Comply with personal data privacy laws
Comply with personal data privacy laws
ISO 27701 is a Privacy Information Management System (PIMS) standard that helps organizations comply with personal data privacy laws around the world. In recent years, new data protection laws have been introduced in multiple countries that establish requirements for securing and processing Personally Identifiable Information (PII). However, it is not always clear how organizations should comply with these laws. The standard was introduced in 2019 and provides actionable guidance to help organizations conform to these regulations.
ISO/IEC 27701:2019 is an extension of ISO/IEC 27001, the information security management system (ISMS) standard. Where ISO/IEC 27001 sets a standard for secure IT governance in the broadest sense, ISO/IEC 27701 focuses specifically on protecting personal data.
ISO/IEC 27701 is the first standard of its type and applies to public and private companies, government entities, and not-for-profit organizations. It supports compliance with the EU’s GDPR and applies to personal data privacy governance laws in all other countries.
TÜV SÜD has developed an efficient five-step process:
TÜV SÜD’s experienced ISMS teams possess the accreditation and expertise to conduct ISO/IEC 27001 and ISO/IEC 27701 audits across industries. Through our worldwide network of IT governance professionals, we can provide information security certification services no matter where you are. We have an in-depth understanding of the standard and have extensive experience helping organizations implement this kind of IT governance regulation.
Furthermore, TÜV SÜD’s experts actively participate in international standardization committees, and we have a complete understanding of the latest PII regulatory developments around the world. And because we are vendor agnostic, our third-party audits are both impartial and independent, meaning your organization gains valuable insights from an unbiased expert.
ISO 27001 designed a framework for Information Security Management Systems (ISMS) to provide confidentiality. ISO 27701 is an extension of the ISO/IEC 27001 standard, and it provides the requirements for General Data Protection Regulation (GDPR). ISO 27701 focuses on privacy and defines a framework for Privacy Information Management System (PIMS). It manages privacy with processors and controllers for personally identifiable information.
Yes, ISO 27701 can be achieved by any organization regardless of its size or sector or ownership. Government, private, non-profit sectors can get ISO 27701 certified. It serves as a valuable framework for organizations to comply with privacy legislation.
The 114 security controls of ISO 27701 are part of Annex A of ISO 27001. ISO 27701 also defines guidelines to implement these controls. They include mapping to:
The ISO 27701 standard focuses on the protection of Personally Identifiable Information (PII). The PIMS definition allows organizations to comply with privacy regulations around the world.
Learn how ISO 27701 can help you successfully manage your organization's data privacy
Learn More
Site Selector
Global
Americas
Asia
Europe
Middle East and Africa