Skip to content
DM11AI TRUST & IT RISK PROTECTION
StandardsProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • SastAction®
  • NosConformes®
  • Cyber Antifrágil®
  • All products

Company

  • About Us
  • Case Studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000
  • Standards and certifications
  • Comparisons between standards

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption
  1. Home
  2. ISO/IEC 27701
  3. ISO/IEC 27701 implementation

ISO/IEC 27701

Privacy can now be certified on its own

Until 2019 this standard was an extension, and nobody certified privacy without first building an entire security management system. The October 2025 revision ended that requirement. For a company that already treats personal data seriously and now has to prove it to a customer or a regulator, the road got significantly shorter.

Talk to a specialistSee the other standards

DM11 prepares your company and runs the implementation. The audit and the certificate come from an accredited certification body that you contract. The standard covers privacy management and does not replace legal advice on data protection law: the two go together, and DM11 has digital law specialists on the team.

Who runs the implementation

  • Data protection specialists certified by EXIN (DPO, PDPP and PDPF)

  • ISO/IEC 27001 Lead Auditor certified by BSI

  • Legal advisory in privacy and data protection

  • 17 years of governance, risk and compliance

WHAT CHANGED, AND WHY IT MATTERS

The standard changed its nature, and most material out there missed it

ISO/IEC 27701 sets the requirements for a privacy information management system. It organises how a company decides what it may do with personal data, who answers for each decision, and how that is evidenced over time. In the revision published on 14 October 2025 it stopped being an appendix to security and started standing on its own.

It no longer requires ISO 27001 underneath

This is the change that rewrites the budget. In the 2019 version, certifying privacy meant having or building the whole security management system first. The standard is now self-contained, and a company can certify privacy without going through 27001. If you received a recent proposal saying otherwise, it was written against the old version.

The structure now matches the other management standards

The revision adopted the harmonised structure of clauses 4 to 10, the same as ISO 27001 and ISO/IEC 42001 for AI governance. In practice, a company already running one of those reuses context, leadership, planning and management review instead of maintaining three parallel systems.

Controllers and processors get different lists

Annex A separates the controls by role: one set for controllers, another for processors, and a block that applies to both. Defining your role in each processing activity is the first decision of the project and the one that most changes its size. Many companies are a controller in one flow and a processor in another.

The GDPR mapping is inside the standard itself

The standard carries annexes linking the controls to the GDPR and to other privacy references, including the 2019 version for anyone migrating. That is what makes the certificate useful as an answer to a European customer, and what saves work for a company that already organised itself for a data protection law.

WHO USUALLY NEEDS IT

Three situations where certifying privacy solves the problem

Data protection law already obliges you, and nobody certifies a law. ISO 27701 comes in when you have to prove to third parties that the obligation is being met with method.

A European customer asked for evidence

A contract with an EU company usually demands guarantees about personal data processing. An internationally recognised certificate answers that better than a dossier assembled in a hurry, and it answers once for every customer rather than one at a time.

You are a processor and live answering audits

A company that processes data on someone else's behalf receives a privacy questionnaire from every customer, each in a different format. The certificate swaps that queue for a single document, and the processor control set was designed for exactly that role.

The regulator came into view

An enforcement action, a reported incident, or a sector that became a priority. A working privacy management system is the difference between demonstrating diligence with dated documents and trying to reconstruct the story after the question has arrived.

STORIES

Three situations we have already solved

We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern repeats. Where a client agrees, we give named references in a conversation.

Payroll and benefits services

A data processor that did not know it was one

Situation

The company processed the personal data of thousands of its customers' employees and treated all of it as if it were its own. The contracts did not say who answered for what, and a large customer opened a privacy audit the company had no way to answer.

What we did

We started by separating the roles flow by flow: where it was a controller and where it was a processor. That distinction changed the whole design of the programme and much of the contractual wording. The inventory of processing activities, the legal bases and the processor control block followed.

Result

The customer's audit was answered with a document instead of a meeting. The company then began using the same material commercially, because its processor role was clear in the contract and stopped being an argument at every renewal.

Technology, serving Europe

They complied and could not prove it

Situation

The company had run a data protection compliance project two years earlier, with good results and no maintenance since. When a European customer asked for evidence of adequate processing, what existed was an out-of-date report and the memory of the people who took part.

What we did

We reused what the earlier project had left behind, which was more than the board expected, and what was missing was precisely the management system: who reviews, when, with what record. We built that and mapped the controls against the GDPR using the standard's own annexes.

Result

The company ended up with a system that maintains itself and a mapping ready to answer European customers. The earlier project stopped being a sunk cost and became the base of the new one.

Private healthcare

Sensitive data handled like ordinary data

Situation

The operation handled health information, which the law treats as sensitive personal data, and applied the same controls to it as to everything else. There was no intent to get it wrong: nobody had made the distinction on paper, so it did not exist in practice.

What we did

We classified the processing activities by the nature of the data and reinforced where the law demands more: a specific legal basis, tighter access control, a record of who consults what, and retention periods set by type of information.

Result

The difference showed up in access control: dozens of people could reach patient records with no functional need, and nobody knew because there was no log. After the project, access became justified, logged and reviewed.

HOW WE RUN IT

From the processing inventory to the certification audit

The method is the one we use for ISO 27001, adapted to what privacy has of its own: the role in each processing activity, the legal basis and the data subject's rights. Led by an external specialist, with one focal point from your team, and each requirement assessed on a binary scale rather than a subjective score nobody defends in an audit.

  1. 01

    Scope, roles and management system foundation

    We define the scope and boundaries of the management system (clause 4), engage leadership and set up the privacy governance (clause 5). In parallel we map the personal data processing activities and decide, activity by activity, whether the company is controller or processor.

    • Scope and boundaries of the management system approved

    • Inventory of personal data processing activities

    • Role defined per activity: controller or processor

    • Privacy governance in place, with the data protection officer formalised

    MilestoneProcessing inventory approved and the role defined for 100% of the mapped flows.

  2. 02

    Legal bases, privacy risks and gaps

    We run the gap analysis against clauses 6 and 7, record the legal basis for each processing activity and assess the risks to the data subjects' privacy, which are not the same as information security risks. Where the law requires it, we produce the impact assessment.

    • Legal basis recorded for every processing activity

    • Assessment of risks to data subjects' privacy

    • Data protection impact assessment where applicable

    • Treatment plan and statement of applicability for the controls

    MilestoneLegal bases approved by legal counsel and the treatment plan signed off by leadership.

  3. 03

    Privacy controls and data subject rights

    We implement the Annex A controls matching the company's role, with the shared block serving both. This is the phase where handling data subject requests stops being improvisation: deadline, channel, record and a standard response, plus retention and disposal set by type of data.

    • Controller controls, processor controls or both, according to the role

    • A data subject request process, with deadlines and records

    • Retention and disposal policy by type of data

    • Privacy clauses reviewed in third-party contracts

    MilestoneFirst cycle of data subject requests handled within the deadline and fully recorded.

  4. 04

    Internal audit, management review and certification

    We run the internal audit (clause 9) with a consultant independent of whoever implemented, conduct the management review and handle the findings (clause 10). We consolidate the evidence and stay with you through both stages of the external audit.

    • Internal audit run by an independent consultant

    • Management review, with findings addressed

    • Consolidated privacy evidence repository

    • Support through stage 1 and stage 2 of the external audit

    MilestoneCertification audit completed and the certificate issued by the accredited body.

HOW LONG IT TAKES

It depends most on how much of the data protection work was genuinely done

We do not publish a standard timeline, because a published timeline becomes a promise. The spread is even wider here than for ISO 27001, for one specific reason: a company that ran a data protection project with method arrives halfway there, and a company that ran a paper project arrives at roughly zero. The first conversation already tells the two apart.

What survived from the compliance project

An up-to-date processing inventory and recorded legal bases take months off. A two-year-old report nobody maintained is usually worth less than it looks, and it is honest to say so before starting.

How many roles the company holds

Being only a controller is the shortest road. Holding both roles across different flows multiplies the applicable controls and the contract clauses to revise.

Whether another management system is already running

With ISO 27001 or ISO 42001 in operation, clauses 4 to 10 are the same and much of the governance work is already done. With none, that base has to be built, and it can now be built directly on 27701.

THE ROLES ARE KEPT APART

Whoever prepares does not certify, and privacy is not only a legal matter

As with every certifiable standard, the certificate comes from an accredited body you contract, never from DM11, and the clause 9 internal audit is run by someone who did not implement. There is a second separation here: the standard covers management and does not replace legal advice on data protection law. Both sides need to talk, and the project runs with a digital law specialist alongside the management specialist.

  • DM11 prepares, implements and supports. It issues no certificate

  • You contract the certification body, and the choice is yours

  • The clause 9 internal audit is carried out by someone who did not implement

  • The standard organises the management; interpreting the law stays with counsel

FREQUENTLY ASKED

What people ask before deciding

The questions that come up in almost every first meeting, answered straight.

No, and that is the change that alters the maths. Up to the 2019 version, 27701 was an extension and could not be certified without 27001 in place. The revision published on 14 October 2025 made the standard self-contained: it no longer depends on implementing 27001 or 27002. If you received a proposal saying otherwise, it was written against the previous version. Holding 27001 still helps considerably, because clauses 4 to 10 are the same, but it stopped being a prerequisite.

Find out how much of your data protection work already counts toward the certificate

In the first conversation we look at what exists in terms of inventory, legal bases and the data subject request process, and tell you honestly whether the road is short or long.

Talk to a specialistSee the other standards

Comparisons on this subject

  • ISO 27701 vs LGPD
  • GDPR vs LGPD
See all 13 comparisons