ISO 27701 consulting: a privacy management system you can evidence
We implement a Privacy Information Management System (PIMS) that gives customers, partners and regulators independent assurance that personal data is handled correctly — and, for groups operating across the EU, Türkiye and the Gulf, one privacy system across several legal regimes.
What is ISO/IEC 27701?
ISO/IEC 27701 specifies requirements for a Privacy Information Management System (PIMS) for organisations acting as controllers and processors of personal data. With the 2025 edition it is no longer an extension of ISO/IEC 27001 but a standalone standard that can be certified on its own. In practice it integrates most efficiently with an existing ISMS, sharing context, risk method, document control and audit programme. It is the most practical way to demonstrate GDPR and KVKK accountability to customers and supervisory authorities.
What ISO/IEC 27701 gives your organisation
GDPR and KVKK accountability
Demonstrable compliance that pre-empts sanctions and the financial and reputational cost of a breach.
Independent proof
A certificate from an accredited body showing that personal data is processed securely.
Commercial advantage
In data-driven sectors, certification is a deciding factor in tenders and partner selection.
One system, several regimes
One privacy system covering GDPR, Turkish KVKK and Gulf regimes where you operate in several.
Processor control
Third-party processor management under GDPR Article 28, with contracts that match the operation.
Breach readiness
Breach assessment and notification procedures aligned to the 72-hour clock and to NIS2 reporting.
From current state to certifiable PIMS
We take organisations from zero to conformity, or develop an existing system that has stopped keeping pace with how the business actually processes data.
Current state analysis
Processing activities, current legal compliance level and privacy risks identified.
Roadmap
An organisation-specific compliance strategy and implementation plan, including the controller and processor roles you hold.
Documentation and process design
Policies, procedures, instructions and a records management system; records of processing that can be maintained.
Implementation and integration
A PIMS that operates alongside or integrated with your ISMS, with shared document control and audit programme.
Transfers and third countries
SCCs, transfer impact assessments and supplementary measures for non-adequate jurisdictions, including Türkiye.
Internal audit and improvement
Internal audit, corrective action, performance evaluation and a pre-certification mock audit.
Certification support
Certification body selection and support through the Stage 1 and Stage 2 audits.
Engagement summary
- Standard
- ISO/IEC 27701:2025 — standalone or integrated with ISO/IEC 27001
- Delivered as
- Word and Excel; version-controlled, metadata cleaned, document IDs applied
- Language
- English by default for EU clients; Turkish available
- Regimes covered
- EU GDPR, Türkiye KVKK, UAE PDPL, Qatar PDPPL
Our approach
- One privacy system covering GDPR, KVKK and Gulf regimes where you operate in several
- Standard contractual clauses attached in unaltered official form, never reproduced
- Transfer impact assessments written for the actual data flow, not generic
- Integration with the existing ISMS document control and audit programme
- Data subject request handling the operational team can run
What you hold at the end of the engagement
- PIMS scope and controller / processor role analysis
- Privacy policy and objectives
- Records of processing activities, designed to be maintained
- Privacy risk assessment and DPIA procedure
- Privacy notices, consent and data subject rights procedures
- Processor register and Article 28 agreement set
- Transfer map, SCC package and transfer impact assessments
- Breach assessment and 72-hour notification procedure
- Retention and deletion schedule
- Training and attendance records
- Internal audit report and management review pack
- Pre-certification mock audit findings
Questions we are asked
Do we need ISO/IEC 27001 before ISO/IEC 27701?
Not any more. The 2025 edition made ISO/IEC 27701 a standalone standard that can be certified on its own. If you already run an ISMS, integrating the PIMS with it is usually the most efficient route, because context, risk method, document control and audit programme are shared.
Does ISO/IEC 27701 certification prove GDPR compliance?
It is strong evidence of accountability, but not a legal declaration of compliance. It shows a supervisory authority, customers and partners that privacy is managed systematically — records of processing, DPIAs, processor control, breach handling. Legal obligations such as lawful basis and transfer mechanisms still have to be right in substance, which is why we cover both sides.
Can one PIMS cover GDPR and Turkish KVKK?
Yes, and that is one of the main reasons groups with operations in both use it. The management system is common; jurisdiction-specific requirements — for example KVKK’s standard contract notification and VERBIS registration — sit in annexes. We advise on both ends of the same data flow.
We are a processor for our customers. Is the standard relevant?
Very. ISO/IEC 27701 has requirements specific to processors, and customers increasingly ask processors for independent assurance before signing Article 28 agreements. A certificate can shorten due diligence considerably.
Let us start with a scoping conversation
Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.