i-Prot

Frameworks · ISO/IEC 27701:2019

ISO/IEC 27701: extend your ISMS to privacy management.

We prepare and support your organization to certify ISO/IEC 27701 — the privacy extension (PIMS) on top of ISO/IEC 27001.

diagram · frameworks · iso/iec 27701:2019

Who it applies to

ISO/IEC 27701 applies to organizations that process personal data and want to demonstrate formal privacy management, as an extension of an existing ISMS.

What the framework requires

The standard extends the ISMS (ISO 27001) with a Privacy Information Management System (PIMS): requirements and controls depending on the role of data controller or processor.

ISO 27001 foundation

It requires an ISMS as its foundation.

Processing roles

Controller and processor.

Privacy controls

Specific annexes for personal data.

Data-subject rights

Processes to handle individuals’ rights.

Risks of not acting

  • Processing personal data without formal privacy management.
  • Being unable to demonstrate compliance to customers or authorities.
  • Managing security and privacy as separate silos.
  • Making it harder to handle data-subject rights.

The i-Prot proposal

We extend your ISMS to privacy with a PIMS aligned with ISO/IEC 27701: roles, privacy controls and rights processes. We prepare the organization for certification, integrated into the CGF cycle.

How we work with this framework

Privacy assessment

Gaps against ISO/IEC 27701 on top of the ISMS.

Roles and scope

Controller or processor and the PIMS boundaries.

Privacy controls

Specific personal-data controls and measures.

Rights processes

Handling of data-subject rights.

Certification and improvement

Support in the audit and continuous improvement.

Deliverables

  • Gap analysis
  • Implementation plan
  • Controls matrix
  • System documentation
  • Evidence
  • Internal audit
  • Management review
  • Roadmap

How it connects with CGF

CGF uses ISO/IEC 27701 as a source of requirements. This framework mainly covers the Design, Implement, Operate & measure, and Improve stages of the cycle.

See the CGF methodology →

Complyze and ISO/IEC 27701

Complyze adds the privacy controls to the security ones, with the records of processing and the evidence in a single place.

Frequently asked questions

Ready to certify ISO/IEC 27701?

Tell us your context and we’ll propose a tailored path to certification.

By submitting you accept our privacy policy.

By submitting you accept the privacy policy and the processing of your data in order to be contacted.