ANALYSISMEMBER

ISO updates standard on managing privacy compliance programs

Published
Subscribe to IAPP Newsletters

Contributors:

Henry Davies

AIGP, CIPP/E, CIPM, FIP

Data Protection Officer

Birdie

Editor's note: The IAPP is policy neutral. We publish contributed opinion and analysis pieces to enable our members to hear a broad spectrum of views in our domains.

For the first time since 2019, the International Organization for Standardization has updated its international standard for managing privacy compliance programs.

The international standard for "Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance," ISO 27701, "specifies requirements and provides guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System."

There are several significant changes in the updated ISO 27701. The standard is now a standalone management system, meaning organizations will no longer need to have an ISO 27001 certified Information Security Management System. However, those with an ISMS will be able to integrate the two management systems.

PIMS clauses

The updated standard outlines clauses that set out the high-level requirements of establishing a PIMS, which must be followed and implemented by any organization seeking certification.

Clause 4: Context of the organization. Like many other standards, ISO 27701 requires organizations to fully understand the context of their organization. This is achieved by determining the external and internal issues relevant to the PIMS, understanding the needs and expectations of interested parties — specifically those with interests or responsibilities when it comes to processing personally identifiable information — and determining the scope of the PIMS. This understanding must include the organization's role in relation to PII, either as a controller and/or as a processor.

Contributors:

Henry Davies

AIGP, CIPP/E, CIPM, FIP

Data Protection Officer

Birdie

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership