ISO 27701:2019 Privacy Information Management System (PIMS)

This specifies requirements and provides guidance for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS) in the form of an extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy management within the organization.

This specifies PIMS-related requirements and provides guidance for PII controllers and PII processors holding responsibility and accountability for PII processing.

This document is applicable to all types and sizes of organizations, including public and private companies, government entities and not-for-profit organizations, which are PII controllers and/or PII processors processing PII within an ISMS.

In August 2019, ISO announced its latest certification ISO 27701: 2019 also known as the Privacy Information Management System or PIMS. Previously, ISO 27701 was called ISO 27552.

It is an extension certification on top of the ISO 27001.

Need More information on ISO/IEC 27001:2019 PIMS? Refer to our webinar videos.

How ISO/IEC 27701 (PIMS) can help for GDPR CCPA Privacy Compliance :

ISO/IEC 27701 (PIMS)

How ISO/IEC 27701 can help comply with India's Data Protection Bill 2021 :

ISO/IEC 27701


  • Assures that the data subjects of customers are managed responsibly.
  • Integrates with ISO 27001 based on your Information Security Management System (ISMS).
  • Provide clear visibility of data management approaches with partners.
  • It can help to identify, prioritize, and manage risks throughout the data lifecycle.
  • Helps achieve compliance with data protection regulations such as GDPR, CCPA and others.
  • Indicates assurance that PII can be managed without infringing data subjects’ privacy.

Read More about ISO 27701:2019 Privacy Information Management System

Read More