ISO 27701 Certification

ISO/IEC 27701 is an international standard that provides a framework for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS). A PIMS helps organizations protect and control its PII (Personally Identifiable Information). ISO/IEC27701 extends ISO/IEC 27001 (Information Security Management) and ISO/IEC 27002 (Security Controls) to include requirements and guidelines specifically focused on managing privacy-related risks and ensuring compliance with privacy regulations.

Contains two key appendices:
Appendix A: Provides PIMS-specific controls for organizations acting as PII controllers.
Appendix B: Provides PIMS-specific controls for organizations acting as PII processors.

ISO/IEC 27701 is increasingly recognized as a key tool for organizations aiming to ensure robust privacy practices and regulatory compliance in today’s data-driven environment.

Why is Privacy needed ?

Privacy refers to the right of individuals to control their personal information and to decide how it is collected, used, shared, and stored. It encompasses the protection of personal data and the assurance that an individual’s activities, communications, and preferences are not exposed or misused without their consent.

Protects Individual Freedom: Ensures freedom of expression, thought, and action without fear of surveillance or judgment.

Prevents Abuse of Power: Protects individuals from misuse of their data by governments, organizations, or other entities.

Facilitates Trust: Builds confidence in relationships, whether personal or professional, by safeguarding sensitive information.

Enables Compliance: Ensures adherence to privacy laws and regulations like GDPR, CCPA, or HIPAA, which promote the ethical handling of personal data.

Being audited to ISO27701

ISO/IEC27701 extends ISO/IEC 27001 (Information Security Management) and ISO/IEC 27002 (Security Controls). To obtain an accredited certificate you must implement Information Security Management System (ISMS) along side Privacy Management Information System (PIMS).

Once implemented, you can apply for an external audit.  This should be carried out by a third party, certification body, such as Approachable Certification.

Approachable Certification will firstly review relevant documentation.  This should include the declared policy, scope of the PIMS, documents covering the risk assessment, risk treatment plan, and documented privacy procedures.  The auditor(s) will also be checking that you’ve identified and implemented the controls that are appropriate to your size and type of business as a PII Processor, PII Controller or both.  This process is normally carried out at your premises, being more beneficial to both parties.

This is followed at a later date by a full on-site audit to ensure that working practices observe these procedures and stated objectives, and that appropriate records are kept.

After a successful audit, a certificate of registration to ISO/IEC 27701 will be issued.  There’ll then be surveillance visits (usually once or twice a year) to ensure that the system continues to work.

Benefits of Certification to ISO27701

ISO/IEC 27701 Enhances trust with customers and stakeholders by demonstrating commitment to privacy and compliance.

Certification demonstrates a systematic approach to identifying and mitigating privacy risks.

Cost

Approachable Certification is committed to transparent pricing with fees based on a fixed daily rate.  Criteria for the number of days required for a particular audit is specified by the accreditation body, UKAS, and depends on such factors as the size of your company and what it does.

Consequently, a few specific details are required to provide you with a competitive quotation.  Please call us on 0161 667 6610, email us or tell us a bit more about what your organisation does on this quotation request form.

Why Approachable Certification

Why choose Approachable Certification for your ISO 27001 Certification Audit?  Simple.  We’re competitive, friendly and offer excellent customer service.  Read more here.

Approachable Certification
0161 667 6610