Skip to content
ARROW Consulting
ISO 27701 privacy information management for GDPR

ISO 27701 - Privacy Information Management

The international extension of ISO 27001 for personal data management and GDPR compliance

ISO/IEC 27701:2019 (PIMS) is the extension of ISO 27001 for Privacy Information Management. It provides a framework for PII Controllers and PII Processors for managing personal data.

The standard maps directly to key GDPR requirements, such as data minimization, purpose limitation, accountability, and processing security. Annex D includes detailed mapping to the General Data Protection Regulation.

In Greece, ISO 27701 certification is a powerful tool for demonstrating compliance with GDPR (Regulation 2016/679) and Law 4624/2019 on personal data protection. The Hellenic Data Protection Authority (HDPA) encourages the use of certifications.

A prerequisite for ISO 27701 certification is holding ISO 27001 certification. The certification is valid for 3 years.

Who is this for

ISO 27701 is aimed at any organization processing personal data: technology companies, financial institutions, healthcare organizations, e-commerce companies, SaaS providers, HR companies, educational institutions, and public bodies. Particularly critical for Data Controllers and Data Processors.

Key Benefits

GDPR Compliance Evidence

Documented proof of GDPR compliance through internationally recognized certification.

Reduced Fine Risk

Minimized risk of GDPR fines that can reach 4% of global annual turnover.

Customer Trust

Enhanced customer trust through demonstrated commitment to personal data protection.

Competitive Differentiation

Market differentiation with certification demonstrating high privacy management standards.

Integrated Approach

Unified information security and data protection framework combined with ISO 27001.

ISO 27701 Certification Process

01
Step 1

Initial Assessment

Assessment of existing data protection practices and mapping of personal data flows.

02
Step 2

GDPR Gap Analysis

Identification of gaps from ISO 27701 and GDPR requirements, creation of action plan.

03
Step 3

Privacy Training

Staff training on GDPR principles, data subject rights, breach incident response.

04
Step 4

Documentation Development

Drafting privacy policy, DPIA, records of processing activities, rights management procedures.

05
Step 5

Certification

Support during ISO 27701 certification audit as an extension of existing ISO 27001.

ISO 27701 FAQ

Yes, ISO 27001 certification is a prerequisite for ISO 27701. They can be implemented simultaneously to save time and cost.

ISO 27701 aligns closely with GDPR, but does not automatically constitute official GDPR certification. However, it provides strong evidence of good practice.

As an ISO 27001 extension, the additional cost is 30-50% above ISO 27001. For SMEs, the 27001+27701 combination starts from EUR 15,000.

If ISO 27001 already exists, the extension to ISO 27701 is completed in 2-4 months. Simultaneous implementation of both: 8-14 months.

Annex D provides detailed mapping between ISO 27701 controls and GDPR articles, facilitating compliance documentation.

Protect personal data

Contact us for a free GDPR readiness assessment and ISO 27701 quote.