🔐

ISO/IEC 27701

Security techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management - Requirements and guidelines

Organization: ISO/IEC Category: Privacy Management
10
Related Articles
22
Articles with Obligations
5
Key Sections
10
Coverage Areas

Overview

Extends ISO 27001 and ISO 27002 with specific requirements and guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS). Maps directly to GDPR requirements and provides a certifiable framework for privacy compliance.

Applicability

Privacy information management systems (PIMS) for GDPR compliance

Relevance to Digital Services Act (DSA)

Key Coverage Areas

1
Privacy Information Management System (PIMS)
2
PII controller obligations (GDPR Articles 5-11, 12-22, 24-43)
3
PII processor obligations (GDPR Article 28)
4
Data subject rights implementation
5
Privacy by design and by default
6
Data protection impact assessments (DPIAs)
7
Records of processing activities
8
Data breach notification
9
International data transfers
10
Consent management

Standard Sections & Chapters

5

PIMS-specific requirements (extends ISO 27001 clause 5)

6

PIMS-specific guidance for PII controllers

7

PIMS-specific guidance for PII processors

A.7

PII controller controls (mapping to GDPR)

A.8

PII processor controls (mapping to GDPR)

Related Digital Services Act (DSA) Articles

Article 14: Terms and conditions

View Article →
Sections: A.7.2.2, A.7.4.1

Transparency and accountability in policy communication

Implementation Guidance:

Ensure terms and conditions comply with privacy and transparency requirements

Mapped Obligations:

  • Describe content moderation methods (algorithms, human review) and complaint procedures

Article 15: Transparency reporting obligations for providers of intermediary services

View Article →
Sections: A.7.4.1, A.7.4.8

Transparency and records of processing

Implementation Guidance:

Implement transparent reporting mechanisms per ISO 27701

Mapped Obligations:

  • Publish annual transparency reports in machine-readable format
  • Report complaint handling metrics including processing times and decisions

Article 16: Notice and action mechanisms

View Article →
Sections: A.7.3.2, A.7.3.4

Data subject requests and complaints

Implementation Guidance:

Handle user complaints with privacy compliance

Mapped Obligations:

  • Implement user-friendly electronic reporting mechanisms for illegal content

Article 17: Statement of reasons

View Article →
Sections: A.7.4.1, A.7.4.5

Transparency and explanation of decisions

Implementation Guidance:

Provide clear reasoning for content moderation decisions

Article 24: Transparency reporting obligations for providers of online platforms

View Article →
Sections: A.7.2.1, A.7.2.2

Identity verification and data collection

Implementation Guidance:

Verify trader identities while maintaining privacy compliance

Mapped Obligations:

  • Report all account suspensions categorized by reason (illegal content, false notices, false complaints)
  • Ensure no personal data is included in any submitted information

Article 27: Recommender system transparency

View Article →
Sections: A.7.4.1, A.7.4.5

Transparency in algorithmic decision-making

Implementation Guidance:

Provide transparency about recommender system parameters and logic

Article 28: Online protection of minors

View Article →
Sections: A.7.2.4, A.7.4.1

Consent and transparency for advertising

Implementation Guidance:

Ensure advertising complies with privacy and transparency requirements

Mapped Obligations:

  • Implement appropriate and proportionate measures for high level of privacy, safety, and security for minors
  • Must not use personal data profiling for advertising to known minors
  • Comply without processing additional personal data to determine if users are minors

Article 33: Very large online platforms and very large online search engines

View Article →
Sections: A.7.2.5, A.7.4.1

User-friendly design and transparency

Implementation Guidance:

Design interfaces with privacy by design principles

Mapped Obligations:

  • Maintain transparency about monthly active user counts for ongoing designation assessment

Article 37: Independent audit

View Article →
Sections: 9.2

Privacy audits

Implementation Guidance:

Include privacy compliance in audit scope

Mapped Obligations:

  • Maintain confidentiality while enabling transparency reporting

Article 42: Transparency reporting obligations

View Article →
Sections: A.7.4.1, A.7.4.8

Enhanced transparency and reporting

Implementation Guidance:

Publish comprehensive transparency reports meeting DSA requirements

Mapped Obligations:

  • Publish transparency reports within 2 months of designation and then every 6 months

Quick Information

Organization
ISO/IEC
Category
Privacy Management
Certification
✓ Available

🤝 Still Feeling Overwhelmed?

EU cybersecurity laws can be complex. Our free tools and guides work great for most people, but if you're dealing with something particularly challenging or have tight deadlines, we're here to help.