> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ISO 27701:2019

> Extend your ISMS to a Privacy Information Management System (PIMS) for managing PII.

> Extend your ISMS to a Privacy Information Management System (PIMS) for managing PII.

ISO/IEC 27701 is a privacy extension to ISO 27001 and ISO 27002. It specifies requirements for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS). It helps organizations manage personally identifiable information (PII) as both controllers and processors.

<Note>
  ISO 27701 builds on top of an existing ISO 27001 certification. You cannot certify to 27701 without an ISO 27001 ISMS in place.
</Note>

## Who needs ISO 27701:2019?

<CardGroup cols={2}>
  <Card title="PII controllers and processors" icon="user-shield">
    Any organization that collects, processes, or stores personal data and wants to demonstrate privacy governance.
  </Card>

  <Card title="GDPR-regulated organizations" icon="globe">
    27701 maps closely to GDPR and helps demonstrate accountability to regulators and customers.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="PIMS requirements" icon="lock">
    Privacy-specific extensions to the ISO 27001 management system clauses.
  </Card>

  <Card title="Controller guidance" icon="user-gear">
    Controls and obligations for organizations that determine the purpose of processing PII.
  </Card>

  <Card title="Processor guidance" icon="server">
    Controls for organizations that process PII on behalf of others.
  </Card>

  <Card title="PII mapping" icon="sitemap">
    Maps controls to GDPR, ISO 29100, and other privacy frameworks.
  </Card>
</CardGroup>

## How DSALTA helps with ISO 27701:2019

<Steps>
  <Step title="Activate ISO 27701">
    Select ISO 27701 from the Frameworks page. DSALTA layers PIMS controls on top of your ISO 27001 ISMS.
  </Step>

  <Step title="Review privacy controls">
    Review controller and processor controls and assign owners.
  </Step>

  <Step title="Collect evidence automatically">
    Connect integrations to collect privacy and security evidence continuously.
  </Step>

  <Step title="Approve privacy policies">
    Review and approve AI-generated privacy policies and records of processing.
  </Step>

  <Step title="Prepare for audit">
    Share evidence with your certification body through the platform.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Do I need ISO 27001 first?" icon="list-ol">
    Yes. ISO 27701 is an extension and requires an established ISO 27001 ISMS as its foundation.
  </Accordion>

  <Accordion title="Does 27701 satisfy GDPR?" icon="globe">
    It does not replace GDPR but provides a strong, auditable framework that maps to many GDPR obligations and demonstrates accountability.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
