ISO/IEC 27701:2025
Requires a privacy policy, privacy roles and the PII-processing documents of its Annex A: purposes and lawful basis, consent, the impact assessment, processor contracts, the record of processing, information for PII principals, requests, retention, disposal and transfers, beside the information security controls it restates for PII.
Tick ISO/IEC 27701:2025 on the register and these documents are expected and these clauses attach. Open the standard.
The documents it expects
14 documents expectedEach becomes a line on the gap list when the regime is ticked and no document on the paste resolves to it (or to the parent it may fold into).
Governance and the management system
- Document control procedure (procedure): ISO 27701 7.5.3. Owner: The information security lead (CISO or ISMS manager). Template: Document control policy.
- Information security roles and responsibilities (record; accepted folded into the information security policy): ISO 27701 5.3. Owner: The information security lead (CISO or ISMS manager). No template yet.
- Internal audit charter and programme (plan): ISO 27701 9.2.2. Owner: The head of internal audit, independent of the functions audited. Template: Internal audit policy.
- Management review procedure (procedure): ISO 27701 9.3.2. Owner: The information security lead (CISO or ISMS manager). Template: Management review policy.
- Nonconformity and corrective action procedure (procedure): ISO 27701 10.2. Owner: The information security lead (CISO or ISMS manager). Template: Corrective action policy.
- Risk management policy (policy): ISO 27701 6.1.2, ISO 27701 6.1.3. Owner: The information security lead (CISO or ISMS manager). Template: Risk management policy.
Assets, data and classification
- Records retention schedule (record): ISO 27701 A.1.4.8. Owner: Legal or the compliance officer. Template: Data retention policy.
Privacy
- Data processing agreement (record): ISO 27701 A.1.2.7. Owner: The data protection officer or privacy lead. No template yet.
- Data protection impact assessment procedure (procedure): ISO 27701 A.1.2.6. Owner: The data protection officer or privacy lead. Template: Data protection impact assessment procedure.
- Data protection policy (policy): ISO 27701 5.2. Owner: The data protection officer or privacy lead. Template: Data protection policy.
- Data subject rights procedure (procedure): ISO 27701 A.1.3.10, ISO 27701 A.1.3.7. Owner: The data protection officer or privacy lead. Template: Subject access request procedure.
- Personal data breach procedure (procedure): ISO 27701 A.3.12. Owner: The data protection officer or privacy lead. Template: Data breach notification procedure.
- Privacy notice (record): ISO 27701 A.1.3.3, ISO 27701 A.1.3.4. Owner: The data protection officer or privacy lead. Template: Privacy notice template.
- Record of processing activities (record): ISO 27701 A.1.2.9, ISO 27701 A.1.2.2. Owner: The data protection officer or privacy lead. Template: Records of processing activities template.
Every document it reaches
38 types carry at least one of its clausesThe clauses, quoted
44 of 108 in the frameworkRequirement text quoted from the standards themselves, read clause by clause against the copy we hold: our statement of each clause, not the instrument verbatim.
ISO 27701 10.2 Nonconformity and corrective actionWhen a nonconformity occurs the organization shall react to it and, as applicable, take action to control and correct it and deal with the consequences; evaluate the need for action to eliminate the causes of the nonconformity so that it does not recur or occur elsewhere, by reviewing the nonconformity, determining its causes and determining whether similar nonconformities exist or could potentially occur; implement any action needed; review the effectiveness of any corrective action taken; and make changes to the PIMS if necessary. Corrective actions shall be appropriate to the effects of the nonconformities encountered, and the organization shall retain documented information as evidence of the nature of the nonconformities and any subsequent actions taken, and of the results of any corrective action.
Common gap: Corrections applied without a cause analysis
Source: ISO/IEC 27701:2025
ISO 27701 5.2 Privacy policyTop management shall establish a privacy policy that is appropriate to the purpose of the organization, provides a framework for setting privacy objectives, includes a commitment to satisfy applicable requirements related to the processing of PII, and includes a commitment to continual improvement of the privacy information management system. The policy shall be available as documented information, be communicated within the organization, and be available to interested parties as appropriate. The transition documents record that a written privacy policy is now a mandatory standalone requirement rather than an augmentation of the information security policy.
Common gap: A privacy notice to individuals presented as the management system policy
Source: ISO/IEC 27701:2025
ISO 27701 5.3 Roles, responsibilities and authoritiesTop management shall ensure that the responsibilities and authorities for roles relevant to the privacy information management system are assigned and communicated within the organization. Top management shall assign the responsibility and authority for ensuring that the PIMS conforms to the requirements of this document, and for reporting on the performance of the PIMS to top management. Roles that jurisdictions can require, such as a data protection officer, and the point of contact for PII principals and for customers are addressed by the controls in Annex A (A.3.4).
Common gap: Responsibilities assigned but never communicated
Source: ISO/IEC 27701:2025
ISO 27701 6.1.2 Privacy risk assessmentThe organization shall define and apply a privacy risk assessment process that establishes and maintains privacy risk criteria, including risk acceptance criteria and criteria for performing assessments; ensures that repeated assessments produce consistent, valid and comparable results; identifies the privacy risks associated with the processing of PII within the scope of the PIMS, both risks to the organization and risks to PII principals, and identifies the risk owners; analyses the risks by assessing the potential consequences and the realistic likelihood of their occurrence and determining the levels of risk; and evaluates the risks by comparing the results against the criteria and prioritising them for treatment. Where the organization also runs an information security risk assessment, the relationship between information security and the protection of PII shall be managed throughout. The organization shall retain documented information about the process. The first edition's dual assessment, information security risk plus privacy risk inside an ISMS, becomes a privacy risk assessment in its own right; the transition documents note the guidance draws on ISO/IEC 27557.
Common gap: Risk register that holds security risks only, with no risk to individuals recorded
Source: ISO/IEC 27701:2025
ISO 27701 6.1.3 Privacy risk treatmentThe organization shall define and apply a privacy risk treatment process that selects appropriate treatment options taking account of the assessment results; determines all controls necessary to implement the options; compares the determined controls with those in Annex A to verify that no necessary controls have been omitted, Annex A being a reference list of possible controls that the organization can add to; identifies and documents the information security programme that protects PII, which the transition documents record as required to address a stated set of areas and which may but need not follow ISO/IEC 27002; produces a Statement of Applicability that contains the necessary controls, the justification for their inclusion, whether they are implemented and the justification for excluding any Annex A control; formulates a privacy risk treatment plan; and obtains the risk owners' approval of the plan and their acceptance of the residual privacy risks. Documented information about the process shall be retained. In the first edition the comparison ran against ISO/IEC 27001:2013 Annex A and the two PIMS annexes; in this edition it runs against Annex A of this document alone.
Common gap: Statement of Applicability copied from an ISO/IEC 27001 SoA with the 2019 annexes bolted on
Source: ISO/IEC 27701:2025
ISO 27701 7.3 AwarenessPersons doing work under the organization's control shall be aware of the privacy policy, of their contribution to the effectiveness of the privacy information management system including the benefits of improved privacy performance, and of the implications of not conforming with the PIMS requirements. The implications the first edition spelled out are carried into the guidance: consequences to the organization, to the person, and to the PII principal of breaching privacy rules, and awareness of how to report an incident involving PII.
Common gap: Awareness limited to annual e-learning that never mentions PII principals or the reporting route
Source: ISO/IEC 27701:2025
ISO 27701 7.5.3 Control of documented informationDocumented information required by the PIMS and by this document shall be controlled to ensure that it is available and suitable for use where and when needed and that it is adequately protected, for example from loss of confidentiality, improper use or loss of integrity. The organization shall address distribution, access, retrieval and use; storage and preservation including preservation of legibility; control of changes including version control; and retention and disposition. Documented information of external origin that the organization determines necessary for planning and operating the PIMS shall be identified as appropriate and controlled. Retention of previous versions of privacy policies and procedures, which the annex guidance calls for, is part of this control.
Common gap: Superseded privacy notices and procedures discarded, so the organization cannot show what applied at a given date
Source: ISO/IEC 27701:2025
ISO 27701 9.2.2 Internal audit programmeThe organization shall plan, establish, implement and maintain an audit programme or programmes including the frequency, methods, responsibilities, planning requirements and reporting, taking into consideration the importance of the processes concerned and the results of previous audits. The organization shall define the audit criteria and scope for each audit, select auditors and conduct audits that ensure objectivity and impartiality of the audit process, ensure the results are reported to relevant management, and retain documented information as evidence of the implementation of the programme and the audit results.
Common gap: Privacy lead auditing their own processes
Source: ISO/IEC 27701:2025
ISO 27701 9.3.2 Management review inputsThe management review shall include consideration of the status of actions from previous management reviews; changes in external and internal issues that are relevant to the PIMS; changes in the needs and expectations of interested parties relevant to the PIMS; information on the PIMS performance including trends in nonconformities and corrective actions, monitoring and measurement results, and audit results; and opportunities for continual improvement. The Robere correspondence table records that the first edition's ISMS-derived inputs on fulfilment of objectives, interested party feedback and results of risk assessment are not carried as separate items.
Common gap: Inputs that omit changes in privacy law or regulator expectations
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.2 Identify and document purposeThe organization must identify and document the specific purposes for which personal data will be processed, documented clearly and in enough detail to be usable in the information given to individuals, in obtaining consent, and in the records of policies and procedures, so that individuals understand why their data is processed.
Common gap: Purposes written as business objectives such as improving service, too vague to test any later processing against
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.3 Identify lawful basisThe organization must determine, document and comply with the lawful basis for each processing activity against its identified purposes, documenting the basis per activity, including any special categories of personal data in its classification scheme with awareness that the classification and its consequences vary by jurisdiction and regime, and revisiting the basis and any need for fresh consent whenever purposes change or extend.
Common gap: Consent recorded as the basis for processing that is in fact contractual, creating a withdrawal right the organization cannot honour
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.4 Determine when and how consent is to be obtainedThe organization must determine and document a process by which it can demonstrate whether, when and how consent to processing was obtained, clearly documenting when consent is needed and what obtaining it requires, correlating purposes with how consent is obtained, and taking into account jurisdiction specific requirements such as consent not being bundled with other agreements and additional requirements for particular collections or for particular individuals such as children.
Common gap: Consent bundled into terms of service acceptance, which several jurisdictions treat as no consent at all
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.5 Obtain and record consentThe organization must obtain and record consent according to its documented process, recording it so that on request it can produce the details of the consent given, including when it was given, the identity of the individual and the consent statement itself, having first provided the information required before consent, and the consent must be freely given, specific as to the purpose, and unambiguous and explicit.
Common gap: Consent recorded as a boolean flag with no record of what wording the person actually saw
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.6 Privacy impact assessmentThe organization must assess whether a privacy impact assessment is needed and carry one out where appropriate whenever new processing of personal data or a change to existing processing is planned, determining the elements the assessment needs, which can include the types of personal data processed, where it is stored and where it may be transferred, supported by data flow diagrams and data maps, and recognising that some jurisdictions mandate an assessment for cases such as automated decisions with legal effect, large scale processing of special categories, or systematic large scale monitoring of public areas.
Common gap: Assessment performed only for projects that reach a funding threshold, so small high risk changes escape
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.7 Contracts with PII processorsThe organization must have a written contract with every processor it uses and must ensure those contracts address implementation of the appropriate processor controls, requiring the processor to implement them in light of the risk assessment and the scope of processing it performs, with all such controls assumed relevant by default and any decision not to require one justified in the Statement of Applicability, responsibilities being allocable differently between the parties provided every control is considered and documented.
Common gap: Processors engaged under standard purchasing terms with no privacy schedule
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.8 Joint PII controllerWhere the organization is a joint controller, it must determine the respective roles and responsibilities for processing, including privacy and security requirements, transparently and in a contract or similar binding document covering matters such as the purpose of the sharing, the parties, the categories of data shared, the processing operations, the allocation of technical and organizational measures, responsibility in the event of a breach including who notifies and when, retention and disposal terms, liabilities, how obligations to individuals are met and how they can obtain information, and a contact point for individuals.
Common gap: Joint controllership misclassified as a processor relationship, so the wrong contract terms apply
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.9 Records related to processing PIIThe organization must determine and securely maintain the records that support its obligations for processing, typically an inventory of processing activities covering the type of processing, its purposes, the categories of personal data and of individuals including any special cases such as children, the categories of recipients including those in third countries or international organizations, a general description of the technical and organizational security measures, and the privacy impact assessment report, with a named owner responsible for the inventory's accuracy and completeness.
Common gap: Inventory owned by nobody, so it decays between audits
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.10 Handling requestsThe organization must define and document policies and procedures for handling and responding to legitimate requests from individuals, which can include requests for a copy of data or to lodge a complaint, handling them within appropriate defined response times, taking account of jurisdictions that set response times by complexity and volume and that require the individual be told of delay, with the appropriate response times stated in the privacy policy, and of jurisdictions that permit a fee in limited cases such as excessive or repetitive requests.
Common gap: Requests handled through general customer service with no privacy specific triage, so clocks start late
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.11 Automated decision makingThe organization must identify and address the obligations, including legal obligations, that it owes to individuals arising from decisions it makes about them based solely on automated processing of their personal data, taking account of jurisdictions that impose specific obligations where such decisions significantly affect the individual, such as notifying that automated decision making exists, allowing objection to it, or providing human intervention, and of jurisdictions where some processing may not be fully automated at all.
Common gap: Automated decisions unrecognised as such because a person nominally approves an output they never question, which is not meaningful human involvement
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.3 Determining information for PII principalsThe organization must determine and document what information is to be provided to individuals about the processing of their data and when it is to be provided, working out the legal, regulatory and business requirements for timing and content, which typically covers the purpose, the controller's contact details, the lawful basis, the source where data was not obtained from the individual, whether provision is statutory or contractual and the consequences of not providing it, the obligations owed and how to benefit from them including access, amendment, correction, erasure, obtaining a copy and objecting, how to withdraw consent, transfers, recipients or categories of recipients, the retention period, any automated decision making, the right to complain and how, and how often information is provided, updated whenever purposes change or extend.
Common gap: Notice content copied from a template, so elements that do not apply are present and elements that do are missing
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.4 Providing information to PII principalsThe organization must give individuals clear and easily accessible information identifying the controller and describing the processing of their data, delivered in a timely, concise, complete, transparent, intelligible and easily accessible form using clear and plain language suited to the audience, given at the time of collection where appropriate and permanently accessible thereafter.
Common gap: Notice legally complete and written at a reading level the audience cannot use, which fails the intelligibility requirement
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.7 Access, correction or erasureThe organization must implement policies, procedures or mechanisms enabling individuals to obtain access to, correct and erase their personal data without undue delay, must define and meet a response time, must disseminate corrections and erasures through its systems and to authorized users and pass them to third parties who received the data, must have a route for disputes about accuracy or correction that includes telling the individual what changes were made and why corrections could not be made where that is so, and must keep current with jurisdictional restrictions on when and how these requests may be made.
Common gap: Erasure performed in the primary system while backups, archives, logs and analytics copies retain the data
Source: ISO/IEC 27701:2025
ISO 27701 A.1.4.8 RetentionThe organization must not retain personal data longer than the purposes for which it is processed require, developing and maintaining retention schedules that take account of legal, regulatory and business requirements and, where those requirements conflict, taking and documenting a business decision based on a risk assessment and recording it in the appropriate schedule.
Common gap: Schedule published and never enforced, so the actual retention is indefinite
Source: ISO/IEC 27701:2025
ISO 27701 A.1.4.9 DisposalThe organization must hold documented policies, procedures or mechanisms for the disposal of personal data, choosing disposal techniques with regard to factors including the nature and extent of the data, any associated metadata, and the physical characteristics of the media it is stored on, since techniques differ in their properties and outcomes such as the granularity of the resulting media or whether deleted information can be recovered.
Common gap: One disposal method assumed adequate across all media, ignoring how outcomes differ
Source: ISO/IEC 27701:2025
ISO 27701 A.1.5.2 Identify basis for PII transfer between jurisdictionsThe organization must identify and document the basis on which personal data is transferred between jurisdictions, documenting compliance with the legislation and regulation that applies depending on the jurisdiction or international organization the data goes to and comes from, and being aware that some jurisdictions require transfer agreements to be reviewed by a designated supervisory authority.
Common gap: Transfers identified only where data physically moves, missing remote access from another jurisdiction, which is itself a transfer
Source: ISO/IEC 27701:2025
ISO 27701 A.1.5.4 Records of transfer of PIIThe organization must record transfers of personal data to and from third parties and ensure cooperation with those parties to support future requests arising from its obligations to individuals, which includes transfers from third parties of data modified as a result of controllers managing their obligations and transfers to third parties implementing legitimate individual requests such as erasure after consent withdrawal, holding a policy defining the retention period of these records and applying data minimisation so only the strictly needed information is retained.
Common gap: Only outbound transfers recorded, so data flowing back after a third party correction is untracked
Source: ISO/IEC 27701:2025
ISO 27701 A.3.10 Addressing information security within supplier agreementsAgreements with suppliers shall specify whether PII is processed and the minimum technical and organizational measures the supplier must meet for the organization to meet its information security and PII protection obligations, shall clearly allocate responsibilities between the organization, its partners, suppliers and applicable third parties taking account of the type of PII processed, shall provide a mechanism for ensuring the organization supports and manages compliance with applicable legislation and regulation, and shall call for independently audited compliance acceptable to the customer. When the organization is a PII processor, its contracts with suppliers shall specify that PII is processed only on its instructions.
Common gap: Supplier contracts silent on PII while the supplier processes it
Source: ISO/IEC 27701:2025
ISO 27701 A.3.11 Information security incident management planning and preparationAs part of its information security incident management process the organization shall establish responsibilities and procedures for identifying and recording breaches of PII, and responsibilities and procedures for notifying the required parties of PII breaches, including the timing of notification, and for disclosure to authorities, taking account of applicable legislation and regulation; where a jurisdiction imposes specific breach response and notification regulation, the organization shall be able to demonstrate compliance with it.
Common gap: Security incident process with no PII breach determination step
Source: ISO/IEC 27701:2025
ISO 27701 A.3.12 Response to information security incidentsFor a PII controller, an incident that involves PII shall trigger a review to determine whether a breach involving PII requiring a response has occurred, an event alone not necessarily triggering it; when a breach has occurred the response shall include the relevant notifications and records, jurisdictions defining when the supervisory authority and PII principals must be notified, and a record with sufficient information for regulatory or forensic reporting shall be kept covering the incident, the period, the consequences, the reporter, to whom it was reported, the resolution steps and data recovered, whether it caused unavailability, loss, disclosure or alteration of PII, the PII compromised, and the notifications made. For a PII processor, the contract with the customer shall cover breach notification, how the organization will provide the information the customer needs to notify authorities, the exclusion of breaches caused by the customer or PII principal or within components they are responsible for, and the expected and externally mandated limits on notification response times; some jurisdictions require the processor to notify the controller without undue delay and some require direct notification of a regulatory authority.
Common gap: Incidents closed as security events with no PII breach determination
Source: ISO/IEC 27701:2025
ISO 27701 A.3.18 Confidentiality or non-disclosure agreementsIndividuals operating under the organization's control with access to PII shall be subject to a confidentiality obligation, the agreement, whether part of a contract or separate, specifying the length of time the obligation lasts; when the organization is a PII processor, the confidentiality agreement in whatever form between the organization, its employees and its agents shall ensure they comply with the policy and procedures on data handling and protection.
Common gap: Confidentiality obligation that ends at termination when the PII obligation does not
Source: ISO/IEC 27701:2025
ISO 27701 A.3.19 Clear desk and clear screenThe organization shall restrict the creation of hardcopy material that includes PII to the minimum needed to fulfil the identified processing purpose, in addition to the clear desk and clear screen rules that protect information left unattended.
Common gap: PII printed routinely for convenience with no restriction
Source: ISO/IEC 27701:2025
ISO 27701 A.3.20 Storage mediaThe organization shall document any use of removable media or devices for the storage of PII and, wherever feasible, use media and devices that permit encryption, using unencrypted media only where unavoidable and then with procedures and compensating controls such as tamper-evident packaging to mitigate the risk, because media taken outside the organization is prone to loss, damage and inappropriate access; where media on which PII is stored is disposed of, secure disposal procedures shall be documented and implemented so that the previously stored PII is not accessible; and media carrying PII shall be handled under the transfer, logging and authorisation measures of A.3.7.
Common gap: Unencrypted USB media in routine use with no record
Source: ISO/IEC 27701:2025
ISO 27701 A.3.21 Secure disposal or re-use of equipmentWhenever storage space is re-assigned the organization shall ensure that any PII previously residing on it is not accessible, using specific technical measures where deletion of PII in an information system cannot practically be made explicit for performance reasons and another user could otherwise access it, and for disposal or re-use it shall treat equipment containing storage media that could possibly contain PII as though it does contain PII.
Common gap: Equipment resold or returned to lessors with storage intact
Source: ISO/IEC 27701:2025
ISO 27701 A.3.22 User endpoint devicesThe organization shall ensure that the use of mobile and other user endpoint devices does not lead to a compromise of PII, through the device rules, protections and handling requirements it applies to endpoints that access or store PII.
Common gap: Mobile rules that address device loss but not PII stored in applications and caches
Source: ISO/IEC 27701:2025
ISO 27701 A.3.23 Secure authenticationWhere required by the customer, the organization shall provide the capability for secure log-on procedures for any user accounts under the customer's control, in addition to applying secure authentication to its own accounts on systems that process PII.
Common gap: Customer accounts limited to password-only log-on with no stronger option
Source: ISO/IEC 27701:2025
ISO 27701 A.3.24 Information backupThe organization shall have a policy addressing the backup, recovery and restoration of PII and any further contractual or legal requirements for the erasure of PII held in backups; shall inform customers of the limits of the service regarding backup and, where it explicitly provides backup and restore services, give them clear information about its backup and restoration capabilities for PII; shall demonstrate compliance with any jurisdiction-specific requirements on backup frequency, testing and recovery procedures; shall ensure that restored PII is brought to a state where its integrity can be assured or where inaccuracy or incompleteness is identified and resolved, which can involve the PII principal; and shall keep a procedure for and a log of PII restoration efforts recording at least the person responsible and a description of the PII restored, meeting any jurisdiction-prescribed log content. Subcontracted storage of backup copies falls under the supplier controls.
Common gap: PII erased from live systems and retained indefinitely in backups
Source: ISO/IEC 27701:2025
ISO 27701 A.3.25 LoggingA process shall be in place to review event logs, by continuous automated monitoring and alerting or by manual review at a specified, documented periodicity, to identify irregularities and propose remediation; where possible event logs shall record access to PII including by whom, when, which PII principal's PII was accessed and what additions, modifications or deletions were made; where several service providers share roles in logging, the roles and any agreement on log access shall be defined and documented. Log information can itself contain PII, so access to it shall be controlled to ensure it is used only as intended, and a procedure, preferably automatic, shall delete or de-identify logged information as the retention schedule specifies. A PII processor shall define and make available to customers the criteria for if, when and how log information is made available to them, and where customers can access logs the processor controls it shall ensure each customer can access only records of its own activities and cannot amend the logs.
Common gap: Logs collected and never reviewed
Source: ISO/IEC 27701:2025
ISO 27701 A.3.26 Use of cryptographyThe organization's rules on the use of cryptography shall recognise that some jurisdictions require cryptography to protect particular kinds of PII, such as health data, resident registration numbers, passport numbers and driver's licence numbers, and the organization shall provide information to the customer about the circumstances in which it uses cryptography to protect the PII it processes and about any capabilities it provides that can help the customer apply their own cryptographic protection.
Common gap: Special categories stored in clear because the rule addressed only data in transit
Source: ISO/IEC 27701:2025
ISO 27701 A.3.27 Secure development life cyclePolicies for system development and design shall include guidance for the organization's processing of PII based on its obligations to PII principals, applicable legislation and regulation and the types of processing it performs, the Annex A controls providing the considerations; policies that contribute to privacy by design and privacy by default shall consider guidance on PII protection and the implementation of the ISO/IEC 29100 privacy principles in the development life cycle, privacy and PII protection requirements in the design phase drawn from privacy risk or impact assessment, PII protection checkpoints within project milestones, the privacy knowledge required, and minimising the processing of PII by default.
Common gap: Privacy addressed at release through a legal review only
Source: ISO/IEC 27701:2025
ISO 27701 A.3.5 Classification of informationThe organization's information classification scheme shall explicitly consider PII, including its type and any special categories, so that classification is the means by which the organization understands what PII it processes, where that PII is stored and the systems through which it can flow.
Common gap: PII treated as ordinary confidential information with no distinction for special categories
Source: ISO/IEC 27701:2025
ISO 27701 A.3.6 Labelling of informationThe organization shall ensure that people under its control are made aware of the definition of PII and of how to recognise information that is PII, so that labelling and handling rules are applied to PII wherever it occurs.
Common gap: Labelling limited to a confidentiality marking that says nothing about PII
Source: ISO/IEC 27701:2025
ISO 27701 A.3.7 Information transferThe organization's information transfer rules and procedures shall ensure that the rules related to the processing of PII are enforced throughout and, where applicable, outside the system, and where physical media is used to transfer PII a system shall record incoming and outgoing media including the type of media, the authorised sender and recipients, the date and time and the number of media, with additional measures such as encryption where possible so that the PII can be accessed only at the destination; physical media carrying PII shall be subject to an authorisation procedure before leaving the premises and kept inaccessible to anyone but authorised personnel.
Common gap: Transfer rules enforced inside the system but not on exports and extracts
Source: ISO/IEC 27701:2025
ISO 27701 A.3.8 Identity managementProcedures for the registration and de-registration of users who administer or operate systems and services that process PII shall address the situation where those users' access control is compromised, such as the corruption or compromise of passwords or other registration data. The organization shall not reissue deactivated or expired user identifiers on systems and services that process PII. Where the organization provides PII processing as a service, the customer can be responsible for some or all aspects of user identifier management and such cases shall be included in the documented information; some jurisdictions impose specific requirements on the frequency of checks for unused authentication credentials on systems that process PII.
Common gap: Identifiers reissued to new joiners so historical access records point at the wrong person
Source: ISO/IEC 27701:2025
ISO 27701 A.3.9 Access rightsThe organization shall maintain an accurate, up-to-date record of the user profiles created for users authorised to access information systems and the PII they contain, the profile comprising the data about the user, including the user identifier, needed to implement the technical controls that provide authorised access. Individual user identifiers shall be used so that appropriately configured systems can identify who accessed PII and what additions, deletions or changes they made, which protects users as well as the organization. Where the organization provides PII processing as a service and the customer is responsible for some or all access management, the organization shall where appropriate provide the customer the means to perform it, such as administrative rights to manage or terminate access, and document such cases.
Common gap: Shared or generic accounts on systems holding PII
Source: ISO/IEC 27701:2025
See what it expects of your list
Paste the policy list, tick the regime, and every document it reaches carries its clauses, with the ones it expects and the list does not carry named. Eight documents free, no account.
Build a register