Requirements included in the framework

A.7
ISO 27701

Additional ISO/IEC 27002 guidance for PII controllers

A.7.2
ISO 27701

Conditions for collection and processing

A.7.2.1
ISO 27701

Identify and document purpose

A.7.2.2
ISO 27701

Identify lawful basis

A.7.2.3
ISO 27701

Determine when and how consent is to be obtained

A.7.2.4
ISO 27701

Obtain and record consent

A.7.2.5
ISO 27701

Privacy impact assessment

A.7.2.6
ISO 27701

Contracts with PII processors

A.7.2.7
ISO 27701

Joint PII controller

A.7.2.8
ISO 27701

Records related to processing PII

A.7.3
ISO 27701

Obligations to PII principals

A.7.3.1
ISO 27701

Determining and fulfilling obligations to PII principals

A.7.3.10
ISO 27701

Automated decision making

A.7.3.2
ISO 27701

Determining information for PII principals

A.7.3.3
ISO 27701

Providing information to PII principals

A.7.3.4
ISO 27701

Providing mechanism to modify or withdraw consent

A.7.3.5
ISO 27701

Providing mechanism to object to PII processing

A.7.3.6
ISO 27701

Access, correction and/or erasure

A.7.3.7
ISO 27701

PII controllers' obligations to inform third parties

A.7.3.8
ISO 27701

Providing copy of PII processed

A.7.3.9
ISO 27701

Handling requests

A.7.4
ISO 27701

Privacy by design and privacy by default

A.7.4.1
ISO 27701

Limit collection

A.7.4.2
ISO 27701

Limit processing