ISO standard

ISO/IEC 27701

The privacy-information management extension of ISO/IEC 27001 — operationalises GDPR controls.

What it is

ISO/IEC 27701 is an extension of ISO/IEC 27001 for managing personal data. It adds a Privacy Information Management System (PIMS) on top of the ISMS, with controls that map to the responsibilities of data controllers and data processors.

Why it matters in practice

ISO 27701 is the closest thing the industry has to a certifiable bridge between security management (27001) and EU privacy law (GDPR). Certification gives a structured, auditable demonstration that the organisation operates the privacy controls a regulator would expect — without supplanting the legal obligation itself.

What it adds over 27001

See also

Authoritative sources

How this matters in our work

Silbad's federated architecture means that customer personal data does not enter our infrastructure in the first place. ISO 27701 controls govern the limited categories of personal data we do process — staff records, contractual contacts.