ISO 27701:2019 and the GDPR
The EU General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018 (DPA) both require organisations to protect and ensure the privacy of any personal data which they process. ?However, neither the GDPR nor the DPA provide much guidance on what measures organisations should take to safeguard the privacy of that data. ?This is where ISO/IEC 27701:2019 (ISO 27701) fits in, by providing you with a best practice framework to implement a privacy information management system (PIMS) and improve your data protection/data privacy capabilities.
The Standard, which was published in August 2019, provides the requirements and guidance for establishing, implementing, maintaining and continually improving a PIMS as an extension of ISO/IEC 27001:2013 and ISO/IEC 27002:2013. ?ISO 27701 outlines a framework for personally identifiable information (PII) controllers and PII processors to manage privacy controls so that the risk to individual privacy rights is reduced.
Whilst naturally influenced by the release of the GDPR, ISO 27701 is unique in that it has been designed to provide a framework on how organisations should manage personal information and demonstrate compliance, irrespective of which local privacy regime applies, including the GDPR.
领英推荐
Benefits of implementing and certifying against ISO 27701:2019
You will be able to:
How do I achieve certification to ISO 27701?
If your organisation has already achieved certification to ISO 27001, you should find it relatively straightforward to extend your security efforts to include your processing of PII. ISO 27701 has been designed to be used by both data controllers and data processors alike. If your organisation has not implemented an ISMS, you can implement ISO 27001 and ISO 27701 simultaneously as a single project, however, ISO 27701 cannot be implemented as a standalone management system standard.