ISO 27701: Data Compliance Management System Supporting GDPR Compliance
What is ISO 27701?
ISO/IEC 27701:2019 is a data privacy extension to ISO 27001. This newly published information security standard provides guidance for organizations looking to put in place systems to support compliance with GDPR and other data privacy requirements. ISO 22701, also abbreviated as PIMS (Privacy Information Management System) outlines a framework for Personally Identifiable Information (PII) Controllers and PII Processors to manage data privacy. Privacy information management systems are sometimes referred to as personal information management systems.This reduces risk to the privacy rights of individuals and to the organisation by enhancing an existing Information Security Management System.
This standard is a great way of demonstrating to customers, external stakeholders and internal stakeholders that effective systems are in place to support compliance to GDPR and other related privacy legislation.
Organizations looking to get certified to ISO 27701 in order to comply with GDPR will either need to have an existing ISO 27001 certification or implement ISO 27001 and ISO 27701 together as a single implementation audit. ISO 27701 is a natural expansion to the requirements and guidance set out in ISO 27001.
The ISO 27001 standard provides a framework for an Information Security Management Systems (ISMS) that enables the continued confidentiality, integrity and availability of information as well as legal compliance. More than 60,000 organizations worldwide have certified to date to ISO 27001, proving certification to be an essential part of protecting your most vital assets.
The significant overlap in system and technical requirements between a privacy information management system and an information security system presents a compelling case to adopt ISO 27001 and ISO 22701. This is supported by the international recognition of an ISO standard.
- GDPR compliance
- Privacy rights of individuals
- Continued confidentiality
- IT governance
- Data breaches
- Securing personal information
- Building customers trust
- Increasing customer satisfaction
- Protecting the organization’s reputation
Other risk management standards:
- ISO 27701 - GDPR Compliance
- ISO 20000-1 - IT Service Management
- ISO 22301 - Business Continuity
- ISO 44001 - Collaborative Working
- ISO 55001 - Asset Management
- ISO 41001 - Facilities Management
NOTE: We are currently offering certification to this scheme.
Benefits of ISO 27701 Certification
Is ISO 27701 certification right for me?
This standard is essential for organizations worldwide that are responsible for Personally Identifiable Information (PII). It provides a framework on how to manage and process data and safeguard privacy. ISO 22701 enhances an already implemented information security management system to address privacy requirements and put in place the systems and infrastructure to support compliance to legislation including GDPR.
The General Data Protection Regulations (GDPR) is in full swing. Since its implementation in May 2018, the EU's landmark legislation has brought sweeping change to data privacy rights, particularly who "owns" data, who controls it and who gets the final say in its uses and transactions in today's digital-first world.
Under the GDPR the upper limit could reach €20 Million or 4% of the annual global turnover of an organization - whichever is higher. Organizations also face significant reputational damage risk from non-compliance and data breaches. For some business this could posed a threat of bankruptcy or even closure.
The Information Commissioner’s Office (ICO) in the UK has indicated that organizations adopting certification or having a robust system in place to manage their data protection may be seen more favourably from a regulatory perspective in the event of a data breach.
Implementing a Privacy Information Management System (PIMS) in compliance with the requirements of ISO 27701 will enable organizations to assess, react and reduce risks associated with the collection, maintenance and processing of personal information. Certification to ISO 27701 does not confirm legal compliance to GDPR however it provides a valuable framework for any company to support their efforts in compliance to legislation.
Organizations can also consider implementing BS 10012:2017 with Annex A1:2018 as an alternative approach. This is for organizations seeking to implement a standalone Privacy Information Management System without ISO 27001.
Differences between ISO 27001 and ISO 27701
ISO 27701 is set to be the go to standard for compliance with GDPR regulations, in the same way that ISO 27001 is considered to be the ‘gold standard’ for information security management.
It aligns to GDPR but also allows organizations to use the standard to incorporate other privacy laws, regulations and requirements. This makes it an excellent choice for organizations of all industries and sizes looking to demonstrate their compliance with the ‘accountability’ principle of GDPR.
How to get certified to ISO 27701
If you already have accredited certification to ISO 27001 you will find applying the information risk management principals to personal information fairly straightforward.
The standards requires that organizations with certification to ISO 27001 must include privacy management, this means reviewing the organization’s contextual analysis, risk assessment and control environment to ensure that privacy management is incorporated.
The privacy information management system then needs to be documented. Organizations that are less confident in their GDPR compliance will find ISO 27701 particularly helpful as it provides specific recommendations for actions to comply with the regulation.
We can assess your compliance to ISO 27701 as an addition to your ISO 27001 assessment. We will ensure our approach follows the same method as the standard – looking at one system supporting information security and personal information management.
ТРИ СТЪПКИ ЗА СЕРТИФИЦИРАНЕ
Заявление за регистрация се прави чрез попълване на форма Заявка за оферта за избрания от Вас стандарт – тези форми могат да бъдат намерени на уеб-страницата за всеки стандарт. Тази форма ще даде информация за Вашата организация и ние ще можем точно да определим обхвата на сертификация и продължителността на одитиране.
Одитирането се извършва от NQA по специфичните изисквания на избрания от Вас стандарт. То се състои от две задължителни посещения за първоначален сертификационен одит (обяснено по-долу). Моля имайте в предвид, че Вие трябва да бъдете в състояние да докажете, че Вашата система за управление е напълно действаща от минимум три месеца и е била обект на пълен цикъл на вътрешни одити.
Сертификати се издават от NQA при успешно приключване на етап 2 на оценяването. Сертификацията се поддържа чрез програма от годишни контролни одити и ре-сертификационен одит през третата година.