ISO/IEC 27701 extends ISO/IEC 27001 and 27002 to cover privacy information management. It adds requirements and guidance for organisations acting as personally identifiable information controllers or processors, providing a framework for managing privacy risk alongside information security.
What ISO/IEC 27701 delivers for your organisation.
The core requirements your organisation will need to meet.
Implemented on top of an ISO/IEC 27001 management system
Determination of the organisation's role as controller or processor
Privacy risk assessment and privacy impact assessment
Records of processing activities for personally identifiable information
Controls for data subject rights, consent and retention
Requirements flowed down to processors and sub-processors
Our structured approach from initial assessment through to completion.
We determine your role as controller or processor and define the privacy scope over your existing ISMS.
We build records of processing, privacy risk assessments and the additional controls the extension requires.
We implement privacy controls, train staff on data subject rights, and run an internal audit.
We prepare you for the certification audit covering the extended system.
Our expertise spans across diverse sectors, delivering tailored certification solutions.
Common questions answered by our consultants.
Others we support in Information Security & Privacy.
Empower your business today with Achievemax's expertise.