Privacy & security

ISO/IEC 27701

ISO/IEC 27701 — Privacy Information Management System

ISO / IECLatest · 2019

Scope

An extension to ISO/IEC 27001 that adds privacy-specific controls for organizations that process personally identifiable information. Referenced by hospitals building privacy-management programs beyond HIPAA's baseline.

Where it applies in the room

  • Privacy governance and controller/processor roles
  • Third-party data-processing arrangements

Source & further reading

Also known as

  • ISO/IEC 27701:2019
  • ISO/IEC 27701
  • ISO 27701

Help us improve

Spotted something wrong, outdated, or unclear? Let the editors know.