FintastIQTrust Center
LoginBook a Consultation
Framework

ISO/IEC 27701 (PII controller)

Version: 2019 (clause 5 and Annex A)

ISO/IEC 27701 extends an ISO/IEC 27001 information security management system into a privacy information management system (PIMS); this catalog covers the PIMS-specific clause 5 requirements and the Annex A controls for organizations acting as PII controllers. ISO/IEC 27701:2025 restructured the standard as a standalone privacy management system; this catalog tracks the 2019 numbering used by current certificates.

Official source

Summary

Where we stand

Controls
83%
Evidence
0%
Policies
25%

24 of 55 clauses mapped to adopted controls

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
5.2 Context of the organization
5.2.1Understanding the organization and its contextUnmappedUnmappedUnmappedNot yet
5.2.2Understanding the needs and expectations of interested partiesUnmappedUnmappedUnmappedNot yet
5.2.3Determining the scope of the information security management systemUnmappedUnmappedUnmappedNot yet
5.2.4Information security management system
Controls: BIZ-14
PassingNot currentNot approvedNot yet
5.3 Leadership
5.3.1Leadership and commitment
Controls: BIZ-12, BIZ-14
PassingNot currentNot approvedNot yet
5.3.2Policy
Controls: BIZ-14, PEOPLE-04
PassingNot currentNot approved(4 mo ago)
5.3.3Organizational roles, responsibilities and authorities
Controls: BIZ-15, PEOPLE-08
Not passingNot currentNot approvedNot yet
5.4.1 Actions to address risks and opportunities
5.4.1.1General
Controls: BIZ-04, BIZ-05
PassingNot currentNot approved(4 mo ago)
5.4.1.2Information security risk assessment
Controls: BIZ-04
PassingNot currentNot approvedNot yet
5.4.1.3Information security risk treatment
Controls: BIZ-07
PassingNot currentApprovedNot yet
5.4 Planning
5.4.2Information security objectives and planning to achieve themUnmappedUnmappedUnmappedNot yet
5.5 Support
5.5.1ResourcesUnmappedUnmappedUnmappedNot yet
5.5.2CompetenceUnmappedUnmappedUnmappedNot yet
5.5.3Awareness
Controls: PEOPLE-04, PEOPLE-06, PEOPLE-07
Not passingNot currentNot approved(8 h ago)
5.5.4CommunicationUnmappedUnmappedUnmappedNot yet
5.5.5Documented informationUnmappedUnmappedUnmappedNot yet
5.6 Operation
5.6.1Operational planning and control
Controls: PDP-02, PDP-14, VEND-04
Not passingNot currentNot approved(8 h ago)
5.6.2Information security risk assessment
Controls: BIZ-04
PassingNot currentNot approvedNot yet
5.6.3Information security risk treatment
Controls: BIZ-05, BIZ-07
PassingNot currentNot approved(4 mo ago)
5.7 Performance evaluation
5.7.1Monitoring, measurement, analysis and evaluation
Controls: BIZ-08
PassingNot currentApprovedNot yet
5.7.2Internal auditUnmappedUnmappedUnmappedNot yet
5.7.3Management reviewUnmappedUnmappedUnmappedNot yet
5.8 Improvement
5.8.1Nonconformity and corrective action
Controls: BIZ-09
PassingNot currentApprovedNot yet
5.8.2Continual improvement
Controls: BIZ-09
PassingNot currentApprovedNot yet
A.7.2 Conditions for collection and processing
A.7.2.1Identify and document purposeUnmappedUnmappedUnmappedNot yet
A.7.2.2Identify lawful basisUnmappedUnmappedUnmappedNot yet
A.7.2.3Determine when and how consent is to be obtainedUnmappedUnmappedUnmappedNot yet
A.7.2.4Obtain and record consentUnmappedUnmappedUnmappedNot yet
A.7.2.5Privacy impact assessmentUnmappedUnmappedUnmappedNot yet
A.7.2.6Contracts with PII processors
Controls: VEND-02
PassingNot currentNot approvedNot yet
A.7.2.7Joint PII controllerUnmappedUnmappedUnmappedNot yet
A.7.2.8Records related to processing PIIUnmappedUnmappedUnmappedNot yet
A.7.3 Obligations to PII principals
A.7.3.1Determining and fulfilling obligations to PII principalsUnmappedUnmappedUnmappedNot yet
A.7.3.2Determining information for PII principals
Controls: LEGAL-01
PassingNot currentApprovedNot yet
A.7.3.3Providing information to PII principals
Controls: LEGAL-01
PassingNot currentApprovedNot yet
A.7.3.4Providing mechanism to modify or withdraw consentUnmappedUnmappedUnmappedNot yet
A.7.3.5Providing mechanism to object to PII processingUnmappedUnmappedUnmappedNot yet
A.7.3.6Access, correction and/or erasure
Controls: DATA-05
PassingNot currentNot approvedNot yet
A.7.3.7PII controllers' obligations to inform third partiesUnmappedUnmappedUnmappedNot yet
A.7.3.8Providing copy of PII processedUnmappedUnmappedUnmappedNot yet
A.7.3.9Handling requestsUnmappedUnmappedUnmappedNot yet
A.7.3.10Automated decision makingUnmappedUnmappedUnmappedNot yet
A.7.4 Privacy by design and privacy by default
A.7.4.1Limit collectionUnmappedUnmappedUnmappedNot yet
A.7.4.2Limit processing
Controls: DATA-04
PassingNot currentNot approvedNot yet
A.7.4.3Accuracy and qualityUnmappedUnmappedUnmappedNot yet
A.7.4.4PII minimization objectivesUnmappedUnmappedUnmappedNot yet
A.7.4.5PII de-identification and deletion at the end of processing
Controls: DATA-04, DATA-05
PassingNot currentNot approvedNot yet
A.7.4.6Temporary files
Controls: DATA-04, DATA-05
PassingNot currentNot approvedNot yet
A.7.4.7Retention
Controls: DATA-04
PassingNot currentNot approvedNot yet
A.7.4.8Disposal
Controls: DATA-05
PassingNot currentNot approvedNot yet
A.7.4.9PII transmission controls
Controls: DATA-03, DATA-06
Not passingNot currentNot approved(8 h ago)
A.7.5 PII sharing, transfer, and disclosure
A.7.5.1Identify basis for PII transfer between jurisdictionsUnmappedUnmappedUnmappedNot yet
A.7.5.2Countries and international organizations to which PII can be transferredUnmappedUnmappedUnmappedNot yet
A.7.5.3Records of transfer of PIIUnmappedUnmappedUnmappedNot yet
A.7.5.4Records of PII disclosure to third partiesUnmappedUnmappedUnmappedNot yet
ISO/IEC 27701 (PII controller) readiness · FintastIQ Trust Center