ISO 27701: a privacy management system on your ISO 27001 evidence
Extend the ISMS you already run into a privacy information management system: controller and processor controls mapped to automated checks and structured evidence, GDPR obligations cross-referenced, and the certification audit run where the evidence lives.
What is ISO 27701?
ISO/IEC 27701 is the international standard for a privacy information management system, a PIMS. It builds on ISO/IEC 27001 and 27002 by adding privacy-specific requirements to the management system clauses and privacy-specific guidance to the security controls, and it adds two sets of controls of its own: one for organizations that decide how and why personally identifiable information is processed, the PII controllers, and one for organizations that process it on another's behalf, the PII processors. The controller controls cover purposes, lawful basis, consent, transparency and the rights of the people whose data is held; the processor controls cover instructions from the controller, sub-processors, international transfers and breach support. The standard maps its controls to the GDPR, so a PIMS doubles as evidence of GDPR accountability. Certification follows the ISO two-stage audit model through an accredited certification body, with surveillance audits in between, and is most often held alongside an ISO 27001 certificate, since the PIMS is built on the ISMS.
ISO/IEC 27701 is the international standard for a privacy information management system (PIMS). It extends the ISO 27001 information security management system with requirements and controls for protecting personally identifiable information, with separate control sets for organizations that act as PII controllers and as PII processors, and it maps its controls to the GDPR and other privacy laws. Certification is issued by an accredited certification body and is most often held together with ISO 27001.
Companies that already hold or are pursuing ISO 27001 and whose customers in Europe, the UK or Asia-Pacific ask for proof that privacy, not only security, is managed.
How Viglyn runs ISO 27701
- The controller and processor control sets mapped to controls in the library, with automated checks where the evidence lives in connected systems and structured evidence requests where it does not
- Records of processing, consent and purpose records, data subject request handling and transfer mechanisms held as dated evidence with a full audit trail
- Sub-processor management in the vendor module, with agreements, assessments and the instructions that bind them
- Every clause and control shared with your ISO 27001 ISMS, so the privacy extension reuses the security evidence instead of duplicating it
- Stage 1 and Stage 2 run inside Viglyn, with scoped auditor access and workpapers that export with integrity hashes
The ISO 27701 questions that decide it
Do we need ISO 27001 before ISO 27701?
The PIMS is built on an ISMS, so in practice ISO 27701 is implemented and audited together with ISO 27001, and most certificates are issued alongside it. If you already hold ISO 27001, the extension reuses most of your evidence; if you do not, Viglyn runs both from one evidence base.
How long does ISO 27701 take?
Two to four months on top of an existing ISO 27001 management system is typical, because the security clauses carry over. Mapping your processing activities and writing the privacy-specific records is the work; our practitioners do it with you.
How much does ISO 27701 cost with Viglyn?
ISO 27701 counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. The certification body's fee is separate and paid by you directly; we take no commission.
ISO 27701 against the standards it is weighed with
More ISO 27701 questions
Is ISO 27701 the same as GDPR compliance?
Are we a PII controller or a PII processor?
Can ISO 27701 share evidence with SOC 2?
See ISO 27701 run on your stack
A 30-minute walkthrough with your systems and your framework. No commitment.
