Compliance · Privacy extension

ISO/IEC 27701 — privacy information management (PIMS)

Turn privacy promises into a system you can certify.

ISO/IEC 27701 extends ISO 27001 and 27002 into a privacy information management system. It's the closest thing to a certifiable, internationally recognized way to demonstrate that your privacy program is real — and it maps cleanly onto GDPR obligations.

27001+

Extension of

Both

Controller & processor

GDPR

Maps to

What a PIMS involves

27701 takes the ISMS discipline you already have and points it at personal data.

Controller and processor

The standard has separate control sets for when you decide the purpose of processing (controller) and when you process on someone's behalf (processor). Most companies are both, in different places.

Built on the ISMS

27701 assumes ISO 27001. You extend the scope, risk assessment, and SoA to cover privacy rather than starting a parallel program.

Regulation mapping

Annexes map controls to GDPR articles and other privacy regimes — which is what makes it useful as evidence to regulators and customers.

Who needs ISO 27701

Organizations under multiple privacy regimes that need one defensible system.

  • Companies subject to GDPR, and increasingly US state privacy laws
  • Processors asked to prove privacy maturity in diligence
  • ISO 27001-certified organizations extending into privacy
  • Multinationals reconciling several privacy regulations at once

How intSignal gets you there

We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.

Role mapping

We determine where you're a controller and where you're a processor — the answer changes which controls apply.

Data mapping & ROPA

We build the records of processing, data flows, lawful bases, and retention that everything else depends on.

PIMS build

We extend your ISMS scope, risk assessment, and SoA to cover privacy properly.

Data subject rights

We operationalize access, deletion, portability, and objection so requests are handled inside statutory clocks.

DPIAs & transfers

We stand up impact assessments and handle cross-border transfer mechanisms.

Audit readiness

We prepare the evidence for certification alongside your 27001 audit.

How the engagement runs

1

Scope & roles

Define PIMS scope and where you act as controller vs. processor.

2

Map data

Build the ROPA, flows, lawful bases, and retention schedule.

3

Implement

Close privacy control gaps and wire up rights handling.

4

Assess

Internal audit and management review across the PIMS.

5

Certify

Extend your 27001 certification scope to include 27701.

Frequently asked questions

Does ISO 27701 make us GDPR compliant?

It gets you most of the way and gives you defensible evidence, but no certification makes you automatically compliant with a law. GDPR includes obligations — lawful basis decisions, regulator relationships, specific notices — that live outside the standard. We map 27701 to GDPR and handle the remainder explicitly.

Do we need ISO 27001 first?

Effectively yes. 27701 is written as an extension and is certified as an extension of a 27001 certification. If you don't have an ISMS, we build them together rather than sequentially, which is usually cheaper.

Is ISO 27701 recognized in the US?

It's growing, particularly with multinationals and companies facing the patchwork of US state privacy laws. It's less commonly demanded than SOC 2 in US-only B2B, but valuable when you need one system that satisfies several regimes at once.

Other frameworks we support

Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.

ISO 27701 for your environment

Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.