Frameworks · ISO/IEC 27701:2019
ISO/IEC 27701: extend your ISMS to privacy management.
We prepare and support your organization to certify ISO/IEC 27701 — the privacy extension (PIMS) on top of ISO/IEC 27001.
Who it applies to
ISO/IEC 27701 applies to organizations that process personal data and want to demonstrate formal privacy management, as an extension of an existing ISMS.
What the framework requires
The standard extends the ISMS (ISO 27001) with a Privacy Information Management System (PIMS): requirements and controls depending on the role of data controller or processor.
ISO 27001 foundation
Processing roles
Privacy controls
Data-subject rights
Risks of not acting
- Processing personal data without formal privacy management.
- Being unable to demonstrate compliance to customers or authorities.
- Managing security and privacy as separate silos.
- Making it harder to handle data-subject rights.
The i-Prot proposal
We extend your ISMS to privacy with a PIMS aligned with ISO/IEC 27701: roles, privacy controls and rights processes. We prepare the organization for certification, integrated into the CGF cycle.
How we work with this framework
Privacy assessment
Roles and scope
Privacy controls
Rights processes
Certification and improvement
Deliverables
- Gap analysis
- Implementation plan
- Controls matrix
- System documentation
- Evidence
- Internal audit
- Management review
- Roadmap
How it connects with CGF
CGF uses ISO/IEC 27701 as a source of requirements. This framework mainly covers the Design, Implement, Operate & measure, and Improve stages of the cycle.
See the CGF methodology →
Complyze and ISO/IEC 27701
Complyze adds the privacy controls to the security ones, with the records of processing and the evidence in a single place.
Frequently asked questions
Ready to certify ISO/IEC 27701?
Tell us your context and we’ll propose a tailored path to certification.
By submitting you accept our privacy policy.