Skip to main content
FRAMEWORK

Privacy management, extending your ISMS.

ISO/IEC 27701 turns an information security management system into a privacy one. It extends ISO 27001 and 27002 with the requirements and guidance a Privacy Information Management System needs — separately for organizations acting as controllers and as processors — and it cannot be certified on its own. You certify to 27701 as an extension of an existing 27001 certificate, or pursue both together. The privacy system sits on top of the security system; it does not replace it.

That dependency is the whole point and also the trap. The security controls you already operate — access, logging, encryption, supplier management — are most of what protects personal data. What 27701 adds is the privacy-specific layer: lawful basis, purpose limitation, data subject rights, records of processing, transfers. Run as a separate project by a separate team, that layer duplicates the controls underneath it and disagrees with them by the second audit.

Who it applies to

Organizations that already hold, or are pursuing, a 27001 certificate and process personal data at a scale where someone wants assurance about it — customers, regulators, or a group privacy function. The standard distinguishes controller and processor obligations, so a SaaS provider and its enterprise customer can both certify to it while carrying different control sets.

27701 and the GDPR

27701 is not a GDPR certificate and no auditor will tell you otherwise. What it does is give the GDPR's accountability principle a management system to live in: the record of processing activities, the data protection impact assessments, the data subject request handling and the processor contracts all have a home, an owner and a review date. Annex D of the standard maps its controls to GDPR articles for exactly this reason. Because the PIMS runs on the same control library as the ISMS, the 72-hour breach notification under Article 33 and the incident process 27001 already requires are one workflow with two clocks — not two teams discovering the same event separately.

What it asks, in operating terms

Read as an operating requirement rather than an extension document, 27701 reduces to a handful of standing asks layered on top of the ISMS you already run.

ISO 27701 requirements · how TruSecure answers them
What the standard asksWhere it is answered
Extend the ISMS, do not duplicate itShared control library · privacy controls layered on the same entries
Know whether you are controller or processor, per activityProcessing register · role recorded per processing activity
Hold records of processing that stay currentProcessing register · owner and review date per entry
Handle data subject requests, with the clock runningRequest workflow · clocked, sealed record
Show the GDPR mapping an auditor or regulator asks forPer-regime exports · Annex D view of the same controls

What you'd actually look at

In the dashboard, every figure opens on click to the activity, the control and the person behind it. This excerpt is what a PIMS file is made of:

PIMS file · excerptSample data
Processing activities
34 · 21 as controller, 13 as processor
Privacy controls
layered on the ISMS · no duplicate set
Data subject requests
7 this quarter · all clocks met
GDPR mapping
Annex D · generated from live control state
Auditor export
sealed · sha256:c4e6...38b9

Where teams usually start

With a demo walked through by TruSecure — your processing activities in one register, a single privacy control opened to show it sits on an ISMS control you already evidence, the GDPR mapping generated rather than maintained. The certificate itself comes from an accredited certification body; TruSecure prepares and maintains the evidence, and holds no certification of its own yet. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

ISO/IEC 27701 extends ISO 27001 into a certifiable Privacy Information Management System, and cannot be certified independently of 27001. It supports GDPR compliance.