Since the introduction of the
General Data Protection Regulation (GDPR), and the continuous growth of comparable data protection laws worldwide, there has been an increasing need for a standard or code of conduct to support compliance.
Although there are already publications and standards discussing data protection, many of them are not international, primarily focusing on data protection requirements and best practices in specific jurisdictions.
For example, BS 10012 is exclusively based on the GDPR and the UK Data Protection Act (DPA) 2018, making it a strong candidate for organizations with a strong regional interest.
Meanwhile, an approach based on international best practices should be adaptable to other frameworks and not impose requirements dependent on specific legislation. Crucially, this means that this standard (ISO 27701) supports compliance with a broader international range of data protection and privacy legislation, including the Health Information Portability and Accountability Act (HIPAA) and the California Consumer Privacy Act (CCPA) in the U.S.
Thus, ISO/IEC 27701 (Security Techniques – Extension to ISO/IEC 27001 and ISO/IEC 27002 for Privacy Information Management – Requirements and Guidelines), published in August 2019, aims to fill the assurance gap and provide a genuinely international approach to data protection as an extension of information security.
Originally based on ISO 27552, ISO 27701 provides specific requirements and guidelines for establishing, implementing, maintaining, and continuously improving a Privacy Information Management System (PIMS) as an extension of the Information Security Management System (ISMS) defined in ISO 27001. It considers the privacy protections required for the proper processing and handling of personally identifiable information (PII).
This ISO 27701 applies to data controllers (including Joint Controllers) and data processors (including Sub-processors), regardless of the jurisdictions and sectors in which they operate.
Some considerations of this ISO 27701 standard:
- It focuses on new requirements and controls in its annex, aimed at the protection of personal data;
- It adds value when implemented as it allows demonstrating accountability (compliance and responsibility) with the GDPR;
- It is privacy-oriented and based on ISO 27001;
- Certification under this standard will first require ISO 27001 certification;
CONTACT US FOR + INFORMATION