEC 27701 extends your ISMS into a full Privacy Information Management System (PIMS), giving you a structured way to demonstrate GDPR- and DPDPA-aligned privacy governance.
What is ISO 27701?
ISO/IEC 27701 adds privacy-specific controls on top of ISO/IEC 27001, for organisations acting as either a data controller or a data processor. It does not replace ISO 27001 - it extends it.
Because it maps directly to major privacy laws, a PIMS built on ISO 27701 gives you a structured, auditable way to demonstrate compliance with regulations like GDPR and India's DPDPA.
What's included
Gap Assessment
Gap assessment against ISO/IEC 27701 controls.
Privacy Risk & DPIAs
Privacy risk assessment and Data Protection Impact Assessments (DPIAs).
Obligation Mapping
Controller and processor obligation mapping.
PIMS Documentation
PIMS documentation aligned to your existing ISMS.
Certification Audit Support
Certification audit readiness support.
Ongoing Privacy Governance
Ongoing privacy governance support.
Our approach - Plan, Do, Check, Act
The same continuous-improvement cycle behind every compliance programme we run.
Plan
Identify objectives, secure management support, define the scope and method of risk assessment, and inventory the assets that need protecting.
Do
Manage risk with a treatment plan, implement the required controls and policies, and train staff to follow them.
Check
Monitor how the management system is actually running, and prepare the organisation for its certification or attestation audit.
Act
Run the audit, then keep improving through continual, corrective and preventive action.
Other compliance frameworks
Questions we get asked first
Do we need ISO 27001 before ISO 27701?
Yes - ISO 27701 is an extension to an existing ISMS, so ISO 27001 (or an equivalent management system) needs to be in place first. We can implement both together if you're starting from scratch.
How is ISO 27701 different from GDPR compliance?
GDPR is a legal requirement; ISO 27701 is a certifiable management-system standard that helps demonstrate GDPR-aligned governance in a structured, auditable way - it supports compliance but doesn't replace a legal GDPR assessment.
Who typically needs ISO 27701?
Organisations that process personal data at scale as a controller or processor, especially those already ISO 27001 certified and looking to formalise privacy governance for enterprise customers or regulators.
Ready to get audit-ready for ISO 27701?
Tell us where you're starting from and we'll come back with a scoped proposal within two working days.
