Extend your ISMS into a Privacy Information Management System under ISO/IEC 27701 — assurance over how you manage personal data.
ISO 27701 extends ISO 27001 with privacy-specific controls for handling personally identifiable information as a controller or processor.
We help you build the PIMS on top of your existing ISMS, mapping privacy obligations to controls and preparing you for certification alongside or after ISO 27001.
Controller and/or processor roles.
Extensions to Annex A for personal data.
Mapping personal-data flows.
Processes to fulfil requests.
Alignment to GDPR and India’s DPDPA.
The kinds of organisations that rely on this work.
ISO/IEC 27701 extends your ISMS into a privacy information management system and is increasingly expected where you process personal data at scale; readiness establishes the privacy controls the standard requires.
A staged approach built to deliver a defensible outcome.
Defining the PIMS scope and your roles as controller or processor.
Assessing current state against ISO 27701 over your ISMS.
Mapping PII processing and assessing privacy risk.
Implementing the privacy controls and documentation.
A full internal audit and management review.
Preparing for and supporting the certification audit.
The work is mapped to the standards and rules that apply to you.
What to have in place before we begin.
Explore this offering in detail.
Learn more →Explore this offering in detail.
Learn more →Explore this offering in detail.
Learn more →Back to the full pillar.
View pillar →Tell us your goals and constraints, and we’ll shape the right engagement.