Back to Frameworks

ISO/IEC 27701:2019

International
3 domains
77 controls

ISO/IEC 27701:2019 is a privacy extension to ISO/IEC 27001 and ISO/IEC 27002, providing requirements and guidance for establishing, maintaining, and continually improving a Privacy Information Management System (PIMS).

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (3)

Both

28 controls
Controls in the Both domain of ISO/IEC 27701:201928 controls
CodeTitle
5.2.1Understanding the organization and its context (PIMS)
5.2.2Understanding the needs and expectations of interested parties (PIMS)
5.2.3Determining the scope of the PIMS
5.2.4PIMS establishment, implementation, maintenance and continual improvement
5.3.1Leadership and commitment (PIMS)
5.3.2Privacy policy
5.3.3Organizational roles, responsibilities and authorities (PIMS)
5.4.1Quality Objectives
5.4.1.2Privacy risk assessment
5.4.1.3Privacy risk treatment
5.4.2Articulating risk management commitment
5.5.1Responsibility and Authority
5.5.2Management Representative
5.5.3Awareness (PIMS)
5.5.4Communication (PIMS)
5.5.5Documented information (PIMS)
5.6.1Management Review - General
5.7.1Monitoring, measurement, analysis and evaluation (PIMS)
5.7.2Internal audit (PIMS)
5.7.3Management review (PIMS)
5.8.1Nonconformity and corrective action (PIMS)
6.11.1.2Inclusion of PII in supplier agreements
6.13.1.1Privacy incident management
6.15.1.1Identification of applicable privacy legislation
6.2.1.1Policies for information security (privacy-extended)
6.5.2.1Classification of information (PII)
6.5.3.1Management of removable media (PII)
6.9.4.1Event logging (PII access)

PII Controller

31 controls
Controls in the PII Controller domain of ISO/IEC 27701:201931 controls
CodeTitle
7.2.1Determination of Product Requirements
7.2.2Information security awareness, education and training (cloud)
7.2.3Communication
7.2.4Obtain and record consent (Controller)
7.2.5Privacy impact assessment (Controller)
7.2.6Contracts with PII processors (Controller)
7.2.7Joint PII controller (Controller)
7.2.8Records related to processing PII (Controller)
7.3.1Determining and fulfilling obligations to PII principals (Controller)
7.3.10Design and Development Files
7.3.2Design and Development Planning
7.3.3Design and Development Inputs
7.3.4Design and Development Outputs
7.3.5Design and Development Review
7.3.6Design and Development Verification
7.3.7Design and Development Validation
7.3.8Design and Development Transfer
7.3.9Control of Design Changes
7.4.1Purchasing Process
7.4.2Purchasing Information
7.4.3Verification of Purchased Product
7.4.4PII minimization objectives (Controller)
7.4.5PII de-identification and deletion at end of processing (Controller)
7.4.6Temporary files (Controller)
7.4.7Retention (Controller)
7.4.8Disposal (Controller)
7.4.9PII transmission controls (Controller)
7.5.1Control of Production and Service Provision
7.5.2Cleanliness of Product
7.5.3Installation Activities
7.5.4Servicing Activities

PII Processor

18 controls
Controls in the PII Processor domain of ISO/IEC 27701:201918 controls
CodeTitle
8.2.1Service Portfolio
8.2.2Asset Management
8.2.3Configuration Management
8.2.4Internal Audit
8.2.5Monitoring and Measurement of Processes
8.2.6Monitoring and Measurement of Product
8.3.1Service Level Management
8.4.1Budgeting and Accounting
8.4.2Demand Management
8.4.3Capacity Management
8.5.1Change Management
8.5.2Service Design and Transition
8.5.3Release and Deployment Management
8.5.4Preservation
8.5.5Post-delivery activities
8.5.6Control of changes
8.5.7Engagement of a sub-contractor to process PII (Processor)
8.5.8Change of sub-contractor to process PII (Processor)

Your Compliance Coverage

If you comply with ISO/IEC 27701:2019, you already cover:

Maps to 38 other frameworks

77 total controls
EU Medical Devices Regulation (MDR 2017/745)
1 source controls mapped|2 target controls covered
1%
ISO 45001:2018
1 source controls mapped|4 target controls covered
1%
SWIFT CSCF
1 source controls mapped|4 target controls covered
1%
ISO 20000-1
1 source controls mapped|2 target controls covered
1%
1%
ISO 14001
1 source controls mapped|2 target controls covered
1%
ISO 13485
1 source controls mapped|4 target controls covered
1%
SWIFT CSCF v2024
1 source controls mapped|4 target controls covered
1%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|2 target controls covered
1%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|5 target controls covered
1%
BRCGS Global Standard for Food Safety Issue 9
1 source controls mapped|7 target controls covered
1%
ISO 9001:2015
1 source controls mapped|3 target controls covered
1%
ISO 14001:2015
1 source controls mapped|4 target controls covered
1%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|3 target controls covered
1%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|3 target controls covered
1%
US OFAC Sanctions Compliance Framework
1 source controls mapped|3 target controls covered
1%
ISO/IEC 27006:2024
1 source controls mapped|3 target controls covered
1%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
1 source controls mapped|3 target controls covered
1%
FSSC 22000 - Food Safety System Certification
1 source controls mapped|3 target controls covered
1%
GS1 Global Standards - Supply Chain Traceability and Data Security
1 source controls mapped|2 target controls covered
1%
21 CFR Part 58 - Good Laboratory Practice (GLP)
1 source controls mapped|1 target controls covered
1%
EU Digital Services Act
1 source controls mapped|1 target controls covered
1%
ISO 27005
1 source controls mapped|2 target controls covered
1%
ISO 13485:2016
1 source controls mapped|2 target controls covered
1%
Singapore Model AI Governance Framework (2nd Edition)
1 source controls mapped|1 target controls covered
1%
GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
1 source controls mapped|2 target controls covered
1%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|2 target controls covered
1%
DO-178C / ED-12C - Software Considerations in Airborne Systems
1 source controls mapped|3 target controls covered
1%
AS9100D - Aerospace Quality Management System
1 source controls mapped|2 target controls covered
1%
ISO/IEC 27003:2017
1 source controls mapped|2 target controls covered
1%
ISO/IEC 25012:2008 - Data Quality Model
1 source controls mapped|1 target controls covered
1%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
1 source controls mapped|3 target controls covered
1%
IEC 62304:2015 Medical Device Software Lifecycle Processes
1 source controls mapped|1 target controls covered
1%
ISO 19011
1 source controls mapped|1 target controls covered
1%
ISO 31000:2018
1 source controls mapped|1 target controls covered
1%
ICH E6(R3) - Good Clinical Practice
1 source controls mapped|1 target controls covered
1%
CDP (formerly Carbon Disclosure Project)
1 source controls mapped|1 target controls covered
1%

Frequently Asked Questions

What is ISO/IEC 27701:2019?

ISO/IEC 27701:2019 is a compliance framework from International with 3 domains and 77 controls. ISO/IEC 27701:2019 is a privacy extension to ISO/IEC 27001 and ISO/IEC 27002, providing requirements and guidance for establishing, maintaining, and continually improving a Privacy Information Management System (PIMS). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ISO/IEC 27701:2019 have?

ISO/IEC 27701:2019 has 77 controls organised across 3 domains. The largest domains are PII Controller (31 controls), Both (28 controls), PII Processor (18 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ISO/IEC 27701:2019 map to?

ISO/IEC 27701:2019 maps to 38 other compliance frameworks. The top mapping partners are EU Medical Devices Regulation (MDR 2017/745) (1% coverage), ISO 45001:2018 (1% coverage), SWIFT CSCF (1% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with ISO/IEC 27701:2019 compliance?

Start your ISO/IEC 27701:2019 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27701:2019 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 77 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required