PIMS
ISO 27701 Privacy Information Management (PIMS) Checklist
A controller/processor checklist to implement a Privacy Information Management System as an extension to ISO 27001.
- Estimated time
- 3–6 Months
- Audience
- Teams Extending ISO 27001 with Privacy Controls
- Last updated
Operational reference for PIMS implementation. Certification requires an accredited audit against ISO 27701 as an extension to ISO 27001.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Scope & Roles
Phase 2: Controller Obligations
Phase 3: Processor Obligations
Phase 4: Audit Readiness
FAQ
Does ISO 27701 certify GDPR compliance?+–
No. It certifies a PIMS. GDPR compliance remains a legal assessment.
Can we certify 27701 alone?+–
It is designed as an extension to ISO 27001/27002.
Controller vs processor annexes?+–
Annex A is for controllers; Annex B for processors. Many SaaS companies need both.
Does this replace a DPO?+–
No. DPO appointment follows GDPR Article 37, independent of certification.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer