Resources
The ISO 27701 privacy (PIMS) toolkit
ISO 27701 extends an ISO 27001 ISMS into a privacy information management system, adding management clauses plus Annex A controls that split by whether you act as a PII controller or a PII processor. This toolkit gives you a plain-language guide and a ready-to-use Control Pack for every one, with DPDP Act context throughout, published one guide a day.
0 of 43 guides published
Publishing begins 28 Oct 2026, one guide a day. Want to know the moment a guide goes live? Reach out and we'll notify you.
Clause 4 · Context of the organization
0 of 4 live- 4.1Understanding the Organization and Its Context28 Oct 2026
- 4.2Understanding the Needs and Expectations of Interested Parties29 Oct 2026
- 4.3Determining the Scope of the Privacy Information Management System30 Oct 2026
- 4.4Privacy Information Management System31 Oct 2026
Clause 5 · Leadership
0 of 3 live- 5.1Leadership and Commitment1 Nov 2026
- 5.2Privacy Policy2 Nov 2026
- 5.3Roles, Responsibilities and Authorities3 Nov 2026
Clause 6 · Planning
0 of 3 live- 6.1Actions to Address Risks and Opportunities4 Nov 2026
- 6.2Privacy Objectives and Planning to Achieve Them5 Nov 2026
- 6.3Planning of Changes6 Nov 2026
Clause 7 · Support
0 of 5 live- 7.1Resources7 Nov 2026
- 7.2Competence8 Nov 2026
- 7.3Awareness9 Nov 2026
- 7.4Communication10 Nov 2026
- 7.5Documented Information11 Nov 2026
Clause 8 · Operation
0 of 3 live- 8.1Operational Planning and Control12 Nov 2026
- 8.2Privacy Risk Assessment13 Nov 2026
- 8.3Privacy Risk Treatment14 Nov 2026
Clause 9 · Performance evaluation
0 of 3 live- 9.1Monitoring, Measurement, Analysis and Evaluation15 Nov 2026
- 9.2Internal Audit16 Nov 2026
- 9.3Management Review17 Nov 2026
Clause 10 · Improvement
0 of 2 live- 10.1Nonconformity and Corrective Action18 Nov 2026
- 10.2Continual Improvement19 Nov 2026
A.1 · Annex A — PII controllers
0 of 11 live- A.1.2Conditions for Collection and Processing (Remaining)20 Nov 2026
- A.1.2.2Identify and Document Purpose21 Nov 2026
- A.1.2.3Identify Lawful Basis22 Nov 2026
- A.1.2.5Obtain and Record Consent23 Nov 2026
- A.1.2.6Privacy Impact Assessment24 Nov 2026
- A.1.3Obligations to PII Principals (Remaining)25 Nov 2026
- A.1.3.7Access, Correction or Erasure26 Nov 2026
- A.1.3.11Automated Decision Making27 Nov 2026
- A.1.4Privacy by Design and Privacy by Default28 Nov 2026
- A.1.5Sharing Transfer and Disclosure (Remaining)29 Nov 2026
- A.1.5.2Identify Basis for PII Transfer Between Jurisdictions30 Nov 2026
A.2 · Annex A — PII processors
0 of 5 live- A.2.2Conditions for Collection and Processing (Remaining)1 Dec 2026
- A.2.2.5Infringing Instruction2 Dec 2026
- A.2.3Obligations and A.2.4 Privacy by Design (Remaining)3 Dec 2026
- A.2.5Sharing Transfer and Disclosure (Remaining)4 Dec 2026
- A.2.5.7Sub-processor Chain5 Dec 2026
A.3 · Annex A — 27002 control themes
0 of 4 live- A.3Organisational Controls6 Dec 2026
- A.3People Controls7 Dec 2026
- A.3Physical Controls8 Dec 2026
- A.3Technological Controls9 Dec 2026
How we can help
Working toward ISO 27701?
If a customer, a regulator or your own board is asking whether you could keep operating through a serious disruption, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.