Certification · International

ISO 27701, without the spreadsheets.

Turn your privacy programme into a certifiable management system.

What is ISO 27701?

ISO/IEC 27701 specifies a privacy information management system (PIMS) with controls for both PII controllers and PII processors. It builds on ISO 27001 security controls and maps closely to GDPR obligations, which makes it a common way to evidence GDPR accountability.

Who needs it

  • Companies with ISO 27001 that want to extend it to privacy
  • Processors who want a recognised way to evidence GDPR commitments
  • Teams answering privacy due diligence from enterprise customers

What ISO 27701 looks at

Conditions for processing

Identified purposes, lawful basis and records of processing.

Obligations to PII principals

Notices, consent and responding to individuals’ requests.

Privacy by design and default

Minimising collection, retention and disclosure of PII.

Sharing and transfers

Controlling disclosures to third parties and transfers between jurisdictions.

How Beviso gets you there

  • PIMS controls alongside ISO 27001, sharing the underlying security evidence
  • GDPR controls cross-referenced to the privacy requirements they satisfy
  • Sub-processor tracking in the vendor register

10 ISO 27701 controls, ready on day one

These controls are loaded when you enable ISO 27701, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

5.2.1

Understanding the Organization and Its Context (Privacy)

The organization shall determine external and internal issues relevant to its purposes and that affect its ability to achieve the intended outcomes of its PIMS.

Evidence from

  • Notion
  • Ironclad

6.4

Privacy Risk Assessment

The organization shall plan and conduct privacy risk assessments, including identifying risks to the rights and freedoms of natural persons.

Evidence from

  • Jira
  • Notion
  • Ironclad

7.2.1

Identify and Document Purpose

The organization shall identify and document the specific purposes for which PII will be processed.

Evidence from

  • Notion
  • Ironclad
  • Segment

7.2.2

Identify Lawful Basis

Where required, the organisation shall determine and document the applicable lawful basis for the processing of PII.

Evidence from

  • Notion
  • Ironclad

7.3.1

Obligations to PII Principals

The organization shall provide PII principals with the information required by applicable legislation and regulation for PII processing.

Evidence from

  • Ironclad
  • DocuSign
  • Zendesk
  • Freshdesk

7.4.1

Limit Collection to Minimum Necessary

The organization shall limit the collection of PII to the minimum necessary in relation to the identified purposes.

Evidence from

  • Segment
  • Airtable

8.2.1

Customer Agreement (Controller)

The organization shall ensure that PII controller obligations are met before processing begins for a customer.

Evidence from

  • Ironclad
  • DocuSign

8.3.1

Obligations to Customers (Processor)

The organization shall process PII in accordance with documented instructions from the PII controller.

Evidence from

  • Ironclad
  • DocuSign

8.4.1

Temporary Files

The organization shall ensure that temporary files created during PII processing are erased or anonymised within a documented time period.

Evidence from

  • Doppler
  • HashiCorp Vault
  • AWS

8.5.1

Privacy Impact Assessment

The organization shall conduct a privacy impact assessment for proposed new or changed PII processing activities.

Evidence from

  • Jira
  • Notion
  • Ironclad

ISO 27701 questions

Does ISO 27701 certification mean GDPR compliance?
It is strong evidence of GDPR accountability, but not a legal safe harbour. You still need to meet every GDPR obligation that applies to you.

Start your ISO 27701 programme today.

Free while Beviso is in beta. No credit card required.

Get started free