Privacy & Data Protection

Automate ISO 27701 certification readiness

ISO/IEC 27701:2019 · Privacy Information Management System

Extension to ISO 27001 and ISO 27002 for privacy information management, providing guidance for PII controllers and processors to manage privacy risks.

26 controls24/7 continuous monitoring
ISO 27701 badgeISO 27701

What is ISO 27701?

Extension to ISO 27001 and ISO 27002 for privacy information management, providing guidance for PII controllers and processors to manage privacy risks.

Who it applies to

Organisations already running an ISO 27001 management system that need to evidence privacy management to customers or regulators. Often the practical answer when a customer asks for "GDPR certification", which does not exist.

How the standard is organised

An extension to ISO 27001 and 27002 that adds privacy-specific requirements and separates duties by role — PII controller and PII processor — rather than standing alone.

Framework names, marks and abbreviations (ISO, SOC 2, PCI DSS, TISAX, HIPAA, GDPR and others) are trademarks of their respective standards bodies and are used here only to describe what the Bitkosh Compliance Management Platform helps you track and prepare for. The badges shown are original Bitkosh artwork, not the official marks. Bitkosh Technologies is not affiliated with, sponsored by, or endorsed by ISO, AICPA, the PCI Security Standards Council, ENX/VDA, or any other framework owner, and using this platform does not by itself confer or guarantee certification — certification/attestation is granted only by the relevant accredited third-party body.

ISO 27701 on the Bitkosh platform

The 26 ISO 27701 controls sit in one workspace, evidence is collected from the systems you already run, and shared controls satisfy the equivalent requirement in the other 34 frameworks at the same time — so a second framework costs a fraction of the first.

How the platform works

Frequently Asked Questions

Who publishes ISO 27701, and who does it apply to?
ISO 27701 is published by ISO and IEC, jointly. Organisations already running an ISO 27001 management system that need to evidence privacy management to customers or regulators. Often the practical answer when a customer asks for "GDPR certification", which does not exist.
How is ISO 27701 conformance demonstrated?
Certified as an extension to an existing ISO 27001 certificate. There is no certificate to obtain. Conformance is shown through mapped controls and retained evidence, and tested by a regulator or a counterparty rather than an auditor you appoint.
How is ISO 27701 structured?
An extension to ISO 27001 and 27002 that adds privacy-specific requirements and separates duties by role — PII controller and PII processor — rather than standing alone. Bitkosh tracks 26 ISO 27701 controls against it, each with its own evidence requirements, owner and review cadence.
Let's build together

Ready to automate ISO 27701?

See how the Bitkosh Compliance Management Platform gets you audit-ready for ISO 27701 and 34 other frameworks from a single control library.