ISO 27701 is an international standard, officially titled ISO/IEC 27701:2019 "Information security management system - Privacy information management system - Requirements and guidelines". It is an expanded version of the ISO 27001 information security management system standard, providing more specific requirements and guidelines for the protection of personal data
The purpose of ISO 27701 is to help organizations establish, implement, and maintain an effective personal data protection management system. This standard provides a framework to guide organizations on how to ensure consistency between information security and privacy protection when handling personal data
ISO 27701 contains a set of requirements and guidelines to help organizations comply with relevant privacy regulations and legal requirements in the processing of personal data, ensuring the legality, accuracy, and reliability of personal data. It emphasizes that organizations should implement appropriate technical and organizational measures to protect the confidentiality, integrity, and availability of personal data
ISO 27701 verification is based on an organization's implementation and compliance with the ISO 27001 information security management system, while also extending to the practice of personal data protection requirements. Through ISO 27701 verification, an organization can demonstrate its commitment and capability to personal data protection and demonstrate its compliance to relevant stakeholders
In summary, ISO 27701 is an expanded standard for information security management systems, focusing on the protection of personal data. It provides guidance and requirements to help organizations ensure compliance with relevant privacy regulations and legal requirements when processing personal data. This helps organizations establish a reliable personal data protection system to safeguard the privacy and security of personal data