ISO 27701 is a privacy extension to ISO 27001. The framework aims to upgrade the existing Information Security Management System (ISMS) with additional requirements related to processing and protecting personal data in order to establish also a Privacy Information Management System (PIMS).
- Documentation related to processing activities, transfers and disclosures of personal data.
- Tasks related to data subject rights and ensuring lawfulness of processing.
- Advanced privacy-related tasks about ensuring proper consent and filling other requirements for personal data controllers and processors.
Certifications are available for ISO 27701. As the framework extends ISO 27001, organizations seeking an ISO 27701 certification will need to have the ISO 27001 certification.