ISO 27701Data PrivacyGlobalAll Industries

ISO/IEC 27701 Privacy Information Management System

International standard extending ISO 27001 to include privacy management. Provides framework for PII controllers and processors to demonstrate compliance with privacy regulations.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

ISO 277017.2.2Knowing where the data isA record of access

Purpose Limitation

PII controllers MUST ensure processing is limited to identified purposes with audit trail evidence.

You cannot evidence a control over data you have not located. Discovery scans every connected store continuously and classifies what it finds against 200+ built-in patterns and 20+ categories, so the inventory reflects the estate as it is today rather than as it was at the last manual survey. Because the classification is what ranks the scanning and shapes the reports, it cannot quietly go stale without something visibly breaking.

ISO 277017.2.6Attribution to an individual

Access Recording

Organizations MUST record access to PII including who accessed, when, and for what purpose.

"Each individual user" is the hard half of this kind of requirement, not "audit trail". Most estates fail it at the connection-pool boundary, where twenty analysts arrive as one service account. Real-time SQL auditing resolves the database session, the OS user, the client host, and the application context on every statement, so access resolves to a person rather than to app_user. User behaviour analytics keeps that attribution useful over time by baselining what each identity normally does — which is how a shared credential looks different from a compromised one.

ISO 277018.2.2Policy, procedure, and documentationA record of access

Processor Obligations

PII processors MUST ensure personnel are bound by confidentiality and log all processing activities.

This mandate asks for documented policy and procedure rather than telemetry, so the platform is the evidence layer beneath it rather than the control itself. Our advisory engagements organise that documentation — a gap register mapping each requirement to its current state and a named owner, a sequenced remediation roadmap, and quarterly auditor-ready packs — and we answer the database-controls questions during the audit window. Drafting and owning the policy stays with you; assembling the evidence that it operates does not have to.

ISO 277017.3.6Detecting it in time to notify

Breach Response

Organizations MUST have procedures to notify authorities and data subjects of PII breaches.

Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.

What ISO 27701 covers

ISO/IEC 27701:2019, terms borrowed from ISO/IEC 29100

Personally identifiable information — any information that can be used to identify a PII principal, or that is or might be linked to one.

In scope

  • Information identifying a PII principal
  • Information linkable to a PII principal

The standard deliberately uses its own vocabulary rather than any statute’s, so it can be mapped onto whichever law applies. That makes it a translation layer, not a definition of scope in its own right.

ISO/IEC 27701 · as at 2026-08

How ISO 27701 is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by Your certification body, as an extension to an ISO 27001 certificate.

A voluntary standard. No regulator enforces it.

ISO 27701 extends an information security management system to cover privacy. It cannot be certified on its own, and no authority enforces it. Its value is evidentiary: it is a structured way of showing a supervisory authority or a customer what your privacy programme actually does.

A certificate is evidence of a management system, not evidence of compliance with any privacy law.

Uncapped exposure that sits outside this instrument

These come from company law rather than from ISO 27701, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for ISO 27701,
not configured for it afterwards

Policy Template

PIMS Access Control

Track all access to PII with purpose limitation verification

Report

ISO 27701 Audit Evidence

Certification-ready documentation of privacy controls

Classification

PII Processing Patterns

Identify and categorize personal information processing

Alert

Purpose Limitation Violation

Alert when PII accessed outside identified purposes

Other Data Privacy frameworks

Walk into the ISO 27701 audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment