# ISO 27701:2019 Privacy Information Management System (PIMS) Standard

## Executive Summary

ISO/IEC 27701:2019 is an international standard that extends ISO/IEC 27001 and ISO/IEC 27002 for privacy information management. It provides a framework for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS), enabling organizations to demonstrate compliance with privacy regulations including GDPR, CCPA, and other global privacy laws.

**Current Version:** ISO/IEC 27701:2019 (published August 2019)  
**Extension to:** ISO/IEC 27001:2022 and ISO/IEC 27002:2022  
**Certification Body:** International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)  
**Certification Name:** ISO/IEC 27001 + ISO/IEC 27701 (requires ISO 27001 as foundation)

---

## 1. Standard Overview

### 1.1 Purpose and Scope

ISO 27701 provides guidance and requirements for:

- Establishing a Privacy Information Management System (PIMS)
- Managing Personally Identifiable Information (PII) processing
- Demonstrating compliance with privacy regulations globally
- Implementing privacy controls for PII Controllers and PII Processors
- Extending existing ISMS (ISO 27001) with privacy-specific requirements
- Meeting obligations under GDPR, CCPA, LGPD, PIPEDA, and other privacy laws

### 1.2 Key Definitions

**Personally Identifiable Information (PII):** Any information that can be used to identify a natural person (data subject), either directly or indirectly.

**PII Controller:** Organization that determines the purposes and means of processing PII (equivalent to "Data Controller" in GDPR).

**PII Processor:** Organization that processes PII on behalf of and according to instructions from a PII Controller (equivalent to "Data Processor" in GDPR).

**PII Principal:** Natural person to whom the PII relates (equivalent to "Data Subject" in GDPR).

**Consent:** Freely given, specific, informed, and unambiguous indication of wishes by statement or clear affirmative action.

**Data Protection Impact Assessment (DPIA):** Process to identify, assess, and mitigate privacy risks in processing operations.

### 1.3 Relationship to ISO 27001

ISO 27701 is structured as an **extension** to ISO 27001:

- Requires existing ISO 27001 ISMS as foundation
- Adds privacy-specific clauses to existing ISMS clauses
- Introduces additional privacy controls in two new annexes
- Can be implemented simultaneously with ISO 27001 or as enhancement
- Certification requires both ISO 27001 and ISO 27701 compliance

**Integration Model:**
```
ISO 27001 (Information Security) 
    ↓
+ ISO 27701 (Privacy Extension)
    ↓
= PIMS (Privacy Information Management System)
```

---

## 2. Standard Structure

### 2.1 Normative Clauses (Requirements)

ISO 27701 adds privacy-specific requirements to ISO 27001 clauses:

**Clause 4: Context of the Organization (Privacy Extensions)**
- Understanding PII processing context
- Identifying PII stakeholders and their privacy requirements
- Determining PIMS scope including PII types and processing activities
- Establishing PIMS within ISMS framework

**Clause 5: Leadership (Privacy Extensions)**
- Top management commitment to privacy
- Privacy policy establishment and communication
- Assignment of privacy roles (DPO, Privacy Officer)
- Integration of privacy into organizational culture

**Clause 6: Planning (Privacy Extensions)**
- Privacy risk assessment methodology
- Privacy objectives aligned with business goals
- Planning for privacy requirement changes
- Identifying legal and regulatory privacy obligations

**Clause 7: Support (Privacy Extensions)**
- Privacy awareness and training programs
- Communication with PII principals
- Privacy-related documented information
- Resources for privacy program

**Clause 8: Operation (Privacy Extensions)**
- PII processing operations management
- Privacy impact assessments
- Procedures for PII principal requests
- PII breach notification procedures
- Third-party PII processor management

**Clause 9: Performance Evaluation (Privacy Extensions)**
- Privacy metrics and monitoring
- Privacy audit programs
- Management review of PIMS effectiveness
- Privacy incident tracking and analysis

**Clause 10: Improvement (Privacy Extensions)**
- Privacy non-conformity management
- Continual improvement of privacy controls
- Updates based on privacy incidents and audits
- Integration of lessons learned

### 2.2 Control Annexes

**Annex A: ISO 27002 Controls Guidance for PII Controllers and Processors**
- Provides privacy-specific guidance for all 93 ISO 27002 controls
- Explains how each security control applies to PII protection
- Maps security controls to privacy requirements

**Annex B: Additional PII Controller Controls (24 controls)**
- Specific controls for organizations determining processing purposes
- Focuses on PII principal rights, consent, transparency
- Addresses legal basis, purpose limitation, data minimization

**Annex C: Additional PII Processor Controls (12 controls)**
- Specific controls for organizations processing PII on behalf of controllers
- Focuses on processing instructions, sub-processor management
- Addresses return/deletion of PII, processor audits

---

## 3. Annex B: PII Controller Controls (24 Controls)

### 3.1 Conditions for Collection and Processing

**B.6.1 Identify and Document Purpose**
- **Requirement:** Identify, document, and maintain specific purposes for PII processing
- **Attributes:** Legitimate, explicit, clearly communicated to PII principals
- **GDPR Alignment:** Article 5(1)(b) - Purpose limitation
- **Implementation:** 
  - Purpose documentation in processing records
  - Purpose statements in privacy notices
  - Regular review and update of purposes
  - Purpose limitation assessments
- **Evidence:** Purpose documentation, privacy notices, processing records

**B.6.2 Identify Legal Basis**
- **Requirement:** Identify and document lawful basis for PII processing
- **Attributes:** Must meet regulatory requirements, documented before processing begins
- **GDPR Alignment:** Article 6 - Lawfulness of processing
- **Legal Bases (GDPR):**
  - Consent of the data subject
  - Contractual necessity
  - Legal obligation
  - Vital interests protection
  - Public interest or official authority
  - Legitimate interests (with balancing test)
- **Implementation:**
  - Legal basis assessment for each processing activity
  - Documentation in Records of Processing Activities (RoPA)
  - Consent management systems where applicable
  - Regular review of legal basis validity
- **Evidence:** Legal basis documentation, consent records, legitimate interest assessments (LIA)

**B.6.3 Determining Information to Collect**
- **Requirement:** Limit PII collection to what is adequate, relevant, and necessary
- **Attributes:** Data minimization, purpose-specific collection
- **GDPR Alignment:** Article 5(1)(c) - Data minimization
- **Implementation:**
  - Data mapping exercises
  - Collection necessity assessments
  - Form field reviews (remove unnecessary fields)
  - Regular audits of collected data elements
- **Evidence:** Data inventory, collection assessments, privacy impact assessments

**B.6.4 Privacy Impact Assessment**
- **Requirement:** Conduct privacy impact assessments for new/changed processing
- **Attributes:** Risk-based, documented, reviewed regularly
- **GDPR Alignment:** Article 35 - Data Protection Impact Assessment (DPIA)
- **Mandatory When:**
  - Systematic monitoring on large scale
  - Large-scale processing of sensitive data
  - Automated decision-making with legal effects
  - New technologies with privacy risks
- **Implementation:**
  - DPIA templates and methodology
  - Risk assessment criteria
  - Stakeholder consultation
  - DPO involvement
  - Supervisory authority consultation (if high risk)
- **Evidence:** Completed DPIAs, risk registers, consultation records

**B.6.5 Limiting Processing**
- **Requirement:** Ensure PII processed only for identified, documented purposes
- **Attributes:** Technical and organizational measures, access controls
- **GDPR Alignment:** Article 5(1)(b) - Purpose limitation
- **Implementation:**
  - Access control based on need-to-know
  - Purpose-specific data segregation
  - Processing logs and monitoring
  - Data usage policies and training
- **Evidence:** Access control matrices, processing logs, policy documentation

### 3.2 Obligations to PII Principals

**B.7.1 Additional Information for PII Principals**
- **Requirement:** Provide comprehensive privacy information to PII principals
- **Attributes:** Clear, transparent, easily accessible, in plain language
- **GDPR Alignment:** Articles 13 & 14 - Information to be provided
- **Information Elements:**
  - Identity and contact details of controller
  - Contact details of Data Protection Officer (if applicable)
  - Purposes of processing and legal basis
  - Categories of PII concerned
  - Recipients or categories of recipients
  - International transfers and safeguards
  - Retention periods or criteria
  - Rights of PII principals
  - Right to withdraw consent
  - Right to lodge complaint with supervisory authority
  - Whether providing PII is contractual/statutory requirement
  - Automated decision-making and profiling information
- **Implementation:**
  - Multi-layered privacy notices
  - Just-in-time notices
  - Icons and visual indicators
  - Language and accessibility compliance
  - Regular notice updates
- **Evidence:** Privacy notices, consent forms, communication records

**B.7.2 Privacy Notice for Third-Party Collection**
- **Requirement:** Provide notice when PII obtained from sources other than PII principal
- **Attributes:** Timely notification, source disclosure
- **GDPR Alignment:** Article 14 - Information where not obtained from data subject
- **Timing:** Within reasonable period, within one month maximum
- **Additional Information Required:**
  - Categories of PII
  - Source of PII (specific or general categories)
- **Exceptions:** When notification impossible, disproportionate effort, or legally prohibited
- **Implementation:**
  - Third-party data source tracking
  - Notification workflows
  - Exception documentation
- **Evidence:** Notification records, source documentation, exception logs

**B.7.3 Provide Mechanism for Consent**
- **Requirement:** Implement mechanisms for obtaining, recording, and managing consent
- **Attributes:** Freely given, specific, informed, unambiguous, verifiable
- **GDPR Alignment:** Article 7 - Conditions for consent
- **Consent Requirements:**
  - Clear affirmative action (no pre-ticked boxes)
  - Separate from other terms and conditions
  - Easy to withdraw as to give
  - Specific and granular (per purpose)
  - Verifiable audit trail
- **Special Category Data:** Explicit consent required
- **Children's Data:** Parental consent required (age varies by jurisdiction)
- **Implementation:**
  - Consent management platform (CMP)
  - Consent capture mechanisms
  - Consent withdrawal functionality
  - Consent refresh for expired consents
  - Age verification systems
- **Evidence:** Consent records, consent management logs, withdrawal records

**B.7.4 Obtain and Record Consent**
- **Requirement:** Obtain valid consent before processing and maintain records
- **Attributes:** Documented, timestamped, version-controlled
- **GDPR Alignment:** Article 7(1) - Burden of proof
- **Record Elements:**
  - Who consented (PII principal identification)
  - When consent given (timestamp)
  - What they were told (privacy notice version)
  - What they consented to (specific purposes)
  - How they consented (mechanism used)
  - Whether consent withdrawn (and when)
- **Implementation:**
  - Consent database
  - Audit trails
  - Consent lifecycle management
  - Integration with CRM/marketing systems
- **Evidence:** Consent records, audit logs, system documentation

**B.7.5 Respond to PII Principal Requests**
- **Requirement:** Provide mechanisms for PII principals to exercise their rights
- **Attributes:** Free of charge (generally), timely response (within one month)
- **GDPR Alignment:** Articles 12-22 - Rights of data subjects
- **PII Principal Rights:**
  - Right of access (copy of PII)
  - Right to rectification (correction)
  - Right to erasure ("right to be forgotten")
  - Right to restriction of processing
  - Right to data portability
  - Right to object to processing
  - Rights related to automated decision-making
- **Implementation:**
  - Data Subject Request (DSR) portal
  - Identity verification procedures
  - Request tracking system
  - Automated data extraction tools
  - Cross-system search capabilities
  - Workflow for request fulfillment
  - Extension documentation (complex requests)
- **Response Timeframe:** One month (extendable to three months for complex requests)
- **Evidence:** DSR logs, response records, identity verification records

### 3.3 Privacy by Design and by Default

**B.8.1 Data Minimization**
- **Requirement:** Process only PII necessary for specified purposes
- **Attributes:** Default configurations minimize PII processing
- **GDPR Alignment:** Article 5(1)(c) & Article 25(2) - Data minimization, Privacy by default
- **Implementation:**
  - Privacy by default settings
  - Optional vs. mandatory field identification
  - Data collection reviews
  - Progressive profiling strategies
  - Default privacy-friendly options
- **Evidence:** Privacy by design documentation, default configuration records

**B.8.2 PII De-identification and Deletion**
- **Requirement:** De-identify or delete PII when no longer necessary
- **Attributes:** Automated where possible, secure deletion methods
- **GDPR Alignment:** Article 5(1)(e) - Storage limitation
- **Techniques:**
  - Anonymization (irreversible)
  - Pseudonymization (reversible with additional information)
  - Data masking
  - Aggregation
  - Secure deletion/destruction
- **Implementation:**
  - Automated retention and deletion policies
  - Data lifecycle management
  - Anonymization workflows
  - Deletion verification procedures
- **Evidence:** Retention schedules, deletion logs, anonymization records

**B.8.3 Temporary Files and Logs**
- **Requirement:** Manage temporary PII files and logs containing PII
- **Attributes:** Limited retention, secure storage, regular purging
- **GDPR Alignment:** Article 5(1)(c) & (e) - Data minimization, Storage limitation
- **Implementation:**
  - Log retention policies
  - PII redaction in logs
  - Temporary file cleanup procedures
  - Cache management
  - Backup management
- **Evidence:** Log management policies, cleanup schedules, backup retention records

**B.8.4 Disposal of Media**
- **Requirement:** Securely dispose of media containing PII
- **Attributes:** Certified destruction, chain of custody
- **GDPR Alignment:** Article 32 - Security of processing
- **Implementation:**
  - Secure erasure standards (NIST 800-88)
  - Physical destruction for irretrievable media
  - Certificates of destruction
  - Asset tracking
- **Evidence:** Destruction certificates, disposal logs, vendor contracts

**B.8.5 Privacy Enhancing Technologies**
- **Requirement:** Evaluate and implement privacy-enhancing technologies
- **Attributes:** State-of-the-art consideration, risk-appropriate
- **GDPR Alignment:** Article 25 - Data protection by design and by default
- **Technologies:**
  - Encryption (data at rest, in transit, in use)
  - Tokenization
  - Differential privacy
  - Homomorphic encryption
  - Secure multi-party computation
  - Zero-knowledge proofs
  - Federated learning
- **Implementation:**
  - PET assessment process
  - Technology evaluation criteria
  - Proof of concept testing
  - Implementation roadmap
- **Evidence:** Technology assessments, implementation records

### 3.4 PII Sharing, Transfer and Disclosure

**B.9.1 Legal Basis for Transfer**
- **Requirement:** Identify and document legal basis for PII transfers
- **Attributes:** Transfer-specific legal basis, documented assessment
- **GDPR Alignment:** Chapter V (Articles 44-50) - Transfers of personal data
- **Transfer Mechanisms:**
  - Adequacy decision (EU Commission approved countries)
  - Standard Contractual Clauses (SCCs)
  - Binding Corporate Rules (BCRs)
  - Certification mechanisms
  - Codes of conduct
  - Explicit consent
  - Contract performance necessity
  - Derogations for specific situations
- **Implementation:**
  - Transfer impact assessment (TIA)
  - Supplementary measures assessment
  - Documentation of transfer mechanisms
  - Regular review of adequacy status
- **Evidence:** Transfer agreements, adequacy assessments, SCCs, BCRs

**B.9.2 Countries and International Organizations**
- **Requirement:** Document countries/organizations receiving PII transfers
- **Attributes:** Maintained inventory, risk assessment
- **GDPR Alignment:** Article 44 - General principle for transfers
- **Implementation:**
  - Transfer mapping
  - Country risk assessments
  - Vendor location tracking
  - Data flow diagrams
- **Evidence:** Transfer inventory, data flow diagrams, vendor lists

**B.9.3 Records of Disclosure to Third Parties**
- **Requirement:** Maintain records of PII disclosures to third parties
- **Attributes:** Timestamped, purpose-documented, recipient-identified
- **GDPR Alignment:** Article 30 - Records of processing activities
- **Record Elements:**
  - Date and time of disclosure
  - Recipient identity and contact
  - Categories of PII disclosed
  - Purpose of disclosure
  - Legal basis for disclosure
  - Safeguards applied
- **Implementation:**
  - Disclosure logging system
  - Integration with data access systems
  - Audit trail maintenance
- **Evidence:** Disclosure logs, audit trails

**B.9.4 Records of PII Disclosures**
- **Requirement:** Enable PII principals to request disclosure records
- **Attributes:** Accessible, comprehensive, timely provision
- **GDPR Alignment:** Article 15(1)(c) - Right of access to recipients
- **Implementation:**
  - Disclosure tracking system
  - Request fulfillment processes
  - Automated reporting capabilities
- **Evidence:** Disclosure reports, request fulfillment records

**B.9.5 Contracts with Other PII Controllers**
- **Requirement:** Establish contracts when sharing PII with joint/independent controllers
- **Attributes:** Clearly defined responsibilities, legally binding
- **GDPR Alignment:** Article 26 - Joint controllers
- **Contract Elements:**
  - Purpose and legal basis
  - Respective responsibilities
  - Communication with PII principals
  - Exercise of PII principal rights
  - Security measures
  - Breach notification procedures
- **Implementation:**
  - Controller agreement templates
  - Responsibility matrices
  - Joint controller arrangements
- **Evidence:** Controller agreements, responsibility documentation

**B.9.6 Contracts with PII Processors**
- **Requirement:** Establish processor agreements with documented obligations
- **Attributes:** Compliant with regulatory requirements, enforceable
- **GDPR Alignment:** Article 28 - Processor obligations
- **Mandatory Contract Terms (GDPR Article 28(3)):**
  - Process only on documented instructions
  - Confidentiality obligations for personnel
  - Security measures (Article 32)
  - Sub-processor requirements and authorization
  - Assistance with PII principal rights
  - Assistance with security and breach obligations
  - Deletion or return of PII after service
  - Audit and inspection rights
  - International transfer provisions
- **Implementation:**
  - Data Processing Agreement (DPA) templates
  - Vendor management processes
  - Contract review and approval workflows
  - Vendor risk assessments
- **Evidence:** Signed DPAs, vendor assessments, contract repositories

**B.9.7 Addressing Privacy in Supplier Agreements**
- **Requirement:** Include privacy requirements in procurement and supplier contracts
- **Attributes:** Standard clauses, pre-contract assessment
- **GDPR Alignment:** Article 28 - Processor selection
- **Implementation:**
  - Supplier privacy questionnaires
  - Privacy requirements in RFPs
  - Supplier privacy assessments
  - Standard contractual privacy clauses
  - Due diligence processes
- **Evidence:** Supplier assessments, contract clauses, due diligence records

### 3.5 Privacy Compliance

**B.10.1 Obligations Arising from Contracts**
- **Requirement:** Identify and comply with contractual privacy obligations
- **Attributes:** Tracked, monitored, regularly reviewed
- **Implementation:**
  - Contract obligation register
  - Compliance monitoring
  - Obligation fulfillment tracking
- **Evidence:** Obligation registers, compliance reports

**B.10.2 PII Breach Obligations**
- **Requirement:** Establish procedures for PII breach notification
- **Attributes:** Timely notification (72 hours for GDPR), documented process
- **GDPR Alignment:** Articles 33 & 34 - Breach notification
- **Notification Requirements:**
  - To supervisory authority (within 72 hours if high risk)
  - To PII principals (without undue delay if high risk to rights)
  - Content requirements: nature of breach, categories and approximate numbers, consequences, measures taken
- **Implementation:**
  - Breach response plan
  - Breach assessment criteria
  - Notification templates
  - Communication workflows
  - Breach register
- **Evidence:** Breach notification records, assessment documentation, communication logs

**B.10.3 Automated Decision Making**
- **Requirement:** Implement safeguards for automated decision-making
- **Attributes:** Transparency, human review option, explainability
- **GDPR Alignment:** Article 22 - Automated decision-making and profiling
- **Requirements:**
  - Not solely based on automated processing (for legal/significant effects)
  - Human intervention option
  - Right to explanation
  - Regular accuracy checks
  - Bias monitoring and mitigation
- **Implementation:**
  - Algorithm impact assessments
  - Explainable AI (XAI) techniques
  - Human review processes
  - Bias testing and monitoring
  - Transparency documentation
- **Evidence:** Algorithm documentation, review records, accuracy reports

---

## 4. Annex C: PII Processor Controls (12 Controls)

### 4.1 Conditions for Collection and Processing

**C.6.1 Processing Based on Instructions**
- **Requirement:** Process PII only according to controller's documented instructions
- **Attributes:** Written instructions, instruction register, deviation procedures
- **GDPR Alignment:** Article 28(3)(a) - Processing on instructions
- **Implementation:**
  - Processing instruction documentation
  - Instruction change management
  - Deviation escalation procedures
  - Instruction compliance monitoring
- **Evidence:** Processing instructions, deviation logs, compliance records

**C.6.2 Limitations on Processing**
- **Requirement:** Do not process PII beyond controller instructions
- **Attributes:** Technical controls, access restrictions, monitoring
- **GDPR Alignment:** Article 28(3)(a) - Processing limitations
- **Implementation:**
  - Purpose-based access controls
  - Processing boundary definitions
  - Technical controls to prevent unauthorized processing
  - Regular compliance audits
- **Evidence:** Access control configurations, audit logs, compliance reports

**C.6.3 Privacy Impact Assessment Support**
- **Requirement:** Assist controller with privacy impact assessments
- **Attributes:** Timely response, relevant information provision
- **GDPR Alignment:** Article 28(3)(f) - Assistance with DPIA
- **Implementation:**
  - DPIA support procedures
  - Information provision protocols
  - Technical documentation maintenance
  - Risk information sharing
- **Evidence:** DPIA assistance records, information provided to controllers

**C.6.4 Return or Deletion of PII**
- **Requirement:** Return or delete PII at end of processing contract
- **Attributes:** Secure deletion, verification, certificate of destruction
- **GDPR Alignment:** Article 28(3)(g) - Deletion or return
- **Implementation:**
  - End-of-contract procedures
  - Data return mechanisms
  - Secure deletion processes
  - Deletion verification
  - Certificate issuance
- **Evidence:** Deletion certificates, return confirmations, destruction records

**C.6.5 Documentation and Records**
- **Requirement:** Maintain documentation demonstrating compliance
- **Attributes:** Comprehensive, accessible to controller, regularly updated
- **GDPR Alignment:** Article 28(3)(h) - Making information available
- **Implementation:**
  - Processing activity records
  - Compliance documentation repository
  - Regular reporting to controllers
  - Audit trail maintenance
- **Evidence:** Processing records, compliance reports, audit documentation

### 4.2 Obligations to PII Controllers and Principals

**C.7.1 PII Principal Requests**
- **Requirement:** Assist controller in responding to PII principal rights requests
- **Attributes:** Prompt assistance, appropriate technical/organizational measures
- **GDPR Alignment:** Article 28(3)(e) - Assistance with rights
- **Implementation:**
  - Request handling procedures
  - Data extraction capabilities
  - Response timeframe commitments
  - Coordination protocols with controllers
- **Evidence:** Request assistance records, response documentation

**C.7.2 Notification to Controller of PII Breach**
- **Requirement:** Notify controller of PII breaches without undue delay
- **Attributes:** Immediate notification, comprehensive information
- **GDPR Alignment:** Implicit in Article 28(3) - Processor security obligations
- **Implementation:**
  - Breach detection mechanisms
  - Immediate notification procedures
  - Breach information compilation
  - Communication protocols
- **Evidence:** Breach notification records, incident reports

**C.7.3 Provide Information on Compliance**
- **Requirement:** Demonstrate compliance with processor obligations
- **Attributes:** Audits, certifications, documentation
- **GDPR Alignment:** Article 28(3)(h) - Making information available
- **Implementation:**
  - Compliance reporting
  - Audit facilitation
  - Certification maintenance
  - Documentation provision
- **Evidence:** Audit reports, certifications, compliance documentation

### 4.3 Sub-contractors and Other Recipients

**C.8.1 Sub-contractor Engagement**
- **Requirement:** Obtain controller authorization before engaging sub-processors
- **Attributes:** Prior written authorization, notification mechanism
- **GDPR Alignment:** Article 28(2) & 28(4) - Sub-processor requirements
- **Implementation:**
  - Sub-processor approval process
  - Controller notification procedures
  - Objection handling mechanisms
  - Sub-processor register maintenance
- **Evidence:** Approval records, notification logs, sub-processor registers

**C.8.2 Sub-contractor Contracts**
- **Requirement:** Impose same data protection obligations on sub-processors
- **Attributes:** Back-to-back obligations, controller protection
- **GDPR Alignment:** Article 28(4) - Sub-processor obligations
- **Contract Requirements:**
  - Same obligations as main processor contract
  - Data protection obligations equivalent to controller-processor agreement
  - Liability provisions
- **Implementation:**
  - Sub-processor agreement templates
  - Contractual flow-down mechanisms
  - Contract review processes
- **Evidence:** Sub-processor agreements, contract reviews

**C.8.3 Change of Sub-contractors**
- **Requirement:** Notify controller of sub-processor changes and provide objection option
- **Attributes:** Advance notice (reasonable period), objection mechanism
- **GDPR Alignment:** Article 28(2) - Advance notification
- **Implementation:**
  - Change notification process
  - Objection handling procedures
  - Alternative arrangements for objections
  - Change management procedures
- **Evidence:** Change notifications, objection records, alternative arrangement documentation

**C.8.4 Records of Disclosures**
- **Requirement:** Maintain records of PII disclosures to sub-processors
- **Attributes:** Comprehensive logging, accessible to controller
- **GDPR Alignment:** Article 30 - Records of processing
- **Implementation:**
  - Disclosure logging systems
  - Sub-processor tracking
  - Access to records for controllers
- **Evidence:** Disclosure logs, sub-processor processing records

---

## 5. Privacy Compliance Framework

### 5.1 GDPR Compliance Mapping

**Complete GDPR Article Mapping:**

| GDPR Article | Requirement | ISO 27701 Control |
|--------------|-------------|-------------------|
| Article 5 | Principles (lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity/confidentiality, accountability) | B.6.1, B.6.3, B.8.1, B.8.2, Multiple |
| Article 6 | Lawfulness of processing | B.6.2 |
| Article 7 | Conditions for consent | B.7.3, B.7.4 |
| Article 9 | Special categories (sensitive data) | B.6.2, B.6.4 |
| Article 12 | Transparent information | B.7.1 |
| Article 13 | Information - direct collection | B.7.1 |
| Article 14 | Information - indirect collection | B.7.2 |
| Article 15 | Right of access | B.7.5 |
| Article 16 | Right to rectification | B.7.5 |
| Article 17 | Right to erasure | B.7.5, B.8.2 |
| Article 18 | Right to restriction | B.7.5 |
| Article 20 | Right to data portability | B.7.5 |
| Article 21 | Right to object | B.7.5 |
| Article 22 | Automated decision-making | B.10.3 |
| Article 25 | Data protection by design/default | B.8.1, B.8.5 |
| Article 26 | Joint controllers | B.9.5 |
| Article 28 | Processor obligations | B.9.6, All Annex C |
| Article 30 | Records of processing | B.9.3, C.6.5 |
| Article 32 | Security of processing | ISO 27002 + Annex A guidance |
| Article 33 | Breach notification to authority | B.10.2 |
| Article 34 | Breach notification to individuals | B.10.2 |
| Article 35 | Data protection impact assessment | B.6.4 |
| Articles 44-50 | International transfers | B.9.1, B.9.2 |

### 5.2 Global Privacy Law Alignment

**CCPA/CPRA (California, USA)**
- Right to know: B.7.5, B.9.4
- Right to delete: B.7.5, B.8.2
- Right to opt-out of sale/sharing: B.7.3, B.7.5
- Right to correct: B.7.5
- Right to limit sensitive data: B.7.3, B.7.5
- Privacy notices: B.7.1
- Do Not Sell link requirement: B.7.1
- Service provider obligations: Annex C controls

**LGPD (Brazil)**
- Legal basis for processing: B.6.2
- Data subject rights: B.7.5
- DPIA requirements: B.6.4
- International transfers: B.9.1
- Data breach notification: B.10.2
- DPO appointment: Clause 5 extensions

**PIPEDA (Canada)**
- Consent requirements: B.7.3, B.7.4
- Openness principle: B.7.1
- Individual access: B.7.5
- Accountability principle: Overall PIMS
- Breach notification: B.10.2

**APPI (Japan)**
- Purpose specification: B.6.1
- Cross-border transfer restrictions: B.9.1
- Security management: ISO 27002 controls
- Individual rights: B.7.5

**POPIA (South Africa)**
- Processing limitation: B.6.1, B.6.5
- Purpose specification: B.6.1
- Data subject participation: B.7.5
- Security safeguards: ISO 27002 controls

---

## 6. Implementation Requirements

### 6.1 Mandatory Documentation for PIMS

**Privacy-Specific Documentation (Beyond ISO 27001):**

1. **Privacy Policy and Framework**
   - Privacy policy (internal)
   - Privacy notice (external, multiple versions)
   - Cookie policy
   - Privacy governance framework

2. **Records of Processing Activities (RoPA)**
   - Processing purposes
   - Categories of data subjects
   - Categories of PII
   - Recipients of PII
   - International transfers
   - Retention periods
   - Security measures
   - Sub-processor information

3. **Legal Basis Documentation**
   - Legal basis for each processing activity
   - Consent records and management
   - Legitimate interest assessments (LIA)
   - Contractual necessity documentation

4. **Privacy Impact Assessments (DPIAs)**
   - DPIA methodology
   - Completed DPIAs for high-risk processing
   - DPIA review and update records
   - Supervisory authority consultations (if required)

5. **PII Principal Rights Management**
   - Rights request procedures
   - Request tracking and response logs
   - Identity verification procedures
   - Deletion and rectification records

6. **Data Transfer Documentation**
   - Transfer impact assessments (TIA)
   - Standard Contractual Clauses (SCCs)
   - Binding Corporate Rules (BCRs) if applicable
   - Adequacy decision documentation
   - Supplementary measures assessment

7. **Processor and Sub-processor Management**
   - Data Processing Agreements (DPAs)
   - Processor/sub-processor register
   - Vendor privacy assessments
   - Sub-processor authorization records

8. **Breach Management**
   - Breach notification procedures
   - Breach assessment records
   - Notification logs (to authorities and individuals)
   - Breach register

9. **Consent Management**
   - Consent capture mechanisms
   - Consent withdrawal procedures
   - Consent records and audit trails
   - Consent refresh procedures

10. **Privacy Training and Awareness**
    - Privacy training programs
    - Training completion records
    - Specialized role training
    - Awareness campaign materials

### 6.2 Data Mapping Requirements

**Essential Data Mapping Elements:**

1. **Data Inventory**
   - All PII types collected/processed
   - Data classification (standard, sensitive, special category)
   - Data sources (direct, indirect, third-party)
   - Data volumes

2. **Data Flow Mapping**
   - Collection points
   - Processing systems
   - Storage locations
   - Transfer destinations
   - Disposal/deletion points
   - Data flow diagrams

3. **Processing Activity Mapping**
   - Processing purposes
   - Processing legal basis
   - Processing duration
   - Processing responsible parties
   - Processing locations (including cloud)

4. **Data Subject Mapping**
   - Categories of data subjects (customers, employees, vendors, etc.)
   - Age considerations (children)
   - Vulnerable populations
   - Special protections required

5. **Risk Mapping**
   - Privacy risks per processing activity
   - Risk levels (low, medium, high)
   - Risk mitigation measures
   - Residual risks

---

## 7. Specialized Attributes for AI Understanding

### 7.1 Control Classification System

**Privacy Control Categories:**

**Category 1: Transparency Controls**
- Purpose: Enable PII principals to understand processing
- Controls: B.7.1, B.7.2
- Implementation: Privacy notices, layered notices, just-in-time notifications
- Automation Level: Medium (template-based with dynamic data)
- Evidence Type: Notice versions, delivery confirmations

**Category 2: Consent Controls**
- Purpose: Manage lawful basis through consent
- Controls: B.7.3, B.7.4
- Implementation: Consent management platforms, consent capture, withdrawal mechanisms
- Automation Level: High (system-managed with audit trails)
- Evidence Type: Consent records, timestamps, version tracking

**Category 3: Rights Management Controls**
- Purpose: Enable exercise of data subject rights
- Controls: B.7.5
- Implementation: DSR portals, automated data extraction, identity verification
- Automation Level: Medium to High (depends on system integration)
- Evidence Type: Request logs, response records, verification logs

**Category 4: Data Minimization Controls**
- Purpose: Limit PII processing to necessary minimum
- Controls: B.6.3, B.8.1, B.8.2
- Implementation: Collection reviews, default settings, retention policies
- Automation Level: Medium (policy-driven with manual review)
- Evidence Type: Collection assessments, configuration records, deletion logs

**Category 5: Purpose Controls**
- Purpose: Ensure processing aligns with specified purposes
- Controls: B.6.1, B.6.5
- Implementation: Purpose documentation, access controls, usage monitoring
- Automation Level: Low to Medium (requires human judgment)
- Evidence Type: Purpose documentation, processing records, access logs

**Category 6: Transfer Controls**
- Purpose: Protect PII in cross-border transfers
- Controls: B.9.1, B.9.2
- Implementation: Transfer mechanisms, impact assessments, contractual safeguards
- Automation Level: Low (high touch, legal complexity)
- Evidence Type: Transfer agreements, assessments, adequacy documentation

**Category 7: Accountability Controls**
- Purpose: Demonstrate compliance and governance
- Controls: B.6.4, B.10.2, Multiple
- Implementation: DPIAs, breach procedures, documentation systems
- Automation Level: Low to Medium (structured but requires expertise)
- Evidence Type: DPIAs, breach records, audit trails

**Category 8: Processor Controls**
- Purpose: Manage processor compliance obligations
- Controls: All Annex C
- Implementation: Processing instructions, sub-processor management, assistance procedures
- Automation Level: Low to Medium (relationship management)
- Evidence Type: Instructions, approvals, assistance records

### 7.2 Privacy Risk Assessment Framework

**Risk Factors for Privacy Impact:**

**Likelihood Factors:**
- Volume of PII processed (higher volume = higher likelihood)
- Sensitivity of PII (special category data increases likelihood)
- Number of data subjects affected
- Complexity of processing operations
- Number of third parties involved
- Geographic scope of processing
- Use of new/emerging technologies
- Level of automation in processing

**Impact Factors:**
- Potential for discrimination or disadvantage
- Potential for identity theft or fraud
- Potential for financial loss
- Potential for physical harm
- Potential for psychological harm
- Potential for reputational damage
- Potential for loss of confidentiality
- Potential for loss of control over personal data
- Irreversibility of consequences

**Risk Matrix:**
```
Likelihood vs Impact Matrix:

Impact →        Low         Medium      High        Critical
Likelihood ↓
Low             Low         Low         Medium      High
Medium          Low         Medium      High        Critical
High            Medium      High        Critical    Critical
Very High       High        Critical    Critical    Critical

Low Risk: Standard controls sufficient
Medium Risk: Enhanced controls required
High Risk: DPIA required, senior review
Critical Risk: DPIA required, DPO consultation, possible supervisory authority consultation
```

### 7.3 Data Subject Rights Workflow Automation

**Automated DSR Processing Requirements:**

**Request Intake:**
- Identity verification (automated challenge questions, document verification)
- Request classification (access, rectification, erasure, restriction, portability, objection)
- Scope determination (systems affected, data categories)
- Complexity assessment (simple vs. complex)

**Request Processing:**
- System search automation (PII location across systems)
- Data compilation (automated extraction and packaging)
- Duplicate detection and deduplication
- Data format conversion (for portability)
- Impact assessment (for erasure/restriction requests)

**Request Fulfillment:**
- Response generation (automated reports)
- Secure delivery mechanisms (encrypted email, secure portal)
- Audit trail creation
- Exception handling (manual review triggers)

**Monitoring and Compliance:**
- SLA tracking (30-day deadline)
- Extension notifications (complex requests)
- Completion verification
- Quality assurance sampling

### 7.4 Privacy Control Dependencies

**Control Dependency Map:**

```
Foundation Controls (Must implement first):
├─ B.6.1 (Identify Purpose) 
│  └─ Enables → B.6.2 (Legal Basis), B.6.5 (Limit Processing), B.7.1 (Privacy Notice)
│
├─ B.6.2 (Legal Basis)
│  └─ Required for → All processing activities
│  └─ If consent-based → B.7.3 (Consent Mechanism), B.7.4 (Consent Records)
│
└─ Data Mapping (Implicit requirement)
   └─ Enables → B.6.3 (Determine Information), B.7.5 (Rights), B.8.2 (Deletion), B.9.1 (Transfers)

Transparency Layer:
├─ B.7.1 (Privacy Notice)
│  └─ Prerequisites → B.6.1 (Purpose), B.6.2 (Legal Basis), Data Mapping
│  └─ Informs → B.7.3 (Consent Mechanism)
│
└─ B.7.2 (Third-Party Notice)
   └─ Prerequisites → B.7.1 (Notice framework), B.9.3 (Disclosure Records)

Rights Management Layer:
└─ B.7.5 (Rights Requests)
   └─ Prerequisites → Data Mapping, B.8.2 (Deletion capability), System integration
   └─ Depends on → B.6.3 (Data Inventory), B.9.4 (Disclosure Records)

Data Minimization Layer:
├─ B.8.1 (Data Minimization)
│  └─ Implements → Privacy by Design principle
│  └─ Supports → B.6.3 (Determine Information)
│
└─ B.8.2 (De-identification/Deletion)
   └─ Prerequisites → Retention policies, B.8.1 (Minimization)
   └─ Enables → B.7.5 (Erasure rights)

Transfer and Sharing Layer:
├─ B.9.1 (Transfer Legal Basis)
│  └─ Prerequisites → B.6.2 (Processing Legal Basis), Transfer Impact Assessment
│  └─ Requires → B.9.2 (Country Documentation)
│
├─ B.9.5 (Controller Contracts)
│  └─ Prerequisites → B.6.1 (Purpose), B.6.2 (Legal Basis)
│
└─ B.9.6 (Processor Contracts)
   └─ Prerequisites → B.6.1 (Purpose), ISO 27001 security controls
   └─ Mandates → All Annex C controls

Processor Controls (Annex C):
├─ C.6.1 (Processing Instructions)
│  └─ Foundation for → All other processor controls
│
└─ C.8.1 (Sub-contractor Engagement)
   └─ Requires → C.8.2 (Sub-contractor Contracts), C.8.3 (Change Management)
```

### 7.5 Privacy Metrics and KPIs

**Transparency Metrics:**
- Privacy notice update frequency
- Privacy notice accessibility score
- Average reading level of privacy notices (aim for 8th grade)
- Multi-language availability coverage
- Just-in-time notice deployment rate

**Consent Metrics:**
- Consent acceptance rate
- Consent withdrawal rate
- Consent refresh completion rate
- Average time to process consent withdrawal
- Consent audit trail completeness

**Rights Management Metrics:**
- DSR volume (by type: access, erasure, rectification, etc.)
- Average DSR response time
- Percentage of DSRs completed within SLA (30 days)
- DSR completion rate
- Identity verification success rate
- Automated vs. manual DSR processing ratio

**Data Minimization Metrics:**
- Percentage of optional vs. mandatory data fields
- Data retention compliance rate
- Automated deletion execution rate
- Data inventory completeness
- PII reduction year-over-year

**Risk and Compliance Metrics:**
- Number of DPIAs completed
- Percentage of high-risk processing with completed DPIA
- Privacy breach incident count
- Breach notification compliance rate (72-hour rule)
- Mean time to detect privacy breach (MTTD)
- Mean time to report privacy breach (MTTR)

**Training and Awareness Metrics:**
- Privacy training completion rate
- Privacy awareness campaign reach
- Role-based training completion (DPO, developers, marketing)
- Privacy incident rate post-training
- Privacy knowledge assessment scores

**Processor Management Metrics:**
- Percentage of processors with compliant DPAs
- Sub-processor approval time
- Processor audit/assessment coverage
- Processor security incident rate
- Processor breach notification compliance

---

## 8. Certification Process

### 8.1 Prerequisites for ISO 27701 Certification

**Mandatory Prerequisites:**

1. **Active ISO 27001 Certification**
   - Must have valid ISO 27001:2022 certificate
   - ISMS must be operational and effective
   - Cannot certify to ISO 27701 without ISO 27001

2. **PIMS Scope Definition**
   - Must align with or be subset of ISMS scope
   - Clear definition of PII processing activities included
   - Identification of controller/processor roles

3. **Privacy Documentation Complete**
   - All mandatory privacy documents in place
   - Records of Processing Activities (RoPA) completed
   - Privacy policies and procedures documented

4. **Gap Assessment Completed**
   - Formal gap analysis against ISO 27701 requirements
   - Action plan to close identified gaps
   - Evidence of gap closure

### 8.2 Certification Stages

**Stage 1: Documentation Review (Conducted with ISO 27001 or separately)**
- Review of PIMS documentation
- Assessment of Records of Processing Activities
- Review of DPIAs and privacy impact assessments
- Evaluation of privacy policies and procedures
- Assessment of readiness for Stage 2
- Duration: 1-2 days (in addition to ISO 27001 Stage 1)

**Stage 2: Implementation Audit**
- Verification of control implementation (Annex B and/or C)
- Testing of DSR processes
- Review of consent management systems
- Examination of processor agreements
- Verification of privacy training effectiveness
- Testing of breach notification procedures
- Interview with DPO/Privacy Officer and staff
- Duration: 2-4 days (in addition to ISO 27001 Stage 2)

**Surveillance Audits (Annual)**
- Verification of PIMS maintenance
- Sample testing of privacy controls
- Review of privacy incidents and breaches
- Assessment of DSR handling
- Review of regulatory changes and compliance
- Duration: 1-2 days (combined with ISO 27001 surveillance)

**Recertification (Every 3 Years)**
- Comprehensive audit similar to Stage 2
- Assessment of continual improvement
- Verification of regulatory compliance
- Review of privacy program maturity
- Duration: Similar to Stage 2 audit

### 8.3 Certification Scopes

Organizations can certify for:

**Controller Certification:**
- Includes Annex B controls (24 controls)
- Suitable for organizations determining purposes and means
- Most common certification type

**Processor Certification:**
- Includes Annex C controls (12 controls)
- Suitable for service providers processing on behalf of controllers
- Increasingly required by enterprise customers

**Combined Controller/Processor Certification:**
- Includes both Annex B and C controls (36 controls)
- Suitable for organizations acting in both roles
- Most comprehensive certification

### 8.4 Common Non-Conformities

**Major Non-Conformities** (prevent certification):
- No Records of Processing Activities (RoPA)
- Missing DPIAs for high-risk processing
- No legal basis documented for processing activities
- Processor agreements missing mandatory Article 28 terms
- No DSR process or mechanism
- Privacy policy missing mandatory information
- No breach notification procedures
- Consent mechanisms not GDPR-compliant

**Minor Non-Conformities** (require correction):
- Incomplete RoPA entries
- Privacy notice missing some information elements
- Consent records incomplete or inconsistent
- DSR response times occasionally exceeding SLA
- Training records incomplete
- Some processor agreements not fully reviewed
- Documentation not current or outdated

---

## 9. Privacy Roles and Responsibilities

### 9.1 Data Protection Officer (DPO)

**Appointment Requirements (GDPR Article 37):**

Mandatory when:
- Public authority or body (with exceptions)
- Core activities require regular and systematic monitoring of data subjects on large scale
- Core activities involve large-scale processing of special category data or criminal data

**Position Characteristics:**
- Must have expert knowledge of data protection law and practices
- Must be independent (no conflict of interest)
- Reports directly to highest management level
- Cannot be dismissed or penalized for performing duties
- Can be in-house or outsourced
- Can be shared among multiple organizations (public authorities)

**Key Responsibilities (GDPR Article 39):**
- Inform and advise organization and employees of privacy obligations
- Monitor compliance with GDPR and organization's privacy policies
- Provide advice regarding Data Protection Impact Assessments (DPIAs)
- Cooperate with supervisory authorities
- Act as contact point for supervisory authorities
- Act as contact point for data subjects regarding their rights
- Consider risks associated with processing operations
- Independence in performing tasks

**ISO 27701 Requirements:**
- Involvement in PIMS development and maintenance
- Escalation point for privacy issues
- Review and approval of privacy documentation
- Privacy training and awareness oversight
- Incident response coordination

### 9.2 Privacy Officer/Manager

**Key Responsibilities:**
- Day-to-day PIMS operation and maintenance
- Coordinate privacy activities across organization
- Manage DSR fulfillment processes
- Oversee privacy training programs
- Conduct privacy assessments and audits
- Maintain privacy documentation
- Manage processor relationships
- Privacy incident response
- Privacy metrics and reporting
- Regulatory monitoring and updates

### 9.3 Data Protection Coordinator (per Department)

**Key Responsibilities:**
- Act as privacy liaison for business unit
- Support privacy officer with local implementation
- Coordinate local privacy training
- Identify and escalate privacy risks
- Support DPIA processes
- Maintain local privacy documentation
- First point of contact for privacy questions

### 9.4 Information Asset Owners

**Privacy-Specific Responsibilities:**
- Classify PII under their control
- Define retention periods for PII
- Authorize access to PII
- Support DSR fulfillment
- Participate in DPIAs
- Report privacy incidents
- Review and approve privacy notices for their systems

### 9.5 System/Application Owners

**Privacy-Specific Responsibilities:**
- Implement privacy by design in systems
- Configure privacy-enhancing controls
- Support data mapping exercises
- Enable DSR fulfillment capabilities
- Implement data retention and deletion
- Support privacy impact assessments
- Privacy incident detection and reporting

### 9.6 All Employees

**Privacy-Specific Responsibilities:**
- Complete mandatory privacy training
- Comply with privacy policies and procedures
- Handle PII according to classification
- Report suspected privacy incidents
- Respect data subject rights
- Follow consent and transparency requirements
- Escalate privacy concerns

---

## 10. Integration with Other Frameworks

### 10.1 ISO Family Integration

**ISO 27001 (Information Security) → ISO 27701 (Privacy)**
- Foundation relationship: ISO 27701 extends ISO 27001
- Single integrated management system
- Shared PDCA methodology
- Combined audit approach
- Unified risk management

**ISO 27002 (Security Controls) → Annex A Guidance**
- Privacy guidance for each ISO 27002 control
- Explains privacy relevance of security controls
- PII-specific implementation considerations

**ISO 27017 (Cloud Security)**
- Complementary for cloud-based PII processing
- Cloud-specific privacy considerations
- Shared responsibility model
- Cloud provider assessments

**ISO 27018 (Cloud Privacy)**
- Specific privacy controls for public cloud PII processors
- Complementary to ISO 27701
- Focus on cloud service provider obligations

**ISO 27701 + ISO 27001 → ISO 27799 (Health Informatics)**
- Healthcare-specific privacy and security
- Patient data protection
- HIPAA alignment

**ISO 27701 → ISO 29100 (Privacy Framework)**
- Conceptual privacy framework alignment
- Privacy principles mapping
- Terminology harmonization

### 10.2 Regulatory Framework Alignment

**GDPR (Primary Alignment)**
- ISO 27701 designed with GDPR as primary reference
- Direct control mapping to GDPR articles
- Compliance with ISO 27701 significantly supports GDPR compliance
- Does not guarantee GDPR compliance (context-dependent)

**CCPA/CPRA Integration**
- Consumer rights mapping to B.7.5
- Sale/sharing opt-out mechanisms
- Privacy notice requirements (B.7.1)
- Service provider obligations (Annex C)
- Sensitive data limitations

**LGPD Integration**
- Similar structure to GDPR
- Legal basis requirements (B.6.2)
- Data subject rights (B.7.5)
- DPIA requirements (B.6.4)
- International transfer controls (B.9.1)

**Multi-Jurisdiction Strategy**
- ISO 27701 provides harmonized approach
- Implement to highest standard (typically GDPR)
- Document jurisdiction-specific variations
- Leverage common controls across regulations
- Reduce compliance complexity and cost

### 10.3 Industry Framework Integration

**NIST Privacy Framework**
- Complementary approach to ISO 27701
- Maps to NIST Privacy Framework Core Functions:
  - Identify-P → Privacy governance, risk assessment (Clause 6)
  - Govern-P → Privacy governance framework (Clause 5)
  - Control-P → Privacy controls (Annex B, C)
  - Communicate-P → Transparency controls (B.7.1, B.7.2)
  - Protect-P → Security controls (ISO 27001/27002)
- Can use together for comprehensive privacy program

**AICPA SOC 2 Type II (Privacy)**
- Trust Services Criteria privacy category
- ISO 27701 supports SOC 2 privacy requirements
- Control mapping between frameworks
- Shared evidence collection

**PCI DSS**
- Payment card data is PII requiring protection
- ISO 27701 provides privacy framework
- PCI DSS provides specific payment security controls
- Complementary, not duplicative

---

## 11. Advanced Implementation Topics

### 11.1 Privacy by Design Integration

**7 Foundational Principles:**

1. **Proactive not Reactive; Preventative not Remedial**
   - Controls: B.6.4 (Privacy Impact Assessment), B.8.5 (Privacy Enhancing Technologies)
   - Implementation: Privacy requirements in project initiation, early-stage DPIAs

2. **Privacy as Default Setting**
   - Controls: B.8.1 (Data Minimization)
   - Implementation: Opt-in defaults, minimum PII collection, automatic deletion

3. **Privacy Embedded into Design**
   - Controls: All Annex B and C controls
   - Implementation: Privacy requirements in SDLC, architecture reviews

4. **Full Functionality (Positive-Sum)**
   - Controls: B.8.5 (Privacy Enhancing Technologies)
   - Implementation: Balance privacy with functionality, avoid false trade-offs

5. **End-to-End Security (Lifecycle Protection)**
   - Controls: B.8.2 (Deletion), B.8.3 (Temporary Files), ISO 27001 controls
   - Implementation: Cradle-to-grave PII protection, secure deletion

6. **Visibility and Transparency**
   - Controls: B.7.1 (Privacy Notice), B.7.2 (Third-Party Notice)
   - Implementation: Clear privacy notices, processing transparency

7. **Respect for User Privacy (User-Centric)**
   - Controls: B.7.3 (Consent), B.7.5 (Rights)
   - Implementation: Easy-to-use privacy controls, rights fulfillment

### 11.2 Privacy Enhancing Technologies (PETs)

**Technology Categories and Use Cases:**

**Data Minimization PETs:**
- Differential Privacy: Statistical anonymization for data analysis
- K-anonymity: Group-based anonymization (k individuals indistinguishable)
- L-diversity: Enhanced k-anonymity with attribute diversity
- T-closeness: Distribution similarity between anonymized and original data
- Use Cases: Analytics, research, data sharing

**Data Protection PETs:**
- Homomorphic Encryption: Computation on encrypted data
- Secure Multi-Party Computation (SMPC): Joint computation without revealing inputs
- Functional Encryption: Selective decryption based on functions
- Use Cases: Cloud computing, data collaboration, secure outsourcing

**Access Control PETs:**
- Attribute-Based Encryption (ABE): Policy-based encryption
- Zero-Knowledge Proofs: Prove knowledge without revealing information
- Anonymous Credentials: Authentication without identification
- Use Cases: Access management, authentication, authorization

**Transparency PETs:**
- Privacy Dashboards: User-facing privacy control centers
- Consent Management Platforms: Granular consent collection and management
- Privacy Icons: Standardized privacy notice symbols
- Use Cases: Transparency, user empowerment, consent management

**Control Mapping:**
- B.8.5 (Privacy Enhancing Technologies) mandates evaluation and implementation
- Risk-based approach: Higher risk = more advanced PETs required
- State-of-the-art consideration: Evolving technology landscape

### 11.3 Cross-Border Transfer Mechanisms

**Detailed Implementation Guidance:**

**Standard Contractual Clauses (SCCs) - Module-Based:**
- Module 1: Controller to Controller
- Module 2: Controller to Processor
- Module 3: Processor to Processor
- Module 4: Processor to Controller

**SCC Implementation Process:**
1. Identify transfer type and select appropriate module
2. Complete mandatory clauses (cannot be modified)
3. Complete optional clauses (docking clause, commercial clauses)
4. Conduct Transfer Impact Assessment (TIA)
5. Implement supplementary measures if required
6. Document and maintain SCC execution records
7. Review periodically (recommend annually minimum)

**Transfer Impact Assessment (TIA) Requirements:**
- Assess laws and practices in destination country
- Evaluate government access to data risks
- Assess practical experience with data requests
- Determine if supplementary measures needed
- Document assessment and conclusions
- Review Schrems II guidance and EDPB recommendations

**Supplementary Measures Examples:**
- Technical: Encryption, anonymization, pseudonymization
- Organizational: Data residency commitments, transparency reports
- Contractual: Enhanced audit rights, breach notification
- Combination of measures often required

**Control Requirements:**
- B.9.1: Identify and document legal basis for transfer
- B.9.2: Document destination countries and organizations
- Regular review of adequacy decisions and transfer mechanisms
- Ongoing monitoring of legal developments in destination countries

### 11.4 Automated Decision-Making and AI

**ISO 27701 Requirements for AI/ML Systems:**

**Transparency Requirements (B.7.1, B.10.3):**
- Inform data subjects about automated decision-making
- Explain logic involved in automated decisions
- Describe significance and envisaged consequences
- Provide information in clear, plain language

**Rights Implementation (B.7.5, B.10.3):**
- Right to human intervention
- Right to express point of view
- Right to obtain explanation
- Right to contest decision
- Mechanism to request human review

**Algorithmic Accountability:**
- Algorithm impact assessments (integrate with B.6.4 DPIAs)
- Regular accuracy testing and validation
- Bias detection and mitigation
- Fairness assessments
- Explainability implementation (XAI techniques)

**Special Protections:**
- Cannot be based solely on automated processing if legal/significant effects
- Exceptions: Contract necessity, explicit consent, legal authorization
- Extra protections for special category data
- Children's data requires enhanced safeguards

**Technical Implementation:**
- Explainable AI (XAI) techniques
- Model documentation and version control
- Training data documentation
- Bias testing frameworks
- Human-in-the-loop mechanisms
- Audit trails for automated decisions

---

## 12. Compliance Measurement and Reporting

### 12.1 Privacy Maturity Model

**Level 1: Initial (Ad-hoc)**
- No formal privacy program
- Reactive approach to privacy incidents
- Limited privacy awareness
- Minimal documentation

**Level 2: Developing (Repeatable)**
- Basic privacy policies in place
- Some privacy processes documented
- Privacy training initiated
- Incident response procedures exist

**Level 3: Defined (Defined and Documented)**
- Comprehensive privacy framework
- All required documentation complete
- Regular privacy training
- Consistent privacy processes
- ISO 27701 baseline compliance

**Level 4: Managed (Measured and Controlled)**
- Privacy metrics and KPIs tracked
- Regular privacy audits
- Privacy integrated into business processes
- Proactive risk management
- Continuous monitoring

**Level 5: Optimized (Continuous Improvement)**
- Privacy by design embedded in culture
- Advanced privacy technologies deployed
- Industry-leading privacy practices
- Continuous optimization
- Innovation in privacy protection

### 12.2 Privacy Program Scorecard

**Governance (25 points):**
- DPO/Privacy Officer appointed and effective (5 pts)
- Privacy policies comprehensive and current (5 pts)
- Privacy governance framework established (5 pts)
- Management commitment demonstrated (5 pts)
- Budget and resources allocated (5 pts)

**Compliance (25 points):**
- Records of Processing Activities complete (5 pts)
- Legal basis documented for all processing (5 pts)
- DPIAs conducted for high-risk processing (5 pts)
- Processor agreements compliant (5 pts)
- Regulatory obligations tracked and met (5 pts)

**Operations (25 points):**
- DSR process effective and timely (5 pts)
- Privacy training completed (5 pts)
- Consent management operational (5 pts)
- Data minimization practiced (5 pts)
- Privacy incidents managed effectively (5 pts)

**Technical (25 points):**
- Privacy-enhancing technologies deployed (5 pts)
- Data security controls implemented (5 pts)
- Privacy by design in development (5 pts)
- Monitoring and logging adequate (5 pts)
- Automated controls where possible (5 pts)

**Scoring:**
- 90-100: Excellent (Level 5)
- 75-89: Good (Level 4)
- 60-74: Adequate (Level 3)
- 40-59: Needs Improvement (Level 2)
- 0-39: Inadequate (Level 1)

### 12.3 Management Reporting Template

**Monthly Privacy Report:**

1. **Executive Summary**
   - Overall privacy posture status
   - Key achievements
   - Critical issues requiring attention
   - Upcoming priorities

2. **Metrics Dashboard**
   - DSR volumes and response times
   - Privacy training completion rates
   - Privacy incident count and severity
   - Breach notification compliance
   - Consent rates and withdrawals

3. **Compliance Status**
   - Regulatory compliance updates
   - Audit findings and remediation status
   - Policy review status
   - Certification status (ISO 27701)

4. **Risk Management**
   - New or emerging privacy risks
   - DPIA completions
   - Risk mitigation progress
   - Residual risk assessment

5. **Initiatives and Projects**
   - Privacy improvement initiatives
   - System privacy enhancements
   - Training and awareness campaigns
   - Technology implementations

6. **Issues and Escalations**
   - Open issues requiring management action
   - Resource needs
   - Budget requests
   - Policy exceptions

**Quarterly Board Report:**
- Strategic privacy program overview
- Regulatory landscape changes
- Privacy risk profile
- Major incidents and lessons learned
- Investment recommendations
- Industry benchmarking
- Privacy program maturity assessment

---

## 13. Certification Maintenance and Continual Improvement

### 13.1 Annual Activities

**Mandatory Annual Activities:**

✓ **Privacy Risk Assessment**
- Re-assess all processing activities
- Identify new privacy risks
- Update risk treatment plans
- Document risk acceptance decisions

✓ **Management Review**
- Review PIMS performance
- Assess privacy objectives achievement
- Review privacy incidents and trends
- Evaluate resource adequacy
- Make decisions on continual improvement

✓ **Internal Privacy Audit**
- Audit sample of Annex B/C controls
- Test DSR processes
- Review processor agreements
- Verify consent management
- Check documentation currency

✓ **Policy Review and Update**
- Review all privacy policies
- Update for regulatory changes
- Incorporate lessons learned
- Obtain management approval

✓ **Training and Awareness**
- Conduct annual privacy training
- Update training content
- Specialized role training
- Record completion

✓ **Surveillance Audit**
- External auditor visit
- Control sampling
- Evidence review
- Non-conformity addressing

### 13.2 Triggers for PIMS Updates

**Mandatory Update Triggers:**
- New or changed processing activities
- New system implementations
- Organizational restructuring
- Mergers or acquisitions
- New third-party processors
- Regulatory changes
- Significant privacy incidents
- Audit findings
- Changes in risk profile
- New products or services
- Geographic expansion
- Technology changes

**Update Process:**
1. Identify change trigger
2. Assess impact on PIMS
3. Update relevant documentation
4. Conduct DPIA if required
5. Update RoPA
6. Train affected personnel
7. Update privacy notices if needed
8. Notify relevant parties
9. Document change
10. Monitor effectiveness

### 13.3 Continuous Improvement Sources

**Internal Sources:**
- Privacy incident analysis
- DSR trends and challenges
- Internal audit findings
- Employee feedback
- Privacy metrics and KPIs
- Process inefficiencies
- Technology limitations

**External Sources:**
- External audit findings
- Regulatory guidance updates
- Industry best practices
- Peer benchmarking
- Privacy research
- Technology innovations
- Stakeholder feedback
- Supervisory authority guidance

**Improvement Implementation:**
1. Identify improvement opportunity
2. Assess feasibility and priority
3. Develop improvement plan
4. Obtain approval and resources
5. Implement changes
6. Monitor effectiveness
7. Document lessons learned
8. Share across organization

---

## 14. Compliance Checklist

### 14.1 Pre-Certification Readiness Checklist

**Foundation Requirements:**
- [ ] ISO 27001 certification active and current
- [ ] PIMS scope defined and documented
- [ ] Controller/Processor role(s) identified
- [ ] Gap assessment completed
- [ ] Remediation plan executed

**Documentation Requirements:**
- [ ] Privacy policy established and approved
- [ ] Records of Processing Activities (RoPA) complete
- [ ] Privacy procedures documented
- [ ] Privacy notices created (internal and external)
- [ ] Cookie policy created (if applicable)
- [ ] DPIAs completed for high-risk processing
- [ ] Legal basis documented for all processing
- [ ] Legitimate Interest Assessments (where applicable)
- [ ] Transfer mechanisms documented (SCCs, BCRs, etc.)
- [ ] Processor agreements in place with Article 28 terms
- [ ] Sub-processor register maintained
- [ ] Consent management procedures documented
- [ ] DSR procedures documented
- [ ] Breach notification procedures documented

**Operational Requirements:**
- [ ] DPO appointed (if required) or Privacy Officer designated
- [ ] Privacy roles and responsibilities assigned
- [ ] DSR process operational and tested
- [ ] Consent management system operational
- [ ] Breach notification process tested
- [ ] Privacy training delivered to all personnel
- [ ] Specialized privacy training for key roles
- [ ] Data mapping completed
- [ ] Privacy controls implemented per scope
- [ ] Processor audits/assessments conducted

**Evidence Requirements:**
- [ ] Privacy training records maintained
- [ ] Consent records available
- [ ] DSR fulfillment records available
- [ ] Privacy incident records maintained
- [ ] Internal privacy audit completed
- [ ] Management review conducted
- [ ] Non-conformities addressed

### 14.2 Controller Controls Checklist (Annex B)

**Purpose and Legal Basis:**
- [ ] B.6.1: Purposes identified and documented
- [ ] B.6.2: Legal basis identified and documented
- [ ] B.6.3: Information to collect determined and justified
- [ ] B.6.4: Privacy impact assessments conducted
- [ ] B.6.5: Processing limited to identified purposes

**PII Principal Obligations:**
- [ ] B.7.1: Privacy information provided to PII principals
- [ ] B.7.2: Privacy notice for third-party collection provided
- [ ] B.7.3: Consent mechanism implemented
- [ ] B.7.4: Consent obtained and recorded
- [ ] B.7.5: PII principal request process operational

**Privacy by Design:**
- [ ] B.8.1: Data minimization implemented
- [ ] B.8.2: De-identification and deletion capabilities operational
- [ ] B.8.3: Temporary files and logs managed
- [ ] B.8.4: Media disposal procedures implemented
- [ ] B.8.5: Privacy-enhancing technologies evaluated and deployed

**Sharing and Transfer:**
- [ ] B.9.1: Legal basis for transfers documented
- [ ] B.9.2: Destination countries documented
- [ ] B.9.3: Records of disclosures to third parties maintained
- [ ] B.9.4: Records of PII disclosures available to PII principals
- [ ] B.9.5: Contracts with other PII controllers established
- [ ] B.9.6: Contracts with PII processors compliant
- [ ] B.9.7: Privacy addressed in supplier agreements

**Compliance:**
- [ ] B.10.1: Contractual obligations tracked
- [ ] B.10.2: PII breach notification procedures operational
- [ ] B.10.3: Automated decision-making safeguards implemented

### 14.3 Processor Controls Checklist (Annex C)

**Processing Obligations:**
- [ ] C.6.1: Processing based on instructions
- [ ] C.6.2: Processing limitations enforced
- [ ] C.6.3: DPIA support procedures established
- [ ] C.6.4: Return or deletion of PII procedures operational
- [ ] C.6.5: Documentation and records maintained

**Controller and Principal Obligations:**
- [ ] C.7.1: PII principal request assistance procedures established
- [ ] C.7.2: Breach notification to controller procedures operational
- [ ] C.7.3: Compliance information provision procedures established

**Sub-contractor Management:**
- [ ] C.8.1: Sub-contractor engagement authorization process established
- [ ] C.8.2: Sub-contractor contracts compliant
- [ ] C.8.3: Sub-contractor change notification process operational
- [ ] C.8.4: Records of disclosures to sub-contractors maintained

### 14.4 Ongoing Compliance Checklist

**Monthly:**
- [ ] Review DSR status and response times
- [ ] Monitor privacy incidents
- [ ] Review consent management metrics
- [ ] Check processor compliance
- [ ] Review privacy training completion

**Quarterly:**
- [ ] Privacy metrics reporting
- [ ] Privacy risk review
- [ ] Processor assessment sampling
- [ ] Privacy awareness campaigns
- [ ] Update privacy notices if needed

**Semi-Annually:**
- [ ] Review RoPA and update
- [ ] Review and update DPIAs
- [ ] Processor agreement reviews
- [ ] Privacy policy review

**Annually:**
- [ ] Comprehensive privacy risk assessment
- [ ] Management review
- [ ] Internal privacy audit
- [ ] Privacy policy formal review and approval
- [ ] Comprehensive privacy training
- [ ] Processor audits (sample)
- [ ] Surveillance audit preparation and execution
- [ ] Transfer mechanism reviews (SCCs, adequacy)
- [ ] Privacy program maturity assessment

**Triggered Events:**
- [ ] New processing activity: DPIA, RoPA update, notice update
- [ ] Privacy incident: Investigation, notification, lessons learned
- [ ] Regulatory change: Gap assessment, updates, training
- [ ] New processor: Due diligence, DPA, authorization
- [ ] System change: Privacy impact assessment
- [ ] Organizational change: PIMS scope review, role updates

---

## 15. References and Resources

### 15.1 Primary Standards and Guidance

**ISO Standards:**
- ISO/IEC 27701:2019 - Privacy Information Management System
- ISO/IEC 27001:2022 - Information Security Management System
- ISO/IEC 27002:2022 - Information Security Controls
- ISO/IEC 27017:2015 - Cloud Services Information Security
- ISO/IEC 27018:2019 - Protection of PII in Public Clouds
- ISO/IEC 29100:2011 - Privacy Framework
- ISO/IEC 29134:2017 - Privacy Impact Assessment Guidelines

**GDPR Resources:**
- Regulation (EU) 2016/679 - General Data Protection Regulation
- EDPB Guidelines (European Data Protection Board)
- Article 29 Working Party Guidance
- Schrems II Decision (C-311/18)
- Standard Contractual Clauses (2021)

**Other Regulatory Frameworks:**
- CCPA/CPRA - California Privacy Rights Act
- LGPD - Lei Geral de Proteção de Dados (Brazil)
- PIPEDA - Personal Information Protection and Electronic Documents Act (Canada)
- APPI - Act on the Protection of Personal Information (Japan)
- POPIA - Protection of Personal Information Act (South Africa)

### 15.2 Certification Bodies and Resources

**Accredited Certification Bodies:**
- Contact your regional accreditation body
- ANAB (ANSI National Accreditation Board) - USA
- UKAS (United Kingdom Accreditation Service) - UK
- DAkkS (Deutsche Akkreditierungsstelle) - Germany
- Others per ISO 17021-1 accreditation

**Professional Resources:**
- IAPP (International Association of Privacy Professionals)
- ISO Technical Committee 215/SC 27
- NIST Privacy Framework
- Privacy by Design principles (Ann Cavoukian)

---

## Document Control

**Document Version:** 1.0  
**Last Updated:** October 2025  
**Next Review Date:** October 2026  
**Document Owner:** Privacy Office  
**Document Classification:** Internal Use  
**Related Documents:** ISO 27001 Compliance Document, Privacy Policy, Records of Processing Activities

**Revision History:**

| Version | Date | Author | Changes |
|---------|------|--------|---------|
| 1.0 | Oct 2025 | Compliance Team | Initial comprehensive ISO 27701 document creation |

---

## Appendix A: Quick Reference - Control Implementation Priority

**Phase 1: Foundation (Months 1-3)**
- B.6.1: Identify and document purpose
- B.6.2: Identify legal basis
- B.6.3: Determine information to collect
- B.7.1: Privacy notice
- Data mapping and RoPA creation

**Phase 2: Rights and Governance (Months 4-6)**
- B.7.5: PII principal rights process
- B.7.3 & B.7.4: Consent mechanism (if consent-based)
- B.6.4: Privacy impact assessment process
- B.10.2: Breach notification procedures
- DPO/Privacy Officer appointment

**Phase 3: Data Protection (Months 7-9)**
- B.8.1: Data minimization
- B.8.2: De-identification and deletion
- B.8.5: Privacy-enhancing technologies
- B.9.6: Processor agreements (if controller)
- C.6.1-C.6.5: Processing obligations (if processor)

**Phase 4: Transfers and Advanced (Months 10-12)**
- B.9.1 & B.9.2: Transfer mechanisms
- B.10.3: Automated decision-making (if applicable)
- C.8.1-C.8.4: Sub-processor management (if processor)
- All remaining controls
- Certification readiness

---

*This document provides comprehensive guidance for ISO 27701:2019 compliance. Organizations should adapt requirements to their specific context, processing activities, and regulatory environment. ISO 27701 certification requires active ISO 27001 certification as a foundation.*