ISO/IEC 27701 Privacy Information Management System
International standard extending ISO 27001 to include privacy management. Provides framework for PII controllers and processors to demonstrate compliance with privacy regulations.
What ISO 27701 draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Purpose Limitation
PII controllers MUST ensure processing is limited to identified purposes with audit trail evidence.
You cannot evidence a control over data you have not located. Discovery scans every connected store continuously and classifies what it finds against 200+ built-in patterns and 20+ categories, so the inventory reflects the estate as it is today rather than as it was at the last manual survey. Because the classification is what ranks the scanning and shapes the reports, it cannot quietly go stale without something visibly breaking.
Access Recording
Organizations MUST record access to PII including who accessed, when, and for what purpose.
"Each individual user" is the hard half of this kind of requirement, not "audit trail". Most estates fail it at the connection-pool boundary, where twenty analysts arrive as one service account. Real-time SQL auditing resolves the database session, the OS user, the client host, and the application context on every statement, so access resolves to a person rather than to app_user. User behaviour analytics keeps that attribution useful over time by baselining what each identity normally does — which is how a shared credential looks different from a compromised one.
Processor Obligations
PII processors MUST ensure personnel are bound by confidentiality and log all processing activities.
This mandate asks for documented policy and procedure rather than telemetry, so the platform is the evidence layer beneath it rather than the control itself. Our advisory engagements organise that documentation — a gap register mapping each requirement to its current state and a named owner, a sequenced remediation roadmap, and quarterly auditor-ready packs — and we answer the database-controls questions during the audit window. Drafting and owning the policy stays with you; assembling the evidence that it operates does not have to.
Breach Response
Organizations MUST have procedures to notify authorities and data subjects of PII breaches.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
What ISO 27701 covers
ISO/IEC 27701:2019, terms borrowed from ISO/IEC 29100
Personally identifiable information — any information that can be used to identify a PII principal, or that is or might be linked to one.
In scope
- Information identifying a PII principal
- Information linkable to a PII principal
The standard deliberately uses its own vocabulary rather than any statute’s, so it can be mapped onto whichever law applies. That makes it a translation layer, not a definition of scope in its own right.
ISO/IEC 27701 · as at 2026-08
How ISO 27701 is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by Your certification body, as an extension to an ISO 27001 certificate.
A voluntary standard. No regulator enforces it.
ISO 27701 extends an information security management system to cover privacy. It cannot be certified on its own, and no authority enforces it. Its value is evidentiary: it is a structured way of showing a supervisory authority or a customer what your privacy programme actually does.
A certificate is evidence of a management system, not evidence of compliance with any privacy law.
Uncapped exposure that sits outside this instrument
These come from company law rather than from ISO 27701, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for ISO 27701,
not configured for it afterwards
PIMS Access Control
Track all access to PII with purpose limitation verification
ISO 27701 Audit Evidence
Certification-ready documentation of privacy controls
PII Processing Patterns
Identify and categorize personal information processing
Purpose Limitation Violation
Alert when PII accessed outside identified purposes
Other Data Privacy frameworks
Walk into the ISO 27701 audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.