Turn GDPR and PIPL obligations from statements of intent into a system that can be audited, handed over and actually run.
ISO/IEC 27701 is the privacy information management system (PIMS) standard. It maps statutory privacy obligations onto auditable controls and separates what a controller owes from what a processor owes. Its real value is not another certificate — it is turning "we comply with GDPR" into evidence a third party can verify line by line, which is exactly what overseas buyers ask for in due diligence. We extend a PIMS from the information security management system you already have rather than starting a parallel one.
Every applicable GDPR and PIPL requirement is mapped to a PIMS control with a named owner, a defined record and retained evidence. Written policy matters less than whether the process runs.
One company can be a controller in one line of business and a processor in another, with different obligations in each. Settle the roles first, then design the processes and contract terms — otherwise the boundary gets discovered during an incident.
Intake, identity verification, internal routing and statutory clocks for access, correction, deletion, portability and objection requests, built as a working process rather than a paragraph in a policy.
PIMS controls overlap heavily with ISO 27001. Extending an existing ISMS is faster and cheaper than standing up a second system, and it avoids preparing for two audits separately.
Work through business lines, data types and processing scenarios, establish whether the company is controller or processor in each, and set the PIMS scope.
Map each applicable obligation to a control, compare against current state, and produce a remediation list with owners and deadlines.
Wire rights response, records of processing, incident notification and vendor assessment into the actual business systems, retaining evidence to audit standard from the start.
Prepare audit materials and coordinate the certification body; after certification, run the system as part of daily operations with change and new business brought into review.
Privacy programmes most often go wrong by treating written policy as completion. Audits and customer due diligence look at operating records — who handled which request, when, on what basis, and how long it took. So we design the processes from day one for the fact that someone will later verify them line by line.
Tell us how the business operates, which jurisdictions you touch and what compliance foundation exists today. We will come back with role definitions, a gap list and a build path.
Book a consultation