Policy Register

ISO/IEC 27701:2025

Requires a privacy policy, privacy roles and the PII-processing documents of its Annex A: purposes and lawful basis, consent, the impact assessment, processor contracts, the record of processing, information for PII principals, requests, retention, disposal and transfers, beside the information security controls it restates for PII.

Tick ISO/IEC 27701:2025 on the register and these documents are expected and these clauses attach. Open the standard.

The documents it expects

14 documents expected

Each becomes a line on the gap list when the regime is ticked and no document on the paste resolves to it (or to the parent it may fold into).

Governance and the management system

Assets, data and classification

Privacy

Every document it reaches

38 types carry at least one of its clauses

The clauses, quoted

44 of 108 in the framework

Requirement text quoted from the standards themselves, read clause by clause against the copy we hold: our statement of each clause, not the instrument verbatim.

ISO 27701 10.2 Nonconformity and corrective action

When a nonconformity occurs the organization shall react to it and, as applicable, take action to control and correct it and deal with the consequences; evaluate the need for action to eliminate the causes of the nonconformity so that it does not recur or occur elsewhere, by reviewing the nonconformity, determining its causes and determining whether similar nonconformities exist or could potentially occur; implement any action needed; review the effectiveness of any corrective action taken; and make changes to the PIMS if necessary. Corrective actions shall be appropriate to the effects of the nonconformities encountered, and the organization shall retain documented information as evidence of the nature of the nonconformities and any subsequent actions taken, and of the results of any corrective action.

Evidence an auditor accepts: Nonconformity and corrective action records with cause analysis; effectiveness reviews of corrective actions; changes to the PIMS resulting from corrective action
Common gap: Corrections applied without a cause analysis
Source: ISO/IEC 27701:2025
ISO 27701 5.2 Privacy policy

Top management shall establish a privacy policy that is appropriate to the purpose of the organization, provides a framework for setting privacy objectives, includes a commitment to satisfy applicable requirements related to the processing of PII, and includes a commitment to continual improvement of the privacy information management system. The policy shall be available as documented information, be communicated within the organization, and be available to interested parties as appropriate. The transition documents record that a written privacy policy is now a mandatory standalone requirement rather than an augmentation of the information security policy.

Evidence an auditor accepts: Approved privacy policy carrying each required element; communication records within the organization; evidence the policy is available to interested parties, for example published or provided to customers
Common gap: A privacy notice to individuals presented as the management system policy
Source: ISO/IEC 27701:2025
ISO 27701 5.3 Roles, responsibilities and authorities

Top management shall ensure that the responsibilities and authorities for roles relevant to the privacy information management system are assigned and communicated within the organization. Top management shall assign the responsibility and authority for ensuring that the PIMS conforms to the requirements of this document, and for reporting on the performance of the PIMS to top management. Roles that jurisdictions can require, such as a data protection officer, and the point of contact for PII principals and for customers are addressed by the controls in Annex A (A.3.4).

Evidence an auditor accepts: Role descriptions assigning PIMS responsibilities and authorities; appointment of the person or function responsible for conformity and for performance reporting; communication of responsibilities to those who hold them
Common gap: Responsibilities assigned but never communicated
Source: ISO/IEC 27701:2025
ISO 27701 6.1.2 Privacy risk assessment

The organization shall define and apply a privacy risk assessment process that establishes and maintains privacy risk criteria, including risk acceptance criteria and criteria for performing assessments; ensures that repeated assessments produce consistent, valid and comparable results; identifies the privacy risks associated with the processing of PII within the scope of the PIMS, both risks to the organization and risks to PII principals, and identifies the risk owners; analyses the risks by assessing the potential consequences and the realistic likelihood of their occurrence and determining the levels of risk; and evaluates the risks by comparing the results against the criteria and prioritising them for treatment. Where the organization also runs an information security risk assessment, the relationship between information security and the protection of PII shall be managed throughout. The organization shall retain documented information about the process. The first edition's dual assessment, information security risk plus privacy risk inside an ISMS, becomes a privacy risk assessment in its own right; the transition documents note the guidance draws on ISO/IEC 27557.

Evidence an auditor accepts: Privacy risk assessment methodology with criteria, acceptance levels and assessment triggers; risk register identifying risks to PII principals separately from risks to the organization, with owners; analysis showing consequence, likelihood and level per risk
Common gap: Risk register that holds security risks only, with no risk to individuals recorded
Source: ISO/IEC 27701:2025
ISO 27701 6.1.3 Privacy risk treatment

The organization shall define and apply a privacy risk treatment process that selects appropriate treatment options taking account of the assessment results; determines all controls necessary to implement the options; compares the determined controls with those in Annex A to verify that no necessary controls have been omitted, Annex A being a reference list of possible controls that the organization can add to; identifies and documents the information security programme that protects PII, which the transition documents record as required to address a stated set of areas and which may but need not follow ISO/IEC 27002; produces a Statement of Applicability that contains the necessary controls, the justification for their inclusion, whether they are implemented and the justification for excluding any Annex A control; formulates a privacy risk treatment plan; and obtains the risk owners' approval of the plan and their acceptance of the residual privacy risks. Documented information about the process shall be retained. In the first edition the comparison ran against ISO/IEC 27001:2013 Annex A and the two PIMS annexes; in this edition it runs against Annex A of this document alone.

Evidence an auditor accepts: Risk treatment plan with options, controls, owners and dates; statement of Applicability listing every Annex A control with inclusion or exclusion justification and implementation status; documented information security programme covering the areas the standard names
Common gap: Statement of Applicability copied from an ISO/IEC 27001 SoA with the 2019 annexes bolted on
Source: ISO/IEC 27701:2025
ISO 27701 7.3 Awareness

Persons doing work under the organization's control shall be aware of the privacy policy, of their contribution to the effectiveness of the privacy information management system including the benefits of improved privacy performance, and of the implications of not conforming with the PIMS requirements. The implications the first edition spelled out are carried into the guidance: consequences to the organization, to the person, and to the PII principal of breaching privacy rules, and awareness of how to report an incident involving PII.

Evidence an auditor accepts: Awareness communications and their reach across everyone who handles PII; evidence personnel know the consequences of non-conformity and how to report a PII incident; awareness checks such as survey or test results
Common gap: Awareness limited to annual e-learning that never mentions PII principals or the reporting route
Source: ISO/IEC 27701:2025
ISO 27701 7.5.3 Control of documented information

Documented information required by the PIMS and by this document shall be controlled to ensure that it is available and suitable for use where and when needed and that it is adequately protected, for example from loss of confidentiality, improper use or loss of integrity. The organization shall address distribution, access, retrieval and use; storage and preservation including preservation of legibility; control of changes including version control; and retention and disposition. Documented information of external origin that the organization determines necessary for planning and operating the PIMS shall be identified as appropriate and controlled. Retention of previous versions of privacy policies and procedures, which the annex guidance calls for, is part of this control.

Evidence an auditor accepts: Access, distribution and change controls on PIMS documentation; retention schedule for PIMS records and superseded document versions; control of external documents such as customer contracts and regulator guidance
Common gap: Superseded privacy notices and procedures discarded, so the organization cannot show what applied at a given date
Source: ISO/IEC 27701:2025
ISO 27701 9.2.2 Internal audit programme

The organization shall plan, establish, implement and maintain an audit programme or programmes including the frequency, methods, responsibilities, planning requirements and reporting, taking into consideration the importance of the processes concerned and the results of previous audits. The organization shall define the audit criteria and scope for each audit, select auditors and conduct audits that ensure objectivity and impartiality of the audit process, ensure the results are reported to relevant management, and retain documented information as evidence of the implementation of the programme and the audit results.

Evidence an auditor accepts: Audit programme with frequency, methods, responsibilities and reporting; audit criteria and scope per audit; auditor independence from the areas audited
Common gap: Privacy lead auditing their own processes
Source: ISO/IEC 27701:2025
ISO 27701 9.3.2 Management review inputs

The management review shall include consideration of the status of actions from previous management reviews; changes in external and internal issues that are relevant to the PIMS; changes in the needs and expectations of interested parties relevant to the PIMS; information on the PIMS performance including trends in nonconformities and corrective actions, monitoring and measurement results, and audit results; and opportunities for continual improvement. The Robere correspondence table records that the first edition's ISMS-derived inputs on fulfilment of objectives, interested party feedback and results of risk assessment are not carried as separate items.

Evidence an auditor accepts: Review input pack covering each required item; trend information on nonconformities, measurement and audit results; consideration of changes in context and interested party expectations
Common gap: Inputs that omit changes in privacy law or regulator expectations
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.2 Identify and document purpose

The organization must identify and document the specific purposes for which personal data will be processed, documented clearly and in enough detail to be usable in the information given to individuals, in obtaining consent, and in the records of policies and procedures, so that individuals understand why their data is processed.

Evidence an auditor accepts: Purpose register at the level of the processing activity, not the system; evidence the documented purpose text is the text actually used in notices and consent; review record showing purposes are updated when processing changes
Common gap: Purposes written as business objectives such as improving service, too vague to test any later processing against
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.3 Identify lawful basis

The organization must determine, document and comply with the lawful basis for each processing activity against its identified purposes, documenting the basis per activity, including any special categories of personal data in its classification scheme with awareness that the classification and its consequences vary by jurisdiction and regime, and revisiting the basis and any need for fresh consent whenever purposes change or extend.

Evidence an auditor accepts: Lawful basis recorded against each processing activity, with the reasoning; where legitimate interests is relied on, the balancing against obligations to individuals; classification scheme entries covering special categories, mapped to the jurisdictions that define them
Common gap: Consent recorded as the basis for processing that is in fact contractual, creating a withdrawal right the organization cannot honour
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.4 Determine when and how consent is to be obtained

The organization must determine and document a process by which it can demonstrate whether, when and how consent to processing was obtained, clearly documenting when consent is needed and what obtaining it requires, correlating purposes with how consent is obtained, and taking into account jurisdiction specific requirements such as consent not being bundled with other agreements and additional requirements for particular collections or for particular individuals such as children.

Evidence an auditor accepts: Documented consent process covering when consent is required and what valid consent demands; mapping from each purpose to whether and how consent is obtained; analysis of jurisdiction specific consent requirements and how the mechanism meets them
Common gap: Consent bundled into terms of service acceptance, which several jurisdictions treat as no consent at all
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.5 Obtain and record consent

The organization must obtain and record consent according to its documented process, recording it so that on request it can produce the details of the consent given, including when it was given, the identity of the individual and the consent statement itself, having first provided the information required before consent, and the consent must be freely given, specific as to the purpose, and unambiguous and explicit.

Evidence an auditor accepts: Consent records holding timestamp, individual identity and the exact statement consented to; the version of the information presented before consent, retained alongside; evidence consent was freely given, meaning a real alternative existed
Common gap: Consent recorded as a boolean flag with no record of what wording the person actually saw
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.6 Privacy impact assessment

The organization must assess whether a privacy impact assessment is needed and carry one out where appropriate whenever new processing of personal data or a change to existing processing is planned, determining the elements the assessment needs, which can include the types of personal data processed, where it is stored and where it may be transferred, supported by data flow diagrams and data maps, and recognising that some jurisdictions mandate an assessment for cases such as automated decisions with legal effect, large scale processing of special categories, or systematic large scale monitoring of public areas.

Evidence an auditor accepts: Documented trigger criteria for when an assessment is required, including the mandated cases; screening records showing the need was assessed even where no assessment followed; completed assessments with data types, storage locations, transfers and data flows
Common gap: Assessment performed only for projects that reach a funding threshold, so small high risk changes escape
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.7 Contracts with PII processors

The organization must have a written contract with every processor it uses and must ensure those contracts address implementation of the appropriate processor controls, requiring the processor to implement them in light of the risk assessment and the scope of processing it performs, with all such controls assumed relevant by default and any decision not to require one justified in the Statement of Applicability, responsibilities being allocable differently between the parties provided every control is considered and documented.

Evidence an auditor accepts: Written contract with every processor, with a register reconciling contracts to processors actually used; contract terms addressing the processor control set; justification for any processor control not required, recorded in the Statement of Applicability
Common gap: Processors engaged under standard purchasing terms with no privacy schedule
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.8 Joint PII controller

Where the organization is a joint controller, it must determine the respective roles and responsibilities for processing, including privacy and security requirements, transparently and in a contract or similar binding document covering matters such as the purpose of the sharing, the parties, the categories of data shared, the processing operations, the allocation of technical and organizational measures, responsibility in the event of a breach including who notifies and when, retention and disposal terms, liabilities, how obligations to individuals are met and how they can obtain information, and a contact point for individuals.

Evidence an auditor accepts: Binding joint controller agreement covering each of the matters the standard lists; identification of every joint controller relationship, distinguished from processor relationships; named contact point for individuals and evidence it is reachable
Common gap: Joint controllership misclassified as a processor relationship, so the wrong contract terms apply
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.9 Records related to processing PII

The organization must determine and securely maintain the records that support its obligations for processing, typically an inventory of processing activities covering the type of processing, its purposes, the categories of personal data and of individuals including any special cases such as children, the categories of recipients including those in third countries or international organizations, a general description of the technical and organizational security measures, and the privacy impact assessment report, with a named owner responsible for the inventory's accuracy and completeness.

Evidence an auditor accepts: Processing inventory carrying each required element; named owner accountable for its accuracy and completeness; evidence the inventory is maintained through change, not rebuilt for audits
Common gap: Inventory owned by nobody, so it decays between audits
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.10 Handling requests

The organization must define and document policies and procedures for handling and responding to legitimate requests from individuals, which can include requests for a copy of data or to lodge a complaint, handling them within appropriate defined response times, taking account of jurisdictions that set response times by complexity and volume and that require the individual be told of delay, with the appropriate response times stated in the privacy policy, and of jurisdictions that permit a fee in limited cases such as excessive or repetitive requests.

Evidence an auditor accepts: Documented request handling procedure covering identification, triage, response and escalation; response times published in the privacy policy and measured in operation; delay notification procedure and evidence of use
Common gap: Requests handled through general customer service with no privacy specific triage, so clocks start late
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.11 Automated decision making

The organization must identify and address the obligations, including legal obligations, that it owes to individuals arising from decisions it makes about them based solely on automated processing of their personal data, taking account of jurisdictions that impose specific obligations where such decisions significantly affect the individual, such as notifying that automated decision making exists, allowing objection to it, or providing human intervention, and of jurisdictions where some processing may not be fully automated at all.

Evidence an auditor accepts: Inventory of decisions made solely by automated processing, with their effect on individuals assessed; obligations register per jurisdiction for those decisions; notification content disclosing the existence and logic of automated decision making
Common gap: Automated decisions unrecognised as such because a person nominally approves an output they never question, which is not meaningful human involvement
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.3 Determining information for PII principals

The organization must determine and document what information is to be provided to individuals about the processing of their data and when it is to be provided, working out the legal, regulatory and business requirements for timing and content, which typically covers the purpose, the controller's contact details, the lawful basis, the source where data was not obtained from the individual, whether provision is statutory or contractual and the consequences of not providing it, the obligations owed and how to benefit from them including access, amendment, correction, erasure, obtaining a copy and objecting, how to withdraw consent, transfers, recipients or categories of recipients, the retention period, any automated decision making, the right to complain and how, and how often information is provided, updated whenever purposes change or extend.

Evidence an auditor accepts: Documented determination of notice content and timing per processing activity; traceability from each required content element to where it appears in the notice; trigger and evidence for updating notices when purposes change
Common gap: Notice content copied from a template, so elements that do not apply are present and elements that do are missing
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.4 Providing information to PII principals

The organization must give individuals clear and easily accessible information identifying the controller and describing the processing of their data, delivered in a timely, concise, complete, transparent, intelligible and easily accessible form using clear and plain language suited to the audience, given at the time of collection where appropriate and permanently accessible thereafter.

Evidence an auditor accepts: The notice as actually presented, in each channel and language used; evidence of delivery at the point of collection; evidence of permanent accessibility after collection
Common gap: Notice legally complete and written at a reading level the audience cannot use, which fails the intelligibility requirement
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.7 Access, correction or erasure

The organization must implement policies, procedures or mechanisms enabling individuals to obtain access to, correct and erase their personal data without undue delay, must define and meet a response time, must disseminate corrections and erasures through its systems and to authorized users and pass them to third parties who received the data, must have a route for disputes about accuracy or correction that includes telling the individual what changes were made and why corrections could not be made where that is so, and must keep current with jurisdictional restrictions on when and how these requests may be made.

Evidence an auditor accepts: Documented procedures for access, correction and erasure with defined response times; request log with dates received and completed, and performance against the response time; evidence corrections and erasures propagated to all systems and to third parties
Common gap: Erasure performed in the primary system while backups, archives, logs and analytics copies retain the data
Source: ISO/IEC 27701:2025
ISO 27701 A.1.4.8 Retention

The organization must not retain personal data longer than the purposes for which it is processed require, developing and maintaining retention schedules that take account of legal, regulatory and business requirements and, where those requirements conflict, taking and documenting a business decision based on a risk assessment and recording it in the appropriate schedule.

Evidence an auditor accepts: Retention schedule covering every category of personal data, with the period and its justification; evidence the schedule is enforced, not merely published; documented risk based decisions where legal, regulatory and business requirements conflicted
Common gap: Schedule published and never enforced, so the actual retention is indefinite
Source: ISO/IEC 27701:2025
ISO 27701 A.1.4.9 Disposal

The organization must hold documented policies, procedures or mechanisms for the disposal of personal data, choosing disposal techniques with regard to factors including the nature and extent of the data, any associated metadata, and the physical characteristics of the media it is stored on, since techniques differ in their properties and outcomes such as the granularity of the resulting media or whether deleted information can be recovered.

Evidence an auditor accepts: Disposal policy naming the technique used per media type and data category; disposal records identifying what was disposed of, when, by whom and by what method; consideration of associated metadata in the disposal decision
Common gap: One disposal method assumed adequate across all media, ignoring how outcomes differ
Source: ISO/IEC 27701:2025
ISO 27701 A.1.5.2 Identify basis for PII transfer between jurisdictions

The organization must identify and document the basis on which personal data is transferred between jurisdictions, documenting compliance with the legislation and regulation that applies depending on the jurisdiction or international organization the data goes to and comes from, and being aware that some jurisdictions require transfer agreements to be reviewed by a designated supervisory authority.

Evidence an auditor accepts: Transfer register naming origin, destination and the documented basis for each transfer; the transfer instruments themselves, such as contractual clauses or binding rules; assessment of destination jurisdiction requirements
Common gap: Transfers identified only where data physically moves, missing remote access from another jurisdiction, which is itself a transfer
Source: ISO/IEC 27701:2025
ISO 27701 A.1.5.4 Records of transfer of PII

The organization must record transfers of personal data to and from third parties and ensure cooperation with those parties to support future requests arising from its obligations to individuals, which includes transfers from third parties of data modified as a result of controllers managing their obligations and transfers to third parties implementing legitimate individual requests such as erasure after consent withdrawal, holding a policy defining the retention period of these records and applying data minimisation so only the strictly needed information is retained.

Evidence an auditor accepts: Transfer log covering transfers both to and from third parties; documented cooperation arrangements supporting later individual requests; retention policy for the transfer records themselves
Common gap: Only outbound transfers recorded, so data flowing back after a third party correction is untracked
Source: ISO/IEC 27701:2025
ISO 27701 A.3.10 Addressing information security within supplier agreements

Agreements with suppliers shall specify whether PII is processed and the minimum technical and organizational measures the supplier must meet for the organization to meet its information security and PII protection obligations, shall clearly allocate responsibilities between the organization, its partners, suppliers and applicable third parties taking account of the type of PII processed, shall provide a mechanism for ensuring the organization supports and manages compliance with applicable legislation and regulation, and shall call for independently audited compliance acceptable to the customer. When the organization is a PII processor, its contracts with suppliers shall specify that PII is processed only on its instructions.

Evidence an auditor accepts: Supplier agreements stating whether PII is processed and the minimum measures required; responsibility allocation clauses by type of PII; audit or assurance clause and the independent evidence obtained under it
Common gap: Supplier contracts silent on PII while the supplier processes it
Source: ISO/IEC 27701:2025
ISO 27701 A.3.11 Information security incident management planning and preparation

As part of its information security incident management process the organization shall establish responsibilities and procedures for identifying and recording breaches of PII, and responsibilities and procedures for notifying the required parties of PII breaches, including the timing of notification, and for disclosure to authorities, taking account of applicable legislation and regulation; where a jurisdiction imposes specific breach response and notification regulation, the organization shall be able to demonstrate compliance with it.

Evidence an auditor accepts: Incident procedure with a defined PII breach identification and recording step; notification procedure naming parties, timing and the authority disclosure route per jurisdiction; responsibilities assigned for breach handling
Common gap: Security incident process with no PII breach determination step
Source: ISO/IEC 27701:2025
ISO 27701 A.3.12 Response to information security incidents

For a PII controller, an incident that involves PII shall trigger a review to determine whether a breach involving PII requiring a response has occurred, an event alone not necessarily triggering it; when a breach has occurred the response shall include the relevant notifications and records, jurisdictions defining when the supervisory authority and PII principals must be notified, and a record with sufficient information for regulatory or forensic reporting shall be kept covering the incident, the period, the consequences, the reporter, to whom it was reported, the resolution steps and data recovered, whether it caused unavailability, loss, disclosure or alteration of PII, the PII compromised, and the notifications made. For a PII processor, the contract with the customer shall cover breach notification, how the organization will provide the information the customer needs to notify authorities, the exclusion of breaches caused by the customer or PII principal or within components they are responsible for, and the expected and externally mandated limits on notification response times; some jurisdictions require the processor to notify the controller without undue delay and some require direct notification of a regulatory authority.

Evidence an auditor accepts: Breach determination records for incidents involving PII; breach register carrying every field the standard names; notifications made to authorities, PII principals or customers with timing against the legal limit
Common gap: Incidents closed as security events with no PII breach determination
Source: ISO/IEC 27701:2025
ISO 27701 A.3.18 Confidentiality or non-disclosure agreements

Individuals operating under the organization's control with access to PII shall be subject to a confidentiality obligation, the agreement, whether part of a contract or separate, specifying the length of time the obligation lasts; when the organization is a PII processor, the confidentiality agreement in whatever form between the organization, its employees and its agents shall ensure they comply with the policy and procedures on data handling and protection.

Evidence an auditor accepts: Confidentiality clauses or agreements covering everyone with access to PII, with duration stated; evidence agents and contractors are bound as well as employees; processor agreements binding staff to the data handling policy
Common gap: Confidentiality obligation that ends at termination when the PII obligation does not
Source: ISO/IEC 27701:2025
ISO 27701 A.3.19 Clear desk and clear screen

The organization shall restrict the creation of hardcopy material that includes PII to the minimum needed to fulfil the identified processing purpose, in addition to the clear desk and clear screen rules that protect information left unattended.

Evidence an auditor accepts: Rules limiting the printing and copying of PII; print controls or monitoring on systems holding PII; clear desk and clear screen rules and spot check results
Common gap: PII printed routinely for convenience with no restriction
Source: ISO/IEC 27701:2025
ISO 27701 A.3.20 Storage media

The organization shall document any use of removable media or devices for the storage of PII and, wherever feasible, use media and devices that permit encryption, using unencrypted media only where unavoidable and then with procedures and compensating controls such as tamper-evident packaging to mitigate the risk, because media taken outside the organization is prone to loss, damage and inappropriate access; where media on which PII is stored is disposed of, secure disposal procedures shall be documented and implemented so that the previously stored PII is not accessible; and media carrying PII shall be handled under the transfer, logging and authorisation measures of A.3.7.

Evidence an auditor accepts: Register of removable media and devices used for PII; encryption applied to media holding PII, with documented exceptions and their compensating controls; secure disposal procedure and disposal records for media that held PII
Common gap: Unencrypted USB media in routine use with no record
Source: ISO/IEC 27701:2025
ISO 27701 A.3.21 Secure disposal or re-use of equipment

Whenever storage space is re-assigned the organization shall ensure that any PII previously residing on it is not accessible, using specific technical measures where deletion of PII in an information system cannot practically be made explicit for performance reasons and another user could otherwise access it, and for disposal or re-use it shall treat equipment containing storage media that could possibly contain PII as though it does contain PII.

Evidence an auditor accepts: Sanitisation procedure for equipment and storage before re-use or disposal; records of sanitisation or destruction per device; technical measures applied where explicit erasure is impractical, for example encryption with key destruction
Common gap: Equipment resold or returned to lessors with storage intact
Source: ISO/IEC 27701:2025
ISO 27701 A.3.22 User endpoint devices

The organization shall ensure that the use of mobile and other user endpoint devices does not lead to a compromise of PII, through the device rules, protections and handling requirements it applies to endpoints that access or store PII.

Evidence an auditor accepts: Endpoint and mobile device rules addressing PII specifically; technical protections on devices that access PII, such as encryption, remote wipe and access control; evidence the rules reach personal devices where these are permitted
Common gap: Mobile rules that address device loss but not PII stored in applications and caches
Source: ISO/IEC 27701:2025
ISO 27701 A.3.23 Secure authentication

Where required by the customer, the organization shall provide the capability for secure log-on procedures for any user accounts under the customer's control, in addition to applying secure authentication to its own accounts on systems that process PII.

Evidence an auditor accepts: Secure authentication capabilities offered for customer-controlled accounts and evidence customers can enable them; authentication configuration on the organization's own accounts on PII systems; contract or service description recording the capability
Common gap: Customer accounts limited to password-only log-on with no stronger option
Source: ISO/IEC 27701:2025
ISO 27701 A.3.24 Information backup

The organization shall have a policy addressing the backup, recovery and restoration of PII and any further contractual or legal requirements for the erasure of PII held in backups; shall inform customers of the limits of the service regarding backup and, where it explicitly provides backup and restore services, give them clear information about its backup and restoration capabilities for PII; shall demonstrate compliance with any jurisdiction-specific requirements on backup frequency, testing and recovery procedures; shall ensure that restored PII is brought to a state where its integrity can be assured or where inaccuracy or incompleteness is identified and resolved, which can involve the PII principal; and shall keep a procedure for and a log of PII restoration efforts recording at least the person responsible and a description of the PII restored, meeting any jurisdiction-prescribed log content. Subcontracted storage of backup copies falls under the supplier controls.

Evidence an auditor accepts: Backup and restoration policy covering PII and the erasure of PII in backups; customer information on backup limits and capabilities; restoration procedure and restoration log with responsible person and PII restored
Common gap: PII erased from live systems and retained indefinitely in backups
Source: ISO/IEC 27701:2025
ISO 27701 A.3.25 Logging

A process shall be in place to review event logs, by continuous automated monitoring and alerting or by manual review at a specified, documented periodicity, to identify irregularities and propose remediation; where possible event logs shall record access to PII including by whom, when, which PII principal's PII was accessed and what additions, modifications or deletions were made; where several service providers share roles in logging, the roles and any agreement on log access shall be defined and documented. Log information can itself contain PII, so access to it shall be controlled to ensure it is used only as intended, and a procedure, preferably automatic, shall delete or de-identify logged information as the retention schedule specifies. A PII processor shall define and make available to customers the criteria for if, when and how log information is made available to them, and where customers can access logs the processor controls it shall ensure each customer can access only records of its own activities and cannot amend the logs.

Evidence an auditor accepts: Log review process with periodicity or automated alerting, and records of reviews; pII access logging capturing actor, time, data subject and change; access control and retention or de-identification procedure for logs
Common gap: Logs collected and never reviewed
Source: ISO/IEC 27701:2025
ISO 27701 A.3.26 Use of cryptography

The organization's rules on the use of cryptography shall recognise that some jurisdictions require cryptography to protect particular kinds of PII, such as health data, resident registration numbers, passport numbers and driver's licence numbers, and the organization shall provide information to the customer about the circumstances in which it uses cryptography to protect the PII it processes and about any capabilities it provides that can help the customer apply their own cryptographic protection.

Evidence an auditor accepts: Cryptography rules identifying the PII types that jurisdictions require to be encrypted; customer-facing information on where cryptography is applied to PII and the capabilities offered; evidence of encryption of the identified PII types at rest and in transit
Common gap: Special categories stored in clear because the rule addressed only data in transit
Source: ISO/IEC 27701:2025
ISO 27701 A.3.27 Secure development life cycle

Policies for system development and design shall include guidance for the organization's processing of PII based on its obligations to PII principals, applicable legislation and regulation and the types of processing it performs, the Annex A controls providing the considerations; policies that contribute to privacy by design and privacy by default shall consider guidance on PII protection and the implementation of the ISO/IEC 29100 privacy principles in the development life cycle, privacy and PII protection requirements in the design phase drawn from privacy risk or impact assessment, PII protection checkpoints within project milestones, the privacy knowledge required, and minimising the processing of PII by default.

Evidence an auditor accepts: Development policy carrying the privacy by design and by default elements; privacy requirements captured at design from risk or impact assessment; privacy checkpoints in project milestones and evidence they are applied
Common gap: Privacy addressed at release through a legal review only
Source: ISO/IEC 27701:2025
ISO 27701 A.3.5 Classification of information

The organization's information classification scheme shall explicitly consider PII, including its type and any special categories, so that classification is the means by which the organization understands what PII it processes, where that PII is stored and the systems through which it can flow.

Evidence an auditor accepts: Classification scheme with PII and special categories as explicit classes; data inventory or map derived from the classification showing where PII resides and flows; evidence systems processing PII are classified accordingly
Common gap: PII treated as ordinary confidential information with no distinction for special categories
Source: ISO/IEC 27701:2025
ISO 27701 A.3.6 Labelling of information

The organization shall ensure that people under its control are made aware of the definition of PII and of how to recognise information that is PII, so that labelling and handling rules are applied to PII wherever it occurs.

Evidence an auditor accepts: Definition of PII communicated to personnel with examples; labelling conventions for PII in systems and documents; evidence personnel can recognise PII in practice, for example through spot checks
Common gap: Labelling limited to a confidentiality marking that says nothing about PII
Source: ISO/IEC 27701:2025
ISO 27701 A.3.7 Information transfer

The organization's information transfer rules and procedures shall ensure that the rules related to the processing of PII are enforced throughout and, where applicable, outside the system, and where physical media is used to transfer PII a system shall record incoming and outgoing media including the type of media, the authorised sender and recipients, the date and time and the number of media, with additional measures such as encryption where possible so that the PII can be accessed only at the destination; physical media carrying PII shall be subject to an authorisation procedure before leaving the premises and kept inaccessible to anyone but authorised personnel.

Evidence an auditor accepts: Transfer procedures applying the PII processing rules to every transfer channel; log of physical media containing PII sent and received with the fields the standard names; authorisation records for media leaving the premises
Common gap: Transfer rules enforced inside the system but not on exports and extracts
Source: ISO/IEC 27701:2025
ISO 27701 A.3.8 Identity management

Procedures for the registration and de-registration of users who administer or operate systems and services that process PII shall address the situation where those users' access control is compromised, such as the corruption or compromise of passwords or other registration data. The organization shall not reissue deactivated or expired user identifiers on systems and services that process PII. Where the organization provides PII processing as a service, the customer can be responsible for some or all aspects of user identifier management and such cases shall be included in the documented information; some jurisdictions impose specific requirements on the frequency of checks for unused authentication credentials on systems that process PII.

Evidence an auditor accepts: Registration and de-registration procedures covering credential compromise; evidence identifiers on systems processing PII are never reissued; documented split of identifier management responsibility with customers
Common gap: Identifiers reissued to new joiners so historical access records point at the wrong person
Source: ISO/IEC 27701:2025
ISO 27701 A.3.9 Access rights

The organization shall maintain an accurate, up-to-date record of the user profiles created for users authorised to access information systems and the PII they contain, the profile comprising the data about the user, including the user identifier, needed to implement the technical controls that provide authorised access. Individual user identifiers shall be used so that appropriately configured systems can identify who accessed PII and what additions, deletions or changes they made, which protects users as well as the organization. Where the organization provides PII processing as a service and the customer is responsible for some or all access management, the organization shall where appropriate provide the customer the means to perform it, such as administrative rights to manage or terminate access, and document such cases.

Evidence an auditor accepts: Current user profile record supporting attribution of access and change; individual identifiers enforced on systems processing PII, with shared accounts prohibited; administrative means provided to customers to manage access, and the responsibility split documented
Common gap: Shared or generic accounts on systems holding PII
Source: ISO/IEC 27701:2025

See what it expects of your list

Paste the policy list, tick the regime, and every document it reaches carries its clauses, with the ones it expects and the list does not carry named. Eight documents free, no account.

Build a register