Recently, the privacy field has come under increasing regulation. Privacy governance remains a complex undertaking, drawing regulatory attention, evolving global legislation and societal maturity.
ISO/IEC 27701:2019 is an extension of the international information security management standard ISO/IEC 27001. By design, the standard is aligned with ISO 27001 to extend existing ISMSs (Information Security Management Systems) and meet additional requirements to enable organizations to establish, implement, maintain and continuously improve their PIMS.
ISO 27701 guidelines protect privacy, including how organizations should manage personal information and demonstrate compliance with global privacy regulations, such as GDPR (General Data Protection Regulation) and the Personal Information Protection Act (POPIA).
ISO 27701 applies to:
In conclusion, ISO 27701 is a broadly applicable standard and an internationally recognized framework that can help integrate privacy governance into risk management practices. In this regard, ISO 27701 could serve as the basis for a potential GDPR or POPIA certification framework.