DataAigis
Going global

ISO 27701 privacy information management

Turn GDPR and PIPL obligations from statements of intent into a system that can be audited, handed over and actually run.

Overview

ISO/IEC 27701 is the privacy information management system (PIMS) standard. It maps statutory privacy obligations onto auditable controls and separates what a controller owes from what a processor owes. Its real value is not another certificate — it is turning "we comply with GDPR" into evidence a third party can verify line by line, which is exactly what overseas buyers ask for in due diligence. We extend a PIMS from the information security management system you already have rather than starting a parallel one.

Key Capabilities

Obligations mapped to controls

Every applicable GDPR and PIPL requirement is mapped to a PIMS control with a named owner, a defined record and retained evidence. Written policy matters less than whether the process runs.

Controller and processor roles

One company can be a controller in one line of business and a processor in another, with different obligations in each. Settle the roles first, then design the processes and contract terms — otherwise the boundary gets discovered during an incident.

Data subject rights in practice

Intake, identity verification, internal routing and statutory clocks for access, correction, deletion, portability and objection requests, built as a working process rather than a paragraph in a policy.

Built alongside information security

PIMS controls overlap heavily with ISO 27001. Extending an existing ISMS is faster and cheaper than standing up a second system, and it avoids preparing for two audits separately.

What you get

A mapping from GDPR and PIPL obligations to specific controls
Controller and processor roles defined, with responsibilities split accordingly
A data subject rights process with statutory deadline management
Records of processing and a data flow inventory
Vendor management and cross-border transfer clauses and assessments
An evidence pack you can hand straight to a customer's due diligence team

How we run it

1

Current state and role mapping

Work through business lines, data types and processing scenarios, establish whether the company is controller or processor in each, and set the PIMS scope.

2

Obligation mapping and gap analysis

Map each applicable obligation to a control, compare against current state, and produce a remediation list with owners and deadlines.

3

Process implementation and evidence

Wire rights response, records of processing, incident notification and vendor assessment into the actual business systems, retaining evidence to audit standard from the start.

4

Audit preparation and ongoing operation

Prepare audit materials and coordinate the certification body; after certification, run the system as part of daily operations with change and new business brought into review.

Privacy programmes most often go wrong by treating written policy as completion. Audits and customer due diligence look at operating records — who handled which request, when, on what basis, and how long it took. So we design the processes from day one for the fact that someone will later verify them line by line.

Talk through your privacy programme

Tell us how the business operates, which jurisdictions you touch and what compliance foundation exists today. We will come back with role definitions, a gap list and a build path.

Book a consultation