Hold more than one standard? One audit.
ISO/IEC 27701 shares its structure with ISO/IEC 27001. We audit them together — one team, one visit, one report.
The privacy extension to ISO/IEC 27001 — a management system for personal data controllers and processors mapped to GDPR requirements.
ISO/IEC 27701 adds privacy-specific requirements and controls to an ISMS: legal basis, data-subject rights, privacy by design, records of processing, transfers and breach notification.
Controller and processor obligations mapped.
Procedures for access, erasure, portability.
Privacy considered in new processing.
Maintained and reviewed.
Detection and notification timelines.
ISO/IEC 27701 is audited against these requirement areas. Open each one to see what auditors look for in your company.
ISO/IEC 27701 shares its structure with ISO/IEC 27001. We audit them together — one team, one visit, one report.
Scroll the steps — the bar shows where you are in the process. Every step has a named coordinator and a fixed timeline.
You send a short application; a coordinator sizes the audit and sends a fixed offer.
→ Offer with audit planDocumentation review and readiness check — remote or on site. Gaps are listed, not penalised.
→ Readiness reportOn-site assessment of implementation and effectiveness with a team that knows your sector.
→ Audit reportIndependent certification decision; the certificate is issued and entered into the public register.
→ ISO/IEC 27701 certificateAnnual surveillance keeps the certificate in force; re-certification in year three.
→ Certificate maintainedTick what you already have. You do not need a perfect system to apply — you need a working one.
Based on the items ticked on the left. Indicative — the Stage 1 audit gives the formal picture.
Apply for ISO/IEC 27701 →Did not find yours? Call us — a coordinator answers within the same business day.
+38 (044) 332-30-76Send an application — we define scope and audit duration, and issue a fixed offer within one business day.