Extend your information security system to demonstrate genuine, auditable privacy management.
ISO/IEC 27701:2019 is an extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management, specifying requirements for a Privacy Information Management System (PIMS).
It defines responsibilities for both data controllers and processors, mapping closely to obligations under the Australian Privacy Act and the GDPR.
No. It is an extension standard and requires ISO 27001 certification, either already held or achieved at the same time.
It does not confer compliance, but it maps closely to GDPR obligations and is strong supporting evidence.
Yes, and we recommend it — a combined assessment is significantly more efficient.
Speak with a dedicated Business Manager and get a transparent quote today.