Policy Register

Data protection policy

The organisation's internal rules for personal data: the principles, the roles, the lawful bases it relies on and how it demonstrates them.

How the register reads it

Also calledprivacy policy (internal), PIMS policy
FamilyPrivacy
Document typePolicy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe data protection officer or privacy lead.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenGDPR or ISO 27701 or ISO 27001 is ticked and no line resolves to it.
TemplateData protection policy.

Which standards require it, and what each expects it to contain

3 requiring clauses, 3 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 5.34 Privacy and protection of personal identifiable information (PII)

Identify and meet privacy and PII-protection requirements from law, regulation and contract.

What the ISO 27002 guidance expects the document to say: Requires the requirements for preserving privacy and protecting personally identifiable information to be identified and met, in line with applicable laws, regulations and contractual requirements.

Evidence an auditor accepts: Identification of the privacy and personally identifiable information requirements that apply, per jurisdiction and per contract; the record of processing activities, showing what personal data is held, why, on what basis and for how long; evidence of the protections applied, such as access restriction, minimisation, pseudonymisation and transfer safeguards
Common gap: Missing documented consent for all data subjects
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO/IEC 27701:2025

ISO 27701 5.2 Privacy policy

Top management shall establish a privacy policy that is appropriate to the purpose of the organization, provides a framework for setting privacy objectives, includes a commitment to satisfy applicable requirements related to the processing of PII, and includes a commitment to continual improvement of the privacy information management system. The policy shall be available as documented information, be communicated within the organization, and be available to interested parties as appropriate. The transition documents record that a written privacy policy is now a mandatory standalone requirement rather than an augmentation of the information security policy.

Evidence an auditor accepts: Approved privacy policy carrying each required element; communication records within the organization; evidence the policy is available to interested parties, for example published or provided to customers
Common gap: A privacy notice to individuals presented as the management system policy
Source: ISO/IEC 27701:2025

GDPR (Regulation (EU) 2016/679)

GDPR Art. 24 Responsibility of the controller

Implement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that processing is performed in accordance with the Regulation, taking into account the nature, scope, context and purposes of processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons. Review and update those measures where necessary. Where proportionate in relation to the processing activities, the measures must include implementing appropriate data protection policies. Adherence to an approved code of conduct or an approved certification mechanism may be used as one element by which to demonstrate compliance, not as a substitute for it.

Evidence an auditor accepts: The data protection policy set, each with an approval authority, an effective date and a review cycle; the risk assessment that drove the choice of measures, referencing nature, scope, context, purposes and risk to individuals; review records showing the measures were reassessed and updated after material changes to the processing
Common gap: A policy suite adopted once and never reviewed, so it describes processing the organisation no longer carries out
Source: GDPR (Regulation (EU) 2016/679)

Also governs

ISO 27001 controls this document is expected to set the rules for, beside the ones that require it: ISO 27001 5.34.

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Data protection officer and privacy roles · Data sharing agreement