ISO/IEC 27701 Privacy Information Management System
ISO/IEC 27701:2019 is a certifiable extension to ISO 27001 and ISO 27002, providing guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS).
As the leading provider of information security certification in Australia, Intertek SAI Global is positioned to help you achieve your privacy certification objectives. Our national network of expert auditors combined with our industry-leading customer service teams ensures you understand what your audit involves, and how to prepare.


Key Benefits of ISO/IEC 27701 Certification
Build Trust in Managing Personal Information
Meet Regulatory Requirements
Drive Business Opportunities
What Is ISO/IEC 27701:2019?
ISO/IEC 27701:2019 is the internationally benchmarked standard for Privacy Information Management Systems (PIMS) and provides guidance on policies and procedures needed to comply with data protection and privacy regulations.
Designed to be implemented with ISO 27001 or added to an existing ISO 27001 Information Security Managment System, ISO 27701 provides guidance for protecting data privacy. It takes into account the privacy protections required for controlling or processing personally identifiable information (PII), and ensures your processes and systems are limited to what is necessary for its purpose.
Intertek SAI Global is the largest JAS-ANZ accredited Certification Body to deliver ISO/IEC 27001 certification. This means that Intertek SAI Global’s processes, systems and auditors are rigorously assessed to ensure you receive the best in customer support and delivery.
Clauses 1-3 of the ISO/IEC 27701:2019 standard outlines the requirements and provides guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS). It mentions the normative references used in the standard, as well as the terms, definitions and abbreviations that apply.
Clause 4 of ISO/IEC 27701:2019 provides the structure of the standard. It shows the location of PIMS-specific requirements and controls that impact ISO 27001:2013 and ISO 27002:2013.
Clause 5 of ISO/IEC 27701:2019 extends the requirements of ISO/IEC 27001 to incorporate privacy protection.
In this clause, your organisation needs to determine whether you act as a processor and/or a controller. Depending on your role, you will need to implement relevant controls specified in Annexes A and/or B.
Requirements for leadership, planning, support, operation, performance evaluation and improvement in ISO 27001 must be evaluated and extended to ensure the protection of privacy.
Clause 6 of ISO/IEC 27701:2019 extends the controls found in ISO/IEC 27002 to incorporate privacy protection.
The clause ensures you consider Personally Identifiable Information (PII) before data transmission occurs, as part of system development and design.
More implementation guidance is included on incident management, removable media, user access on systems and services that process PII, cryptographic protection, re-assigning storage space that previously stored PII, back-up and recovery of PII, event log reviews, information transfer policies, confidentiality agreements and supplier relationships.
In clause 7 of the ISO/IEC 27701 Standard, specific implementation guidance is provided for PII controllers, with additional controls referenced in Annex A.
This guidance outlines considerations of special category data and consent requirements, privacy impact assessment requirements to minimise risk to PII principals, contracts with PII processors and clear roles and responsibilities with joint controllers.
Clause 8 of ISO/IEC 27701 outlines the specific requirements for PII processors, with additional controls referenced in Annex B.
Guidance is outlined to identify and maintain the necessary records to help demonstrate compliance with agreed PII processing you conduct.
The clause also provides specifications for helping you customer respond to requests, managing temporary files created during processing, returning, transferring or disposing PII securely and appropriately.
ISO/IEC 27701 contains 6 Annexes to provide further guidance on implementing effective privacy information management systems. Annex A and B are specific to PII controllers and processors, whereas Annexes C-F provide additional support for setting up and operating a PIMS.
- Annex A – List of controls for PII Controllers
- Annex B – List of controls for PII Processors
- Annex C – Mapping of Controls for PII Controllers to the ISO/IEC 2900 privacy principals
- Annex D – Mapping of ISO/IEC 27701 clauses to GDPR articles 5 to 49 (except 43)
- Annex E – Mapping of ISO/IEC 27701 clauses to ISO/IEC 27018 and ISO/IEC 29151
- Annex F – Details on how to apply ISO/IEC 27701 to ISO/IEC 27001 and ISO/IEC 27002
5 Steps to Certification
Getting certified can be a daunting prospect, however we’ve helped break it down into 5 simple steps.
Frequently Asked Questions
According to the ISO/IEC 27701:2019 standard, a PII Controller is the entity that determines the purpose and means for processing Personally Identifiable Information (PII). They define why and how PII is processed, and are responsible for the implementation of privacy and security processes to meet applicable legal requirements. This includes Joint PII Controllers.
A PII Processor processes Personally Identifiable Information (PII) on behalf of the PII Controller, in accordance to their specifications.
Where ISO/IEC 27001 is the internationally recognised standard for Information Security Management Systems, bridging the gap between risk management and security controls, ISO/IEC 27701 extends ISO/IEC 27001 to incorporate Privacy Information Security Management Systems.
Are You Ready To Take The Next Step to Certification?
ISO 27001 Training Courses
As a leading provider of education and training, SAI Global Assurance offers a wide range of training courses to help you learn, plan, implement, assess and improve your management system.