Privacy Information Management System

ISO 27701 is a data privacy extension to ISO 27001. This standard provides the framework for organizations looking to put in place a system
to support compliance with data privacy requirements. ISO 27701, also referenced as PIMS (Privacy Information Management System), outlines a framework for Personally Identifiable Information (PII) Controllers and PII Processors to manage data privacy.

What is 27701 ?
ISO 27701 is the first international standard that deals with privacy information management. The standard will assist organizations to establish, maintain and continually improve a Privacy Information Management System (PIMS) by enhancing the existing ISMS. It can be used by all types of organizations irrespective of their size, complexity or the country they operate.

Why ISO 27701?
This standard is essential for every organization that is responsible and accountable for Personally Identifiable Information (PII) as it provides requirements on how to manage and process data and safeguard privacy. There are more advantages :

  • Understand the Privacy Information Management System implementation process.
  • Acquire the necessary skills to support an organization in implementing a Privacy Information Management System in compliance with the ISO/IEC 27701 information.
  • Support the continuous improvement process of the Privacy Information Management System within organizations.
  • Protect the organization’s reputation
  • Build customer’s trust
  • Increase customer satisfaction
  • Increase transparency of the organization’s processes and procedures.
  • Maintain the integrity of customers’ and other interested parties’.