ISO 27701, without the spreadsheets.
Turn your privacy programme into a certifiable management system.
What is ISO 27701?
ISO/IEC 27701 specifies a privacy information management system (PIMS) with controls for both PII controllers and PII processors. It builds on ISO 27001 security controls and maps closely to GDPR obligations, which makes it a common way to evidence GDPR accountability.
Who needs it
- Companies with ISO 27001 that want to extend it to privacy
- Processors who want a recognised way to evidence GDPR commitments
- Teams answering privacy due diligence from enterprise customers
What ISO 27701 looks at
Conditions for processing
Identified purposes, lawful basis and records of processing.
Obligations to PII principals
Notices, consent and responding to individuals’ requests.
Privacy by design and default
Minimising collection, retention and disclosure of PII.
Sharing and transfers
Controlling disclosures to third parties and transfers between jurisdictions.
How Beviso gets you there
- PIMS controls alongside ISO 27001, sharing the underlying security evidence
- GDPR controls cross-referenced to the privacy requirements they satisfy
- Sub-processor tracking in the vendor register
10 ISO 27701 controls, ready on day one
These controls are loaded when you enable ISO 27701, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.
5.2.1
Understanding the Organization and Its Context (Privacy)
The organization shall determine external and internal issues relevant to its purposes and that affect its ability to achieve the intended outcomes of its PIMS.
Evidence from
- Notion
- Ironclad
6.4
Privacy Risk Assessment
The organization shall plan and conduct privacy risk assessments, including identifying risks to the rights and freedoms of natural persons.
Evidence from
- Jira
- Notion
- Ironclad
7.2.1
Identify and Document Purpose
The organization shall identify and document the specific purposes for which PII will be processed.
Evidence from
- Notion
- Ironclad
- Segment
7.2.2
Identify Lawful Basis
Where required, the organisation shall determine and document the applicable lawful basis for the processing of PII.
Evidence from
- Notion
- Ironclad
7.3.1
Obligations to PII Principals
The organization shall provide PII principals with the information required by applicable legislation and regulation for PII processing.
Evidence from
- Ironclad
- DocuSign
- Zendesk
- Freshdesk
7.4.1
Limit Collection to Minimum Necessary
The organization shall limit the collection of PII to the minimum necessary in relation to the identified purposes.
Evidence from
- Segment
- Airtable
8.2.1
Customer Agreement (Controller)
The organization shall ensure that PII controller obligations are met before processing begins for a customer.
Evidence from
- Ironclad
- DocuSign
8.3.1
Obligations to Customers (Processor)
The organization shall process PII in accordance with documented instructions from the PII controller.
Evidence from
- Ironclad
- DocuSign
8.4.1
Temporary Files
The organization shall ensure that temporary files created during PII processing are erased or anonymised within a documented time period.
Evidence from
- Doppler
- HashiCorp Vault
- AWS
8.5.1
Privacy Impact Assessment
The organization shall conduct a privacy impact assessment for proposed new or changed PII processing activities.
Evidence from
- Jira
- Notion
- Ironclad
ISO 27701 questions
- Does ISO 27701 certification mean GDPR compliance?
- It is strong evidence of GDPR accountability, but not a legal safe harbour. You still need to meet every GDPR obligation that applies to you.
Often run alongside ISO 27701
Start your ISO 27701 programme today.
Free while Beviso is in beta. No credit card required.
Get started free