Home/Frameworks/ISO 27701
Data Privacy
Data Privacy

ISO 27701

Privacy, made certifiable. ISO 27701 extends ISO 27001 into a Privacy Information Management System — the auditable way to demonstrate systematic compliance with GDPR and other privacy regimes.

The standard

What ISO 27701 is.

ISO/IEC 27701:2019 extends ISO 27001 and 27002 to create a Privacy Information Management System (PIMS). Where ISO 27001 protects information generally, ISO 27701 adds the controls and accountability specific to personal data.

It is explicitly mapped to privacy regulations including GDPR, which makes it the strongest auditable evidence available that an organisation manages personal data systematically — useful where a regulation itself offers no certificate.

It is implemented and certified as an extension to an ISO 27001 ISMS, so the two are best pursued together.

Who it's for

Is this you?

GDPR-bound organisations

Companies that need auditable proof of privacy compliance, not just policies.

International data handlers

Businesses processing personal data across multiple privacy regimes.

Processors & controllers

Both roles benefit from a certified privacy management system.

How we deliver

From kickoff to done,
in five stages.

Delivered through our specialist network, as an extension to ISO 27001. We build the privacy-specific controls and map them to the regulations that apply to you — turning a GDPR programme into something you can actually certify.

01

Scope & kickoff

We define the boundary of your programme — systems, locations, and teams in scope — and agree the timeline and responsibilities up front, so there are no surprises later.

02

Gap diagnostic

A structured assessment of your current posture against every requirement, producing a prioritised remediation plan with realistic effort estimates.

03

Build

We write the policies, procedures, and controls, and work alongside your engineering team on a weekly cadence to implement them — not a stack of templates left for you to figure out.

04

Operate

The management system runs and generates evidence. We drive the internal audit and management review so the programme is demonstrably working before any external scrutiny.

05

Audit support

We prepare the evidence package and sit alongside you through assessment, answering the assessor's questions directly rather than leaving you to defend the work alone.

Questions

Frequently asked.

A GDPR programme makes you compliant; ISO 27701 makes that compliance auditable and certifiable. The PIMS gives you a recognised certificate to show customers and regulators, which GDPR alone does not provide.

Yes — ISO 27701 is built on ISO 27001 and certified together with it. Many clients implement both in a single combined engagement.

Explore more

Other frameworks.

Ready when you are

Let's get you
ISO 27701 ready.

Book a free advisory session and we'll map your fastest credible route to compliance.

Book a free advisory session