Contact us
Illustration for ISO management-system services

ISO/IEC 27701

ISO/IEC 27701 privacy information management consulting

ISO/IEC 27701 consulting helps organisations handling personal data connect privacy risks with management processes. Make processing purposes, roles, rights and supplier responsibilities traceable. Vosurein starts with the scope, existing processes and evidence, then helps assign responsibilities, implement the system and review it internally.

Discuss ISO/IEC 27701 privacy information management consulting needs

For Your Business

Who this service is for and when to start

Organizations that collect, use, or process personal data on behalf of clients can evaluate implementation when services go live, data flow changes, or customers request privacy management proof. Companies that adopted the 2019 version should review gaps according to the new 2025 structure.

First, confirm the organization’s role in different data processing activities. The same company may have different responsibilities across services and cannot be summarized with a single name.

The Challenge

Common challenges faced by businesses

A privacy policy that differs from actual data flows, or unclear retention and deletion after transfer to suppliers, makes accountability difficult. Without identity checks and internal procedures, requests to exercise data subject rights may be delayed or lead to excessive disclosure.

Information security controls alone are insufficient for personal data. Also examine why data is processed, who decides, and the rights of and impacts on the people concerned.

Our Approach

Methods and applicable requirements

ISO/IEC 27701:2025 is the second edition of the privacy information management system requirements and guidance, replacing the 2019 edition. It is a standalone management system standard for personally identifiable information controllers and processors. It can integrate with ISO/IEC 27001, but prior adoption of 27001 is not required to implement it.

Roles, purposes, and data flows

Consulting reviews processing purposes, data sources, flows and roles to clarify the responsibilities of the organisation and outsourced services. Define the scope around actual activities so the policy covers how data is really processed.

Rights requests and data handling

Organize processes for request acceptance, identity verification, internal search, access, and retention/deletion. Confirm specific legal requirements based on applicable regions; the system ensures consistent execution and evidence maintenance.

Impact and external interfaces

Review processing changes, risks, and privacy impacts, and organize supplier and cross-border data interfaces. Management measures need to be linked to actual scenarios; certificates cannot be used as a guarantee of global privacy law compliance.

Process

Consulting scope and process

  1. Map processing activities

    Identify data, purposes, roles, and system suppliers to define the scope of the PIMS.

  2. Establish privacy processes

    Arrange for rights requests, retention/disposal, and external interface responsibilities.

  3. Review case evidence

    Use de-identified examples to check that procedures work and address gaps and training needs.

  4. Review risks and revisions

    Track risks, internal audits, and management reviews; for existing systems, additionally verify gaps in version upgrades.

Preparation

What documents do companies need to prepare?

  • Activities and roles: Processing purposes, types of personal data, and roles of controllers and processors.
  • Data and flows: Data sources, systems, suppliers, and cross-border interfaces.
  • Policies and handling: Privacy policies, rights requests, and retention/deletion rules.
  • Evaluation and implementation: Risk or impact assessment, case summaries, and evidence of improvements.

For an initial discussion, provide a summary or de-identified sample. Share full records under the agreed scope, access permissions and confidentiality arrangements. Check whether existing records are still valid before filling gaps; there is no assumption that every document must be rewritten.

Project Planning

Estimating time and cost

Evaluate based on data activities, involved regions, number of suppliers, and system foundations. Jurisdictional legal judgments and system functionality modifications should be separately confirmed; initially prioritize using summaries and de-identified data.

Each project specifies the number of on-site interviews, document revisions, training sessions, internal-audit support activities and improvement reviews, together with responsibilities. Third-party certification, specialist testing, engineering and legal services are not included in consulting fees by default. Confirm transition schedules for existing certificates with the certification body.

FAQ

Frequently asked questions

Is having a privacy policy enough?

No. The policy must match actual data flows, rights handling and controls. Check applicable laws separately; certification is not proof of compliance with every privacy law worldwide.

Does the 2025 version have to be paired with ISO/IEC 27001?

The 2025 version is a standalone management system standard and can also be integrated with 27001. If applying for third-party certification, it is necessary to separately confirm the applicable arrangements of the certification body and the scheme.

Is it okay to change only the year from the 2019 version to the 2025 version?

Not suitable. The new version is already an independent management system architecture and should be checked according to formal requirements regarding scope, governance, and the connection between existing controls, rather than just changing document labeling.

How do controllers and processors differ?

Responsibilities must be identified based on actual handling activities and decision-making, consistent with contracts and applicable regulations. Judgment cannot be made solely by company name or whether outsourcing is performed.

Can a certificate represent compliance with all personal data laws?

No. Applicable laws, rights and responsibilities still need to be assessed. A management system supports implementation and evidence, but does not replace legal assessment.

Does completing consulting guarantee a certificate?

No certificate is issued automatically. Vosurein helps establish and pilot the system and review evidence. An independent third party assesses and issues certificates under its applicable scheme. Before applying, check the certification scope, accreditation status and customer acceptance. We do not guarantee certification or fabricate records.

Related

Related services and enquiries

Please share your industry, activities and sites in scope, existing management systems and target completion date so we can define the scope of work.Contact Vosurein

Content checked: . Applicable versions and requirements depend on the company’s circumstances.

Let's Talk

Start a conversation about your needs.

Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.

Discuss your service needsBack to ISO management-system contents