| iso-iec-27701-2025::A.1.2.2 | Identify and document purpose | The organization must identify and document the specific purposes for which personal data will be processed, documented... |
| iso-iec-27701-2025::A.1.2.3 | Identify lawful basis | The organization must determine, document and comply with the lawful basis for each processing activity against its iden... |
| iso-iec-27701-2025::A.1.2.4 | Determine when and how consent is to be obtained | The organization must determine and document a process by which it can demonstrate whether, when and how consent to proc... |
| iso-iec-27701-2025::A.1.2.5 | Obtain and record consent | The organization must obtain and record consent according to its documented process, recording it so that on request it... |
| iso-iec-27701-2025::A.1.2.6 | Privacy impact assessment | The organization must assess whether a privacy impact assessment is needed and carry one out where appropriate whenever... |
| iso-iec-27701-2025::A.1.2.7 | Contracts with PII processors | The organization must have a written contract with every processor it uses and must ensure those contracts address imple... |
| iso-iec-27701-2025::A.1.2.8 | Joint PII controller | Where the organization is a joint controller, it must determine the respective roles and responsibilities for processing... |
| iso-iec-27701-2025::A.1.2.9 | Records related to processing PII | The organization must determine and securely maintain the records that support its obligations for processing, typically... |
| iso-iec-27701-2025::A.1.3.10 | Handling requests | The organization must define and document policies and procedures for handling and responding to legitimate requests fro... |
| iso-iec-27701-2025::A.1.3.11 | Automated decision making | The organization must identify and address the obligations, including legal obligations, that it owes to individuals ari... |
| iso-iec-27701-2025::A.1.3.2 | Determining and fulfilling obligations to PII principals | The organization must determine and document its legal, regulatory and business obligations to the individuals whose dat... |
| iso-iec-27701-2025::A.1.3.3 | Determining information for PII principals | The organization must determine and document what information is to be provided to individuals about the processing of t... |
| iso-iec-27701-2025::A.1.3.4 | Providing information to PII principals | The organization must give individuals clear and easily accessible information identifying the controller and describing... |
| iso-iec-27701-2025::A.1.3.5 | Providing mechanism to modify or withdraw consent | The organization must provide a mechanism for individuals to modify or withdraw consent, inform them of their rights to... |
| iso-iec-27701-2025::A.1.3.6 | Providing mechanism to object to PII processing | The organization must provide a mechanism for individuals to object to the processing of their data, documenting the leg... |
| iso-iec-27701-2025::A.1.3.7 | Access, correction or erasure | The organization must implement policies, procedures or mechanisms enabling individuals to obtain access to, correct and... |
| iso-iec-27701-2025::A.1.3.8 | PII controllers' obligations to inform third parties | The organization must inform third parties with whom personal data has been shared of any modification, withdrawal or ob... |
| iso-iec-27701-2025::A.1.3.9 | Providing copy of PII processed | The organization must be able to provide a copy of the personal data it processes when the individual asks, in a structu... |
| iso-iec-27701-2025::A.1.4.10 | PII transmission controls | The organization must subject personal data transmitted over a data transmission network to controls designed to ensure... |
| iso-iec-27701-2025::A.1.4.2 | Limit collection | The organization must limit collection of personal data to the minimum that is adequate, relevant, proportional and nece... |
| iso-iec-27701-2025::A.1.4.3 | Limit processing | The organization must limit processing of personal data to what is adequate, relevant and necessary for the identified p... |
| iso-iec-27701-2025::A.1.4.4 | Accuracy and quality | The organization must ensure and document that personal data is as accurate, complete and up to date as the purposes for... |
| iso-iec-27701-2025::A.1.4.5 | PII minimization objectives | The organization must define and document data minimisation objectives and the mechanisms used to meet them, identifying... |
| iso-iec-27701-2025::A.1.4.6 | PII de-identification and deletion at the end of processing | The organization must delete personal data, or render it into a form that does not permit identification or re-identific... |
| iso-iec-27701-2025::A.1.4.7 | Temporary files | The organization must ensure that temporary files created as a result of processing personal data are erased or destroye... |
| iso-iec-27701-2025::A.1.4.8 | Retention | The organization must not retain personal data longer than the purposes for which it is processed require, developing an... |
| iso-iec-27701-2025::A.1.4.9 | Disposal | The organization must hold documented policies, procedures or mechanisms for the disposal of personal data, choosing dis... |
| iso-iec-27701-2025::A.1.5.2 | Identify basis for PII transfer between jurisdictions | The organization must identify and document the basis on which personal data is transferred between jurisdictions, docum... |
| iso-iec-27701-2025::A.1.5.3 | Countries and international organizations to which PII can be transferred | The organization must specify and document the countries and international organizations to which personal data can poss... |
| iso-iec-27701-2025::A.1.5.4 | Records of transfer of PII | The organization must record transfers of personal data to and from third parties and ensure cooperation with those part... |
| iso-iec-27701-2025::A.1.5.5 | Records of PII disclosures to third parties | The organization must record disclosures of personal data to third parties, including what data was disclosed, to whom a... |