Data protection policy
The organisation's internal rules for personal data: the principles, the roles, the lawful bases it relies on and how it demonstrates them.
How the register reads it
| Also called | privacy policy (internal), PIMS policy |
|---|---|
| Family | Privacy |
| Document type | Policy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The data protection officer or privacy lead. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | GDPR or ISO 27701 or ISO 27001 is ticked and no line resolves to it. |
| Template | Data protection policy. |
Which standards require it, and what each expects it to contain
3 requiring clauses, 3 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27001:2022
ISO 27001 5.34 Privacy and protection of personal identifiable information (PII)Identify and meet privacy and PII-protection requirements from law, regulation and contract.
What the ISO 27002 guidance expects the document to say: Requires the requirements for preserving privacy and protecting personally identifiable information to be identified and met, in line with applicable laws, regulations and contractual requirements.
Common gap: Missing documented consent for all data subjects
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO/IEC 27701:2025
ISO 27701 5.2 Privacy policyTop management shall establish a privacy policy that is appropriate to the purpose of the organization, provides a framework for setting privacy objectives, includes a commitment to satisfy applicable requirements related to the processing of PII, and includes a commitment to continual improvement of the privacy information management system. The policy shall be available as documented information, be communicated within the organization, and be available to interested parties as appropriate. The transition documents record that a written privacy policy is now a mandatory standalone requirement rather than an augmentation of the information security policy.
Common gap: A privacy notice to individuals presented as the management system policy
Source: ISO/IEC 27701:2025
GDPR (Regulation (EU) 2016/679)
GDPR Art. 24 Responsibility of the controllerImplement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that processing is performed in accordance with the Regulation, taking into account the nature, scope, context and purposes of processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons. Review and update those measures where necessary. Where proportionate in relation to the processing activities, the measures must include implementing appropriate data protection policies. Adherence to an approved code of conduct or an approved certification mechanism may be used as one element by which to demonstrate compliance, not as a substitute for it.
Common gap: A policy suite adopted once and never reviewed, so it describes processing the organisation no longer carries out
Source: GDPR (Regulation (EU) 2016/679)
Also governs
ISO 27001 controls this document is expected to set the rules for, beside the ones that require it: ISO 27001 5.34.
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerData protection officer and privacy roles · Data sharing agreement