Skip to content

ISO 27701

Privacy management, properly in order

ISO 27701 extends your ISMS with privacy-specific controls, and helps structurally embed GDPR obligations.

Book an introductory call
  • Privacy & data governance
  • Governance, risk & compliance

When privacy needs a system

Organisations with ISO 27001 certification are often asked how privacy is embedded within it.

GDPR compliance remains hard to demonstrate without a structured system around it.

  • You already have ISO 27001 and want to add privacy structurally

  • Customers ask about your privacy information management

  • GDPR obligations aren’t yet embedded in a system

What needs to be visible during an audit

Without a structured privacy system, GDPR compliance depends on disconnected documents that don’t line up.

That makes it harder to show, during an inspection or incident, that privacy is actually embedded.

What the standard adds to your ISMS

ISO 27701 adds privacy roles, processing purposes and data subject rights to your existing ISMS.

  • Defined roles as controller or processor

  • A process for data subject rights

  • Privacy by design in new processes and systems

  • Agreements with processors and sub-processors

  • Internal audits that cover privacy

Building on ISO 27001

Vedeum builds on your existing ISO 27001 system, so privacy doesn’t become a separate project.

  1. Baseline assessment

    We assess your current ISMS and privacy practice against ISO 27701.

  2. Implementation

    We help set up privacy roles, processes and processor agreements.

  3. Internal audit

    We carry out an internal audit and prepare you for the certification body.

  4. Certification & maintenance

    We guide certification and keep the system current.

Book a no-obligation introductory call

Tell us where your organisation stands. We will think through the first steps with you.

Book an introductory call