The privacy-information management extension of ISO/IEC 27001 — operationalises GDPR controls.
ISO/IEC 27701 is an extension of ISO/IEC 27001 for managing personal data. It adds a Privacy Information Management System (PIMS) on top of the ISMS, with controls that map to the responsibilities of data controllers and data processors.
ISO 27701 is the closest thing the industry has to a certifiable bridge between security management (27001) and EU privacy law (GDPR). Certification gives a structured, auditable demonstration that the organisation operates the privacy controls a regulator would expect — without supplanting the legal obligation itself.
Silbad's federated architecture means that customer personal data does not enter our infrastructure in the first place. ISO 27701 controls govern the limited categories of personal data we do process — staff records, contractual contacts.