A black and white image of white hand holding an iPad with a padlock icon on the screen and the word privacy below it

What is ISO/IEC 27701, and do I need a privacy extension?

September 27th, 2021 By

As the digital world transforms before our eyes, so are the ways companies are operating and conducting business. As times change and technology is developed, more and more companies are inquiring about additions to their information security management system (ISMS) to ensure optimum security of their customers data.

As protecting data is at the forefront of most businesses, ISO 27001 has gained lots of interest in most recent years. Seen as a ‘gold-standard’ for security frameworks, ISO 27001 is an excellent foundation for creating an ISMS. However, lately we have seen clients wanting to go a step further and invest in enhanced privacy by adding a privacy extension through ISO 27701.

ISO 27701 was published in 2019 and is a privacy extension that allows you to extend your current system to include a privacy information management system (PIMS).

Do I need a privacy information management system (PIMS)?

A survey by Acquia discovered that: “65% of respondents would cease using a company that was dishonest about how it was using their data”.

With so many data breaches and hacker attacks in the news, it’s no wonder customers are growing more aware and concerned about how their personal data is being used. Not to mention with mandatory requirements, such as GDPR, protecting personally identifiable information (PII) has never been more crucial.

Adding a privacy extension is the most appropriate way to show clients, regulators, and other stakeholders that you have a robust privacy programme. Demonstrating compliance with privacy regulations may boost revenue and increase trust within consumers.

Why was ISO 27701 developed?

As a type of privacy information management system (PIMS), ISO 27701 creates a framework for privacy controls. This PIMS is an extension to ISO 27001 and can be implemented alongside the ISO 27001 standard or after your are ISO 27001 certified.

The primary purpose of ISO 27701 is to:

  • Strengthen your existing information security management system (ISMS) with privacy-related controls through PIMS
  • Reduce the complexity of managing compliance with multiple, overlapping privacy regulations like GDPR and California’s CCPA
  • Build a privacy programme that’s internationally recognised
  • Assist with GDPR compliance, and serve as a foundation for efficiently managing privacy
  • Detail required functions and define the privacy controls for PIMS data processors and controllers

The Data Protection Act 2018 and the General Data Protection Regulation require organisations to ensure the privacy of any personal information they process. However, none of these laws provide sufficient guidance on what those measures should look like.

Therefore, the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) developed ISO/IEC 27701 as the new standard to provide that guidance. Having ISO 27001 certification with the ISO 27701 privacy extension demonstrates your commitment to data privacy.

What are the benefits of a privacy extension?

A privacy extension provides guidance and requirements regarding protection for PII controllers and processors. The scope of the standard covers all types and sizes of businesses, public, and private companies, government entities, and not-for-profit organisations processing PII with an ISMS.

benefits of ISO 27701 include:

  1. International recognition of your business: Allowing your business to grow and enter new markets. Implementing an internationally recognised standard and an acknowledged framework to your organisation will enable a mature organisational privacy programme.
  2. Global privacy compliance made easy: Complying with this standard enables the processing carried out by your organisation to be compliant with all legal and regulatory requirements. The standard also maps out how to comply with GDPR requirements, which can further help organisations demonstrate accountability while managing PII and instil trust and confidence in their stakeholders. Using this standard can be a good privacy metric.
  3. It helps identify risks: Businesses process personal information about individuals, including sensitive information, posing security risks. This gives precise requirements on what actions should be taken and how to protect assets and personal data.

When you look at all the benefits of the privacy extension, adopting these clauses will allow you to establish an excellent privacy policy. A PIMS is extremely useful, either presently to upgrade your regulatory compliance levels or to tap into future business opportunities.

How does ISO 27701 relate to ISO 27001?

As ISO 27001 is a prerequisite for ISO 27701, the privacy extensions is specifically designed for your ISMS. Therefore, if ISO 27001 is considered the ‘gold-standard’ for an information security management system, then ISO 27701 aims to become the ‘go-to-standard’ for implementing a privacy information management system.

These standards share a significant overlap in requirements, making the adoption of ISO 27701 a smooth addition to your ISO 27001 ISMS. Talk to one of our local experts today and learn how implementing an ISO 27701 privacy extension could benefit your company today.

Get your free quote for ISO 27701

Contact Us

For a free quotation or remote presentation by an ISO specialist, contact us today.

IMSM Ltd Head Office
The Gig House
Oxford Street
Malmesbury
Wiltshire
SN16 9AX

Tel: +44 1793 296704

Contact Us

For a free Quotation or On-Site presentation by an ISO Specialist, contact us today!

IMSM Ltd Head Office The Gig House
Oxford Street
Malmesbury
Wiltshire
SN16 9AX

Tel: 01666 826 065