OnwynStandards › ISO/IEC 27701:2019

Certifiable standard · 2019

ISO/IEC 27701:2019

ISO/IEC 27701 turns an information security management system into a privacy information management system (PIMS): it adds privacy-specific management requirements on top of ISO/IEC 27001 and a set of controls for organizations that decide why personal data is processed (controllers) and for those that process it on someone else's instruction (processors). It is not a standalone certification — you certify ISO/IEC 27001 and 27701 together, against a scope that names your role, so the practical audience is a company that already holds or is building an ISO 27001 certificate and now has to prove privacy governance to customers, tender boards, or a group parent. In the EU market its main commercial value is that it gives GDPR obligations an auditable management-system shape: the standard carries a mapping annex to GDPR articles, and an accredited certificate answers most of what a customer's privacy due-diligence questionnaire asks. Note that clause 6 of the standard is written against the 2013 control numbering of ISO/IEC 27002, while a current ISO 27001:2022 ISMS uses the 2022 numbering; the substance is the same, only the labels differ.

66
Requirements
7
Areas
25
Recommended documents
2
Mapped frameworks
Start ISO/IEC 27701:2019 free Have us do it instead

What this standard asks for

Every requirement in ISO/IEC 27701:2019, grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

PIMS management requirements (clause 5)

12 requirements

  • 5.2.1Determine your privacy role and the context it creates
  • 5.2.2Interested parties and their privacy requirements
  • 5.2.3PIMS scope and its relationship to the ISMS scope
  • 5.3.2Privacy commitments in the management system policy
  • 5.3.3Privacy roles, responsibilities and reporting line
  • 5.4.1.2Risk assessment extended to risks for individuals
  • 5.4.1.3Risk treatment and the extended Statement of Applicability
  • 5.5.2Competence and awareness for privacy-relevant roles
  • 5.6.1Operating the PIMS processes
  • 5.7.2Internal audit covering privacy
  • 5.7.3Management review including privacy performance
  • 5.8.1Nonconformity and corrective action for privacy failures

Privacy extensions to security controls (clause 6)

8 requirements

  • 6.2Privacy content in the topic-specific policy set
  • 6.3Privacy in the internal organization and in projects
  • 6.4Confidentiality obligations and privacy duties of staff
  • 6.5Personal data in the asset inventory and classification scheme
  • 6.9Logging and administrative access to personal data
  • 6.12Privacy requirements in supplier relationships
  • 6.13Personal data breach handling inside incident management
  • 6.15Identifying applicable privacy legislation and obligations

Controller: conditions for processing (A.7.2)

8 requirements

  • A.7.2.1Identify and document the purpose of each processing activity
  • A.7.2.2Determine and record the lawful basis
  • A.7.2.3Define when and how consent is obtained
  • A.7.2.4Obtain and record consent
  • A.7.2.5Privacy impact assessment for higher-risk processing
  • A.7.2.6Contracts with processors
  • A.7.2.7Joint controller arrangements
  • A.7.2.8Maintain records of processing

Controller: obligations to individuals (A.7.3)

10 requirements

  • A.7.3.1Determine and fulfil your obligations to individuals
  • A.7.3.2Determine what information individuals must receive
  • A.7.3.3Provide information in a form people can use
  • A.7.3.4Mechanism to modify or withdraw consent
  • A.7.3.5Mechanism to object to processing
  • A.7.3.6Access, correction and erasure
  • A.7.3.7Inform recipients of corrections and erasures
  • A.7.3.8Provide a copy of the personal data processed
  • A.7.3.9Handle requests within defined timeframes
  • A.7.3.10Automated decision-making

Controller: privacy by design and by default (A.7.4)

9 requirements

  • A.7.4.1Limit collection to what the purpose needs
  • A.7.4.2Limit processing to the documented purpose
  • A.7.4.3Accuracy and quality of personal data
  • A.7.4.4Set minimisation objectives
  • A.7.4.5De-identification and deletion at the end of processing
  • A.7.4.6Temporary files and working copies
  • A.7.4.7Retention periods derived from purpose and law
  • A.7.4.8Disposal that actually removes the data
  • A.7.4.9Controls on transmission of personal data

Controller: sharing, transfer and disclosure (A.7.5)

4 requirements

  • A.7.5.1Basis for transfers between jurisdictions
  • A.7.5.2Define the countries data may be transferred to
  • A.7.5.3Records of transfers
  • A.7.5.4Records of disclosure to third parties

Processor obligations (Annex B)

15 requirements

  • B.8.2.1Process only on documented customer instruction
  • B.8.2.2Keep your own purposes out of customer data
  • B.8.2.3No marketing use of customer data without consent
  • B.8.2.4Challenge instructions that appear unlawful
  • B.8.2.5Support the customer's own obligations
  • B.8.2.6Records of processing carried out for customers
  • B.8.3.1Route individuals' requests to the controller
  • B.8.4.1Temporary files in processing systems
  • B.8.4.2Return, transfer or deletion at the end of the contract
  • B.8.4.3Transmission controls in the service
  • B.8.5.1-8.5.2Basis and permitted destinations for cross-border processing
  • B.8.5.3Records of disclosures to third parties
  • B.8.5.4-8.5.5Handling legally binding disclosure requests
  • B.8.5.6Disclose the sub-processors you use
  • B.8.5.7-8.5.8Engaging and changing sub-processors

The documents you will end up with

The recommended document set for ISO/IEC 27701:2019 — 25 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

PIMS Scope and Role Statement

States whether you act as a controller, a processor or both, and which processing the privacy management system covers.

Privacy Management Policy

The top-level commitment on how the company handles personal data, and the privacy rules that sit alongside your security policies.

Privacy Roles and Responsibilities

Who owns privacy decisions, who they report to, and what confidentiality duties staff carry.

Privacy Risk Assessment Method and Extended Statement of Applicability

How you assess risk to the people whose data you hold — not just risk to the company — and which privacy controls you apply.

Records of Processing Activities

The inventory of what personal data you process, why, on whose behalf, and where it goes.

Consent Procedure and Records

How you ask for consent, what you record when someone gives it, and how they take it back.

Privacy Impact Assessment Procedure

When a new project needs a privacy assessment, who does it, and what the assessment has to answer.

Individual Rights Handling Procedure

What happens when someone asks for their data, asks you to correct or delete it, or objects — including who does what and by when.

Privacy Notice

The public-facing explanation of what you do with people's data, written so a normal person can follow it.

Automated Decision-Making Policy

Where software makes or heavily shapes a decision about a person, what safeguards apply and how someone can challenge it.

Privacy by Design Standard

The rules engineering follows so new features collect the minimum, use it only for the stated purpose, and keep it accurate.

Retention and Deletion Schedule

How long each kind of personal data is kept, who decided that, and how it is actually removed when the time is up.

Personal Data Transmission Standard

How personal data is protected when it moves — between your systems, to customers, and to third parties.

Processor Agreement Template

The contract terms you put in place with anyone who handles personal data for you, and with joint controllers.

International Transfer Policy

Which countries personal data may go to, on what legal footing, and what extra protection travels with it.

Transfer and Disclosure Register

The running record of where personal data has been sent and who it has been disclosed to.

Processor Operating Rules

The rules your own teams follow when handling customer data on the customer's instruction — including what you must not do with it.

Sub-processor Management Procedure

How you pick sub-processors, how customers get told about them, and what happens when you want to change one.

Legally Binding Disclosure Request Procedure

What to do when law enforcement or a court asks for customer data — who is told, and who signs off.

Personal Data Logging Standard

What gets logged when someone touches personal data, especially administrators, and how those logs are protected.

Supplier Privacy Requirements

The privacy questions you ask a supplier before you sign, and the terms you insist on.

Personal Data Breach Procedure

How a security incident gets assessed for personal-data impact, who decides on notification, and against which clock.

Privacy Legal Register

The privacy laws and obligations that apply to you in each place you operate, and who keeps that list current.

Privacy Training Plan

What privacy training people in privacy-relevant roles get, and how you evidence they had it.

PIMS Audit and Management Review Records

The privacy items on the internal audit plan and the management review agenda, and what was done about what they found.

Work that counts twice

ISO/IEC 27701:2019 overlaps with 2 other frameworks in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.

Start ISO/IEC 27701:2019 today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.