Frameworks
ISO/IEC 27701 — Privacy Information Management
The privacy extension to ISO 27001 — one certified system for security and privacy.
Book a demoISO 27701 extends your ISO 27001 ISMS into a privacy information management system (PIMS), adding controller and processor obligations that map cleanly to GDPR. For companies fielding both security and privacy questionnaires, it turns two programs into one certifiable system.
Built on 27001, aligned to GDPR
You can't certify 27701 standalone — it rides on an ISO 27001 certification. Its controls split by role: what you owe as a data controller (purposes, consent, transparency) and as a processor (instructions, subprocessors, assistance duties). Its annexes map to GDPR articles, which is why European enterprise buyers treat it as strong evidence of privacy maturity.
How Compriska helps
Compriska manages the joint ISMS+PIMS: privacy controls cross-mapped with security controls, processing records maintained in the same system as the risk register, and one evidence base serving the 27001 auditor, the 27701 auditor, and the GDPR regulator.
Frequently asked questions
Do we need ISO 27001 first?
Yes — ISO 27701 is an extension, certified together with or on top of an existing ISO 27001 ISMS.
Other frameworks
Automate ISO 27701 with Compriska
See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.
Book a demo