ISO 27701
ISO 27701:2019 extends an ISO 27001 ISMS into a privacy information management system. It is the standard to reach for when customers, regulators or data protection authorities want evidence that personal data is governed, not just secured. It builds on ISO 27001 — the ISMS is the foundation, and Complyanz enforces that.
Privacy management, integrated into your ISMS
How an ISO 27701 program runs
Establish the ISMS
ISO 27701 requires ISO 27001 as its foundation. If the ISMS is not in place yet, that is where the program starts.
Determine your PII role
Record whether the organization acts as a PII controller, a PII processor, or both. That choice drives which privacy controls and risks apply.
Privacy controls and risks
Work through the 78 privacy controls and the privacy risks that attach to the personal data you hold.
Integrated documentation
Generate the integrated 38-document library covering both information security and privacy in one consistent set.
Privacy on top of security, in one system
ISO 27701 cannot be run on its own — it is an extension, and Complyanz enforces that ISO 27001 is enabled first. The payoff is that you maintain one management system: shared clauses live in one place and the privacy requirements slot into the documents you already keep current.
ISO 27701 FAQ
Can we certify to ISO 27701 without ISO 27001?
No. ISO 27701 is an extension to ISO 27001 and requires it as the foundation. Complyanz enforces this: enabling the privacy module without ISO 27001 is blocked rather than silently producing an invalid program.
Does this cover GDPR?
ISO 27701 is a management system standard, not a law. Its controls map onto many of the operational expectations GDPR places on controllers and processors, which is why organizations use it as the framework for demonstrating privacy governance. It is not a substitute for legal advice on your specific obligations.
What changes in our documents when we add privacy?
The library moves from 36 documents to 38 integrated ones. The shared policies gain their privacy content in place rather than being duplicated into a parallel privacy pack.
What does controller versus processor change?
The two PII role categories determine which privacy controls and risk scenarios apply to you. A shared set applies to either role, and the platform removes duplicates across your register.
Add privacy to your management system
Enable ISO 27701 alongside ISO 27001 and the privacy controls, risks and integrated documents are ready to work with.