Compliance · Privacy extension
Turn privacy promises into a system you can certify.
ISO/IEC 27701 extends ISO 27001 and 27002 into a privacy information management system. It's the closest thing to a certifiable, internationally recognized way to demonstrate that your privacy program is real — and it maps cleanly onto GDPR obligations.
27001+
Extension of
Both
Controller & processor
GDPR
Maps to
27701 takes the ISMS discipline you already have and points it at personal data.
The standard has separate control sets for when you decide the purpose of processing (controller) and when you process on someone's behalf (processor). Most companies are both, in different places.
27701 assumes ISO 27001. You extend the scope, risk assessment, and SoA to cover privacy rather than starting a parallel program.
Annexes map controls to GDPR articles and other privacy regimes — which is what makes it useful as evidence to regulators and customers.
Organizations under multiple privacy regimes that need one defensible system.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
We determine where you're a controller and where you're a processor — the answer changes which controls apply.
We build the records of processing, data flows, lawful bases, and retention that everything else depends on.
We extend your ISMS scope, risk assessment, and SoA to cover privacy properly.
We operationalize access, deletion, portability, and objection so requests are handled inside statutory clocks.
We stand up impact assessments and handle cross-border transfer mechanisms.
We prepare the evidence for certification alongside your 27001 audit.
Define PIMS scope and where you act as controller vs. processor.
Build the ROPA, flows, lawful bases, and retention schedule.
Close privacy control gaps and wire up rights handling.
Internal audit and management review across the PIMS.
Extend your 27001 certification scope to include 27701.
It gets you most of the way and gives you defensible evidence, but no certification makes you automatically compliant with a law. GDPR includes obligations — lawful basis decisions, regulator relationships, specific notices — that live outside the standard. We map 27701 to GDPR and handle the remainder explicitly.
Effectively yes. 27701 is written as an extension and is certified as an extension of a 27001 certification. If you don't have an ISMS, we build them together rather than sequentially, which is usually cheaper.
It's growing, particularly with multinationals and companies facing the patchwork of US state privacy laws. It's less commonly demanded than SOC 2 in US-only B2B, but valuable when you need one system that satisfies several regimes at once.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.