ISO 27701:2019
Additional ISO/IEC 27002 guidance for PII processors, ISO 27701:2019

ISO 27701:2019 8.3.1: Obligations to PII principals

The organization must equip the customer to meet the obligations it owes to individuals, recognising that those obligations may be set by legislation, regulation or contract and may include matters where the customer relies on the organization's services to implement them, such as correcting or deleting data in a timely fashion, and where the customer depends on information or technical measures from the organization to meet its obligations, those must be specified in a contract.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 22 controls across 12 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 5 controls

ISO 27002:2022 · 4 controls

  • 5.15 Access control
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.34 Privacy and protection of PII
  • 8.10 Information deletion

SOC 2 · 4 controls

  • SOC2-P5.2 P5.2 Correction of personal information
  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • SOC2-P6.7 P6.7 Accounting of personal information held and disclosed
  • SOC2-P8.1 P8.1 Inquiries, complaints, disputes and compliance monitoring

C5 (Germany) · 1 control

  • C5-PI-01 Documentation and safety of input and output interfaces

CCPA/CPRA · 1 control

  • CCR §7050 Service Provider and Contractor Obligations

CIS Controls v8 · 1 control

CMMC 2.0 · 1 control

  • CCM-DSP-11 Personal Data Access, Reversal, Rectification and Deletion

GDPR · 1 control

  • GDPR-Art.12 Transparent information, communication and modalities for rights

ISO 22301:2019 · 1 control

ISO 27001:2022 · 1 control

  • 5.34 Privacy and protection of personal identifiable information (PII)

ISO 9001:2015 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Additional ISO/IEC 27002 guidance for PII processors, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 8.3.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 22 it maps to, and the evidence behind each claim, over MCP and REST.