Skip to content
Singahi

Resources

The ISO 27701 privacy (PIMS) toolkit

ISO 27701 extends an ISO 27001 ISMS into a privacy information management system, adding management clauses plus Annex A controls that split by whether you act as a PII controller or a PII processor. This toolkit gives you a plain-language guide and a ready-to-use Control Pack for every one, with DPDP Act context throughout, published one guide a day.

0 of 43 guides published

Publishing begins 28 Oct 2026, one guide a day. Want to know the moment a guide goes live? Reach out and we'll notify you.

Clause 4 · Context of the organization

0 of 4 live
  • 4.1Understanding the Organization and Its Context28 Oct 2026
  • 4.2Understanding the Needs and Expectations of Interested Parties29 Oct 2026
  • 4.3Determining the Scope of the Privacy Information Management System30 Oct 2026
  • 4.4Privacy Information Management System31 Oct 2026

Clause 5 · Leadership

0 of 3 live
  • 5.1Leadership and Commitment1 Nov 2026
  • 5.2Privacy Policy2 Nov 2026
  • 5.3Roles, Responsibilities and Authorities3 Nov 2026

Clause 6 · Planning

0 of 3 live
  • 6.1Actions to Address Risks and Opportunities4 Nov 2026
  • 6.2Privacy Objectives and Planning to Achieve Them5 Nov 2026
  • 6.3Planning of Changes6 Nov 2026

Clause 7 · Support

0 of 5 live
  • 7.1Resources7 Nov 2026
  • 7.2Competence8 Nov 2026
  • 7.3Awareness9 Nov 2026
  • 7.4Communication10 Nov 2026
  • 7.5Documented Information11 Nov 2026

Clause 8 · Operation

0 of 3 live
  • 8.1Operational Planning and Control12 Nov 2026
  • 8.2Privacy Risk Assessment13 Nov 2026
  • 8.3Privacy Risk Treatment14 Nov 2026

Clause 9 · Performance evaluation

0 of 3 live
  • 9.1Monitoring, Measurement, Analysis and Evaluation15 Nov 2026
  • 9.2Internal Audit16 Nov 2026
  • 9.3Management Review17 Nov 2026

Clause 10 · Improvement

0 of 2 live
  • 10.1Nonconformity and Corrective Action18 Nov 2026
  • 10.2Continual Improvement19 Nov 2026

A.1 · Annex A — PII controllers

0 of 11 live
  • A.1.2Conditions for Collection and Processing (Remaining)20 Nov 2026
  • A.1.2.2Identify and Document Purpose21 Nov 2026
  • A.1.2.3Identify Lawful Basis22 Nov 2026
  • A.1.2.5Obtain and Record Consent23 Nov 2026
  • A.1.2.6Privacy Impact Assessment24 Nov 2026
  • A.1.3Obligations to PII Principals (Remaining)25 Nov 2026
  • A.1.3.7Access, Correction or Erasure26 Nov 2026
  • A.1.3.11Automated Decision Making27 Nov 2026
  • A.1.4Privacy by Design and Privacy by Default28 Nov 2026
  • A.1.5Sharing Transfer and Disclosure (Remaining)29 Nov 2026
  • A.1.5.2Identify Basis for PII Transfer Between Jurisdictions30 Nov 2026

A.2 · Annex A — PII processors

0 of 5 live
  • A.2.2Conditions for Collection and Processing (Remaining)1 Dec 2026
  • A.2.2.5Infringing Instruction2 Dec 2026
  • A.2.3Obligations and A.2.4 Privacy by Design (Remaining)3 Dec 2026
  • A.2.5Sharing Transfer and Disclosure (Remaining)4 Dec 2026
  • A.2.5.7Sub-processor Chain5 Dec 2026

A.3 · Annex A — 27002 control themes

0 of 4 live
  • A.3Organisational Controls6 Dec 2026
  • A.3People Controls7 Dec 2026
  • A.3Physical Controls8 Dec 2026
  • A.3Technological Controls9 Dec 2026

How we can help

Working toward ISO 27701?

If a customer, a regulator or your own board is asking whether you could keep operating through a serious disruption, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.