ISO/IEC 27701 · Privacy Information Management

Turn GDPR accountability into something you can certify.

Data protection law tells you what must be true; it does not tell you how to prove it. ISO/IEC 27701 does. We build privacy information management systems that demonstrate GDPR accountability to regulators, enterprise customers and certification auditors alike, delivered by senior consultants who audit these systems for a living.

We hold ourselves to the standards we audit: Cybercontrols is certified to
ISO/IEC 27001:2022Certified · SANCERT ISO/IEC 42001:2023Certified · SANCERT Cyber EssentialsCertified Government Commercial AgencyApproved Supplier · G-Cloud 15
What we deliver

Privacy management, from data map to certificate.

Whether you process personal data as a controller, a processor, or both, we shape the PIMS around your actual data flows and your obligations, not a generic template with your logo on the cover.

01

PIMS Implementation

Design and build of a privacy information management system to ISO/IEC 27701, from data flow mapping and role determination through privacy risk assessment to embedded operational controls, aligned with the GDPR obligations you already carry.

02

Internal Audit

An impartial audit of your PIMS by qualified Senior Lead Auditors who assess these systems on behalf of certification bodies. You get findings in plain language, a clear severity classification, and a remediation route your team can actually follow.

03

Maintenance & Assurance

Privacy obligations do not stand still, and neither should the PIMS. We keep your records of processing current, close out findings, support surveillance audits, and translate regulatory change into concrete control updates.

Why Cybercontrols

Privacy proven, not merely promised.

Most organisations can describe their GDPR compliance; very few can evidence it. A certified PIMS closes that gap: it converts your privacy notices, DPIAs and processing records into a managed, audited system, and it gives procurement teams the certificate they increasingly ask for before a contract is signed. And we practise what we audit: Cybercontrols is itself certified to ISO/IEC 27001 and ISO/IEC 42001, holds Cyber Essentials, and is an approved Government Commercial Agency supplier.

Controllers and processors

ISO 27701 draws the controller/processor line precisely. We determine your roles per processing activity and apply the right control set to each.

GDPR-mapped by design

Every PIMS control is traced to the GDPR obligation it evidences, so legal, security and audit finally share one picture.

The triangle of control

Privacy sits naturally between ISO 27001 security and ISO 42001 AI governance: one management system, three certificates.

Certified ourselves

ISO 27001 and 42001 certified, Cyber Essentials, and a Government Commercial Agency supplier: we hold the certificates we help you earn.

The new edition

ISO 27701:2019 and 27701:2025, what actually changed.

The 2025 edition is the most significant change in the standard's short history: privacy management has grown up from an extension of information security into a management system standard in its own right.

ISO/IEC 27701:2019

The extension

  • Built on ISO 27001. Written as an extension to ISO 27001 and 27002; it could not stand alone.
  • Certification required an ISMS. You could only certify a PIMS alongside, or on top of, an ISO 27001 certificate.
  • Security-first framing. Privacy requirements were expressed as additions to security clauses, which suited security teams but often left privacy and legal functions at arm's length.
  • Referenced the older control set. Written against the pre-2022 ISO 27002 structure, and straddled the 2022 reorganisation awkwardly.
ISO/IEC 27701:2025

The standalone standard

  • A full management system standard. Restructured around the harmonised structure common to ISO 27001, 9001 and 42001, with its own complete requirements.
  • Certifiable in its own right. A PIMS can now be certified without an ISO 27001 certificate, although the two remain strongest, and cheapest to run, together.
  • Privacy-led framing. Requirements are expressed from the privacy perspective, giving DPOs and legal teams a standard that speaks their language while still integrating cleanly with security.
  • Aligned with the current control landscape. Updated controller and processor control sets, aligned with ISO 27001:2022 and today's regulatory expectations.
Already certified under 2019, or partway there? Existing certificates transition to the 2025 edition on your certification body's timetable, and we manage that as a focused delta exercise rather than a rebuild. Starting fresh? We implement directly against the 2025 edition, so nothing you build is out of date on day one.
How it works

From data map to certificate, without surprises.

Step 1

Data mapping & scoping

We map what personal data you hold, where it flows, and under which lawful bases, then define the PIMS scope. The data flow map becomes the foundation the whole system, and your auditor's first question, rests on.

Step 2

Roles & applicability

Controller, processor, or both, determined per processing activity, with the applicable ISO 27701 controls selected accordingly and documented in a form your assessor will recognise immediately.

Step 3

Build & embed

Privacy policies, DPIA processes, data subject rights handling and supplier controls deployed inside your existing ways of working, with knowledge transfer throughout so the PIMS belongs to your team.

Step 4

Internal audit & readiness

A full internal audit and management review, then a mock assessment conducted exactly as a certification body would conduct it. No surprises at stage 1 or stage 2.

Step 5

Certification & beyond

Support through the certification audit, then ongoing surveillance and continual improvement, and, where it serves you, integration with ISO 27001 and ISO 42001 into a single management system.

Questions we hear most

ISO 27701, answered plainly.

Do we need ISO 27001 before ISO 27701?

Under the 2019 edition, yes, ISO 27701 was an extension to an ISO 27001 ISMS. The 2025 edition establishes it as a standalone standard, though in practice a PIMS is strongest, and cheapest to run, when built alongside or on top of an ISMS. We will advise on the right sequence for your situation at scoping.

Is ISO 27701 the same as GDPR compliance?

No, and no certificate makes you GDPR-compliant by itself. What ISO 27701 provides is the management system that operates and evidences your obligations, which is precisely what regulators mean by accountability, and what enterprise customers accept as proof.

How long does certification take?

Built on an existing ISO 27001 ISMS, typically three to four months. As a standalone programme, closer to the timeline of a full management system build. Either way you will have a realistic plan, in weeks, from the scoping call.

We are a processor, not a controller. Does it still apply?

Very much so: processors carry their own control set under ISO 27701, and processor certification is increasingly requested in B2B due diligence. If you host, process or enrich personal data on behalf of clients, this is the certificate that shortens those security questionnaires.

How does this fit with ISO 27001 and ISO 42001?

As the middle leg of what we call the triangle of control: information security, privacy and AI governance operated as one integrated management system with shared risk management, internal audit and management review. One system, three certificates, far less overhead.

Ready to make privacy provable?

A 30-minute scoping call with a senior lead auditor. We will tell you honestly what a PIMS would take for your organisation, and whether now is the right time.