ISO/IEC 27701 (PII controller)
Version: 2019 (clause 5 and Annex A)
ISO/IEC 27701 extends an ISO/IEC 27001 information security management system into a privacy information management system (PIMS); this catalog covers the PIMS-specific clause 5 requirements and the Annex A controls for organizations acting as PII controllers. ISO/IEC 27701:2025 restructured the standard as a standalone privacy management system; this catalog tracks the 2019 numbering used by current certificates.
Where we stand
Controls
83%
Evidence
0%
Policies
25%
24 of 55 clauses mapped to adopted controls
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| 5.2 Context of the organization | |||||
| 5.2.1 | Understanding the organization and its context | Unmapped | Unmapped | Unmapped | Not yet |
| 5.2.2 | Understanding the needs and expectations of interested parties | Unmapped | Unmapped | Unmapped | Not yet |
| 5.2.3 | Determining the scope of the information security management system | Unmapped | Unmapped | Unmapped | Not yet |
| 5.2.4 | Information security management system Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| 5.3 Leadership | |||||
| 5.3.1 | Leadership and commitment Controls: BIZ-12, BIZ-14 | Passing | Not current | Not approved | Not yet |
| 5.3.2 | Policy Controls: BIZ-14, PEOPLE-04 | Passing | Not current | Not approved | (4 mo ago) |
| 5.3.3 | Organizational roles, responsibilities and authorities Controls: BIZ-15, PEOPLE-08 | Not passing | Not current | Not approved | Not yet |
| 5.4.1 Actions to address risks and opportunities | |||||
| 5.4.1.1 | General Controls: BIZ-04, BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| 5.4.1.2 | Information security risk assessment Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| 5.4.1.3 | Information security risk treatment Controls: BIZ-07 | Passing | Not current | Approved | Not yet |
| 5.4 Planning | |||||
| 5.4.2 | Information security objectives and planning to achieve them | Unmapped | Unmapped | Unmapped | Not yet |
| 5.5 Support | |||||
| 5.5.1 | Resources | Unmapped | Unmapped | Unmapped | Not yet |
| 5.5.2 | Competence | Unmapped | Unmapped | Unmapped | Not yet |
| 5.5.3 | Awareness Controls: PEOPLE-04, PEOPLE-06, PEOPLE-07 | Not passing | Not current | Not approved | (8 h ago) |
| 5.5.4 | Communication | Unmapped | Unmapped | Unmapped | Not yet |
| 5.5.5 | Documented information | Unmapped | Unmapped | Unmapped | Not yet |
| 5.6 Operation | |||||
| 5.6.1 | Operational planning and control Controls: PDP-02, PDP-14, VEND-04 | Not passing | Not current | Not approved | (8 h ago) |
| 5.6.2 | Information security risk assessment Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| 5.6.3 | Information security risk treatment Controls: BIZ-05, BIZ-07 | Passing | Not current | Not approved | (4 mo ago) |
| 5.7 Performance evaluation | |||||
| 5.7.1 | Monitoring, measurement, analysis and evaluation Controls: BIZ-08 | Passing | Not current | Approved | Not yet |
| 5.7.2 | Internal audit | Unmapped | Unmapped | Unmapped | Not yet |
| 5.7.3 | Management review | Unmapped | Unmapped | Unmapped | Not yet |
| 5.8 Improvement | |||||
| 5.8.1 | Nonconformity and corrective action Controls: BIZ-09 | Passing | Not current | Approved | Not yet |
| 5.8.2 | Continual improvement Controls: BIZ-09 | Passing | Not current | Approved | Not yet |
| A.7.2 Conditions for collection and processing | |||||
| A.7.2.1 | Identify and document purpose | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.2.2 | Identify lawful basis | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.2.3 | Determine when and how consent is to be obtained | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.2.4 | Obtain and record consent | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.2.5 | Privacy impact assessment | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.2.6 | Contracts with PII processors Controls: VEND-02 | Passing | Not current | Not approved | Not yet |
| A.7.2.7 | Joint PII controller | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.2.8 | Records related to processing PII | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.3 Obligations to PII principals | |||||
| A.7.3.1 | Determining and fulfilling obligations to PII principals | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.3.2 | Determining information for PII principals Controls: LEGAL-01 | Passing | Not current | Approved | Not yet |
| A.7.3.3 | Providing information to PII principals Controls: LEGAL-01 | Passing | Not current | Approved | Not yet |
| A.7.3.4 | Providing mechanism to modify or withdraw consent | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.3.5 | Providing mechanism to object to PII processing | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.3.6 | Access, correction and/or erasure Controls: DATA-05 | Passing | Not current | Not approved | Not yet |
| A.7.3.7 | PII controllers' obligations to inform third parties | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.3.8 | Providing copy of PII processed | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.3.9 | Handling requests | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.3.10 | Automated decision making | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.4 Privacy by design and privacy by default | |||||
| A.7.4.1 | Limit collection | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.4.2 | Limit processing Controls: DATA-04 | Passing | Not current | Not approved | Not yet |
| A.7.4.3 | Accuracy and quality | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.4.4 | PII minimization objectives | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.4.5 | PII de-identification and deletion at the end of processing Controls: DATA-04, DATA-05 | Passing | Not current | Not approved | Not yet |
| A.7.4.6 | Temporary files Controls: DATA-04, DATA-05 | Passing | Not current | Not approved | Not yet |
| A.7.4.7 | Retention Controls: DATA-04 | Passing | Not current | Not approved | Not yet |
| A.7.4.8 | Disposal Controls: DATA-05 | Passing | Not current | Not approved | Not yet |
| A.7.4.9 | PII transmission controls Controls: DATA-03, DATA-06 | Not passing | Not current | Not approved | (8 h ago) |
| A.7.5 PII sharing, transfer, and disclosure | |||||
| A.7.5.1 | Identify basis for PII transfer between jurisdictions | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.5.2 | Countries and international organizations to which PII can be transferred | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.5.3 | Records of transfer of PII | Unmapped | Unmapped | Unmapped | Not yet |
| A.7.5.4 | Records of PII disclosure to third parties | Unmapped | Unmapped | Unmapped | Not yet |
