Data protection law tells you what must be true; it does not tell you how to prove it. ISO/IEC 27701 does. We build privacy information management systems that demonstrate GDPR accountability to regulators, enterprise customers and certification auditors alike, delivered by senior consultants who audit these systems for a living.
Whether you process personal data as a controller, a processor, or both, we shape the PIMS around your actual data flows and your obligations, not a generic template with your logo on the cover.
Design and build of a privacy information management system to ISO/IEC 27701, from data flow mapping and role determination through privacy risk assessment to embedded operational controls, aligned with the GDPR obligations you already carry.
An impartial audit of your PIMS by qualified Senior Lead Auditors who assess these systems on behalf of certification bodies. You get findings in plain language, a clear severity classification, and a remediation route your team can actually follow.
Privacy obligations do not stand still, and neither should the PIMS. We keep your records of processing current, close out findings, support surveillance audits, and translate regulatory change into concrete control updates.
Most organisations can describe their GDPR compliance; very few can evidence it. A certified PIMS closes that gap: it converts your privacy notices, DPIAs and processing records into a managed, audited system, and it gives procurement teams the certificate they increasingly ask for before a contract is signed. And we practise what we audit: Cybercontrols is itself certified to ISO/IEC 27001 and ISO/IEC 42001, holds Cyber Essentials, and is an approved Government Commercial Agency supplier.
ISO 27701 draws the controller/processor line precisely. We determine your roles per processing activity and apply the right control set to each.
Every PIMS control is traced to the GDPR obligation it evidences, so legal, security and audit finally share one picture.
Privacy sits naturally between ISO 27001 security and ISO 42001 AI governance: one management system, three certificates.
ISO 27001 and 42001 certified, Cyber Essentials, and a Government Commercial Agency supplier: we hold the certificates we help you earn.
The 2025 edition is the most significant change in the standard's short history: privacy management has grown up from an extension of information security into a management system standard in its own right.
We map what personal data you hold, where it flows, and under which lawful bases, then define the PIMS scope. The data flow map becomes the foundation the whole system, and your auditor's first question, rests on.
Controller, processor, or both, determined per processing activity, with the applicable ISO 27701 controls selected accordingly and documented in a form your assessor will recognise immediately.
Privacy policies, DPIA processes, data subject rights handling and supplier controls deployed inside your existing ways of working, with knowledge transfer throughout so the PIMS belongs to your team.
A full internal audit and management review, then a mock assessment conducted exactly as a certification body would conduct it. No surprises at stage 1 or stage 2.
Support through the certification audit, then ongoing surveillance and continual improvement, and, where it serves you, integration with ISO 27001 and ISO 42001 into a single management system.
Under the 2019 edition, yes, ISO 27701 was an extension to an ISO 27001 ISMS. The 2025 edition establishes it as a standalone standard, though in practice a PIMS is strongest, and cheapest to run, when built alongside or on top of an ISMS. We will advise on the right sequence for your situation at scoping.
No, and no certificate makes you GDPR-compliant by itself. What ISO 27701 provides is the management system that operates and evidences your obligations, which is precisely what regulators mean by accountability, and what enterprise customers accept as proof.
Built on an existing ISO 27001 ISMS, typically three to four months. As a standalone programme, closer to the timeline of a full management system build. Either way you will have a realistic plan, in weeks, from the scoping call.
Very much so: processors carry their own control set under ISO 27701, and processor certification is increasingly requested in B2B due diligence. If you host, process or enrich personal data on behalf of clients, this is the certificate that shortens those security questionnaires.
As the middle leg of what we call the triangle of control: information security, privacy and AI governance operated as one integrated management system with shared risk management, internal audit and management review. One system, three certificates, far less overhead.
A 30-minute scoping call with a senior lead auditor. We will tell you honestly what a PIMS would take for your organisation, and whether now is the right time.