Skip to content

PIMS

ISO 27701 Privacy Information Management (PIMS) Checklist

A controller/processor checklist to implement a Privacy Information Management System as an extension to ISO 27001.

Estimated time
3–6 Months
Audience
Teams Extending ISO 27001 with Privacy Controls
Last updated

Operational reference for PIMS implementation. Certification requires an accredited audit against ISO 27701 as an extension to ISO 27001.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: Scope & Roles

Phase 2: Controller Obligations

Phase 3: Processor Obligations

Phase 4: Audit Readiness

FAQ

Does ISO 27701 certify GDPR compliance?+

No. It certifies a PIMS. GDPR compliance remains a legal assessment.

Can we certify 27701 alone?+

It is designed as an extension to ISO 27001/27002.

Controller vs processor annexes?+

Annex A is for controllers; Annex B for processors. Many SaaS companies need both.

Does this replace a DPO?+

No. DPO appointment follows GDPR Article 37, independent of certification.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer