ISO 27701 Privacy Information Management System (PIMS), an extension to ISO 27001 Information Security Management System (ISMS), can support your organization in meeting the regulatory requirements and manage privacy risks related to Personally Identifiable Information (PII).

ISO/IEC 27701:2019 specifies requirements and provides guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS) in the form of an extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy management within the context of the organization.

This document specifies PIMS-related requirements and provides guidance for PII controllers and PII processors holding responsibility and accountability for PII processing.

It is applicable to all types and sizes of organizations, including public and private companies, government entities and not-for-profit organizations, which are PII controllers and/or PII processors processing PII within an ISMS.

ISO 27701 helps companies to maintain an effective privacy and information security system and reduce privacy risks. ISO 27701 is an impressive way of demonstrating to consumers, external organizations and internal stakeholders, that mechanisms are in place to keep data safe and to comply with GDPR and other privacy laws.

The ISO 27701 standard, a PIMS (Privacy Information Management System) standard, lays out a detailed set of operational checklists that can be adapted to a variety of regulations, including GDPR. Companies document their policies, procedures, protocols and activities in line with the standard’s operational checklists, with records then audited by internal and third-party auditors, resulting in detailed proof of compliance with the standard.

Benefits of ISO 27701

  • Support compliance to privacy regulations – such as the European Union General Data Protection Regulation (EU GDPR) and local privacy law & regulations such as Personal Data Protection Act (PDPA) in India.
  • Provide confidence to stakeholders and customers – that you are maintaining the highest standards in managing privacy risks related to PII.
  • Clear roles & responsibilities – for PII controllers and PII processors holding responsibility and accountability for PII processing.
  • Minimise risks – of disruptions of critical processes and financial losses associated with a breach.