What is ISO 27701?
ISO/IEC 27701 extends ISO 27001 to establish a Privacy Information Management System (PIMS), helping organisations manage personal data and demonstrate compliance with privacy regulations such as GDPR.
Benefits of Certification
- โDemonstrate GDPR and privacy law compliance
- โManage personal data as a controller or processor
- โReduce privacy risk and breach exposure
- โBuild trust with customers and regulators
- โExtend an existing ISO 27001 ISMS
Scope
For organisations acting as PII controllers or processors that need to manage privacy within an information security management system.
Who it applies to
- โIT & software / SaaS
- โBPO & shared services
- โFinancial & professional services
- โTelecommunications
- โHealthcare & data processors
- โE-commerce & cloud providers
What the scope covers
- โธInformation security risk assessment and treatment
- โธAccess control and cryptography
- โธAsset, supplier and cloud security
- โธIncident management and business continuity
- โธPhysical and operational security
- โธStatement of Applicability (Annex A controls)
Key Requirements
- โธISO 27001 ISMS as a foundation
- โธPrivacy-specific controls and mapping
- โธRoles of PII controllers and processors
- โธData subject rights processes
- โธPrivacy risk assessment
- โธRecords of processing activities
Certification Process
- 1
Application & Quotation
Submit your details and receive a tailored, fixed-price quotation based on scope, sites and headcount.
- 2
Gap Analysis (Optional)
An optional pre-audit review identifies gaps between your current practices and the standard.
- 3
Stage 1 Audit
Documentation review to confirm your management system is designed and ready for assessment.
- 4
Stage 2 Audit
On-site (or remote) assessment of the implementation and effectiveness of your system.
- 5
Certification Decision
An independent technical review leads to the certification decision and issue of your certificate.
- 6
Surveillance & Renewal
Annual surveillance audits maintain your certification over the three-year cycle before recertification.
Documents Required
- ๐Company registration / incorporation details
- ๐Organisation chart and list of sites
- ๐Scope statement of activities
- ๐Management system manual / documented information
- ๐Key policies and procedures relevant to the standard
- ๐Records demonstrating implementation (audits, reviews, training)
Frequently Asked Questions
How long does ISO 27701 certification take?
Typical timelines range from 4 to 12 weeks depending on the size of your organisation, the number of sites and how mature your existing management system is.
How long is a ISO 27701 certificate valid?
Certificates are issued for a three-year cycle, subject to successful annual surveillance audits, after which recertification renews the cycle.
Can the audit be conducted remotely?
Yes. Where appropriate, UKCTL can conduct Stage 1 and parts of Stage 2 remotely, combined with on-site verification as required.
Is ISO 27701 certification accredited?
UKCTL issues accredited certificates recognised internationally, giving your customers and stakeholders confidence in the assessment.
Get ISO 27701 certified with UKCTL
Apply Now