Information Security Certification

ISO 27701 Certification

Privacy Information Management System

What is ISO 27701?

ISO/IEC 27701 extends ISO 27001 to establish a Privacy Information Management System (PIMS), helping organisations manage personal data and demonstrate compliance with privacy regulations such as GDPR.

Benefits of Certification

  • โœ”Demonstrate GDPR and privacy law compliance
  • โœ”Manage personal data as a controller or processor
  • โœ”Reduce privacy risk and breach exposure
  • โœ”Build trust with customers and regulators
  • โœ”Extend an existing ISO 27001 ISMS

Scope

For organisations acting as PII controllers or processors that need to manage privacy within an information security management system.

Who it applies to

  • โ—IT & software / SaaS
  • โ—BPO & shared services
  • โ—Financial & professional services
  • โ—Telecommunications
  • โ—Healthcare & data processors
  • โ—E-commerce & cloud providers
โœ“

What the scope covers

  • โ–ธInformation security risk assessment and treatment
  • โ–ธAccess control and cryptography
  • โ–ธAsset, supplier and cloud security
  • โ–ธIncident management and business continuity
  • โ–ธPhysical and operational security
  • โ–ธStatement of Applicability (Annex A controls)

Key Requirements

  • โ–ธISO 27001 ISMS as a foundation
  • โ–ธPrivacy-specific controls and mapping
  • โ–ธRoles of PII controllers and processors
  • โ–ธData subject rights processes
  • โ–ธPrivacy risk assessment
  • โ–ธRecords of processing activities

Certification Process

  1. 1

    Application & Quotation

    Submit your details and receive a tailored, fixed-price quotation based on scope, sites and headcount.

  2. 2

    Gap Analysis (Optional)

    An optional pre-audit review identifies gaps between your current practices and the standard.

  3. 3

    Stage 1 Audit

    Documentation review to confirm your management system is designed and ready for assessment.

  4. 4

    Stage 2 Audit

    On-site (or remote) assessment of the implementation and effectiveness of your system.

  5. 5

    Certification Decision

    An independent technical review leads to the certification decision and issue of your certificate.

  6. 6

    Surveillance & Renewal

    Annual surveillance audits maintain your certification over the three-year cycle before recertification.

Documents Required

  • ๐Ÿ“„Company registration / incorporation details
  • ๐Ÿ“„Organisation chart and list of sites
  • ๐Ÿ“„Scope statement of activities
  • ๐Ÿ“„Management system manual / documented information
  • ๐Ÿ“„Key policies and procedures relevant to the standard
  • ๐Ÿ“„Records demonstrating implementation (audits, reviews, training)

Frequently Asked Questions

How long does ISO 27701 certification take?

Typical timelines range from 4 to 12 weeks depending on the size of your organisation, the number of sites and how mature your existing management system is.

How long is a ISO 27701 certificate valid?

Certificates are issued for a three-year cycle, subject to successful annual surveillance audits, after which recertification renews the cycle.

Can the audit be conducted remotely?

Yes. Where appropriate, UKCTL can conduct Stage 1 and parts of Stage 2 remotely, combined with on-site verification as required.

Is ISO 27701 certification accredited?

UKCTL issues accredited certificates recognised internationally, giving your customers and stakeholders confidence in the assessment.

Get ISO 27701 certified with UKCTL

Apply Now