ISO/IEC 27701:2019
Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Both
Establish, implement, maintain, and continually improve a PIMS that extends the ISMS to cover privacy of PII.
- Evidence of PIMS integration with existing ISMS
- No documented PIMS establishment plan covering all PDCA stages
- Maintenance cadence and ownership for PIMS artefacts undefined
- Continual improvement actions not linked to audit, incident, or measurement output
- No evidence of management endorsement of the PIMS programme
Perform privacy risk assessments that consider risks to PII principals (data subjects), not only risks to the organization.
- Risk register with PII-principal impact ratings
- DPIA records where applicable
- No privacy-specific risk assessment methodology separate from generic security risk
- Impact to PII principals (not just the organization) not assessed
- Risk register does not tag PII categories, processing purposes, and lawful bases
- Assessment frequency and triggers (new processing, new vendor) not defined
Define and apply a privacy risk treatment process selecting controls from Annex A (controllers), Annex B (processors), and ISO 27001 Annex A.
- Justification for inclusion/exclusion of Annex A/B controls
- Risk treatment plan does not justify selected privacy controls against Annex A/B
- Residual privacy risk acceptance not authorised by the risk owner
- Treatment actions not tracked to closure with owners and dates
- No linkage between treatment decisions and privacy notices issued to principals
Ensure personnel are aware of the privacy policy, their contribution to PIMS effectiveness, and the implications of not conforming.
- Attendance and completion records
- Acknowledgment of privacy policy
- Awareness content does not cover PII handling responsibilities by role
- No record of completion for privacy awareness across all PII-handling staff
- Refresher cadence for privacy awareness not defined
- Awareness not extended to contractors and temporary staff with PII access
Determine internal and external communications relevant to the PIMS, including who, what, when, and how to communicate.
- Examples of executed communications
- Internal and external privacy communication topics, audiences, and channels not defined
- No log of privacy communications issued to principals and regulators
- Crisis and breach communications not pre-approved
- Communication ownership not assigned to a named role
Maintain documented information required by the PIMS and ISO 27701, with version control and protection.
- Approved current versions of PIMS documents stored in controlled repository
- PIMS documents not version-controlled with approval history
- Retention rules for PIMS records not aligned with statutory minima
- Access to PIMS documentation not restricted on need-to-know basis
- No master index of PIMS documented information
Monitor and measure PIMS performance and effectiveness of privacy controls.
- Metric reports, control effectiveness analysis
- No defined privacy KPIs (DSAR turnaround, breach MTTR, training completion)
- Measurement results not reported to top management
- Data sources for privacy metrics not validated
- No trend analysis across reporting periods
Conduct internal audits at planned intervals to confirm PIMS conforms to requirements and is effectively implemented.
- Auditor independence and competence records
- No risk-based internal audit programme covering all PIMS clauses on a defined cycle
- Auditor independence from PII processing activities not demonstrated
- Audit findings not tracked to remediation closure with evidence
- Results of internal audits not reviewed by top management
Top management reviews the PIMS at planned intervals, including privacy-specific inputs and outputs.
- Decisions and action items with owners
- Management review agenda does not cover all required inputs (audits, incidents, DSARs, changes)
- Review frequency not defined or not adhered to
- Review outputs not converted into actions with owners and dates
- No retention of management review minutes meeting record requirements
React to PIMS nonconformities, evaluate causes, implement corrective actions, and verify effectiveness.
- Root cause analyses and effectiveness verifications
- Nonconformities not formally logged with classification and severity
- Root cause analysis not performed for repeat privacy issues
- Corrective actions not verified for effectiveness
- Trend analysis across nonconformities not performed
Supplier agreements that involve PII processing include specific privacy clauses (purposes, security, sub-processors, return/deletion).
- Executed DPAs with PII-processing suppliers
- Supplier register flagged for PII
- Standard supplier contract template does not include all required PII processing clauses
- Sub-processor approval and notification clauses missing
- Audit and inspection rights not included in agreements
- Contract clauses not updated when applicable law changes
Incident management procedures address privacy incidents, including breach assessment, notification, and recordkeeping.
- Incident register
- Sample notifications to regulators and data subjects (redacted)
- No documented privacy incident playbook distinct from security incident response
- Notification timelines for regulators and principals not codified per jurisdiction
- Incident log does not capture PII categories, volume, and affected principals
- Lessons learned from privacy incidents not fed back into the PIMS
Identify and document all applicable privacy laws, regulations, and contractual requirements for each jurisdiction of operation.
- Legal monitoring service subscriptions or counsel engagement records
- No maintained register of applicable privacy legislation by jurisdiction
- Legislative changes not tracked and assessed for impact
- Sector-specific privacy obligations (health, finance, children) not separated out
- Cross-border transfer rules not mapped to current processing flows
Information security policies are extended to include privacy of PII; reviewed and approved by management.
- Approval and review records
- Information security policies do not explicitly address PII protection
- Privacy-specific policy statements not approved by the same authority as security policies
- No cross-reference between security and privacy policy documents
- Policies not reviewed after major privacy regulatory change
Information classification scheme identifies and labels PII, including special categories of PII.
- Examples of classified datasets and labels
- PII not separately classified from general confidential information
- No labelling scheme for sensitive PII categories
- Classification scheme not applied consistently in data stores and exports
- Reclassification triggers (consent withdrawal, anonymisation) not defined
Procedures for removable media handling explicitly address PII, including encryption and disposal.
- Media inventory and disposal records
- No prohibition or controls on storing PII on removable media
- Cryptographic protection of PII on removable media not enforced
- Inventory of removable media containing PII not maintained
- Disposal records for removable media holding PII not retained
Logs of access to and processing of PII are generated, protected, and reviewed.
- Sample logs, log review records, retention configuration
- Access to PII not logged at the user and record level
- Log retention period for PII access not aligned with legal requirements
- Logs not reviewed for anomalous access to PII
- Log integrity protection (tamper evidence) not in place
PII Controller
Where the organization is a joint controller, determine respective responsibilities through an agreement.
- Executed joint controller agreements
- Essence-of-agreement notice made available to data subjects
- Joint controller arrangements not documented in writing
- Allocation of responsibilities not made available to PII principals
- Single point of contact for principal rights not designated
- No periodic review of joint controller arrangements
Maintain records of PII processing activities (RoPA) including purposes, categories, recipients, retention, and security measures.
- Up-to-date RoPA entries with owner, lawful basis, retention
- No central ROPA maintained for controller activities
- ROPA does not include retention periods and cross-border transfers
- ROPA not updated when processing activities change
- ROPA not provided to supervisory authorities on request
Define and document PII minimization objectives, including de-identification and deletion of unnecessary PII.
- De-identification or deletion job logs
- No defined PII minimisation objectives by processing activity
- Fields collected exceed what is necessary for stated purposes
- No periodic review to remove unnecessary PII fields
- Minimisation not enforced through system design and validation
De-identify or delete PII as soon as the original purpose has expired, unless legally required to retain.
- Deletion job logs with certificates
- No standard for when PII must be de-identified or deleted at end of processing
- De-identification techniques not tested for re-identification risk
- Deletion not enforced across backups and replicas
- No evidence retained of deletion or anonymisation events
Ensure temporary files containing PII are erased or destroyed in line with documented retention rules.
- System configurations for auto-purge
- Sample logs of temp file cleanup
- Temporary files containing PII not identified and inventoried
- No automated cleanup of temporary PII files
- Temporary file locations not access-controlled
- No monitoring of temporary file growth or persistence
Determine and document retention periods for each category of PII based on purpose and legal requirements.
- Retention configurations in systems
- Disposal certificates
- Retention schedule does not cover every PII category and processing purpose
- Legal hold process does not interact correctly with privacy retention
- Retention rules not enforced in production systems
- No periodic review and disposition of expired PII
Dispose of PII securely when no longer required, using methods appropriate to the media.
- Certificates of destruction
- Sanitization logs
- Secure disposal procedures for PII media and devices not defined
- Certificates of destruction not retained
- Disposal not verified for cloud and SaaS data stores
- Third-party disposal vendors not contractually bound to PII standards
Ensure PII transmitted over networks is protected with appropriate controls (encryption, integrity).
- TLS configurations, encryption key inventories
- Pen test results on transmission
- PII transmission channels not inventoried with associated cryptographic protections
- Cross-border transfers not assessed against legal transfer mechanisms
- No detection for PII leaving the environment through unsanctioned channels
- Transmission controls not tested after infrastructure change
PII Processor
Engage sub-contractors only with written authorization from the customer and impose equivalent contractual privacy obligations.
- Executed sub-processor DPAs
- Customer authorization records
- No documented process to obtain controller authorisation before engaging a sub-processor
- Sub-processor due diligence not performed or recorded
- Flow-down of controller instructions to sub-processors not evidenced
- Sub-processor list not provided to controllers on request
Inform customers of any intended changes to sub-contractors so they can object.
- Notification records, objection handling logs
- No mechanism to notify controllers of intended sub-processor changes
- Notice period for sub-processor changes shorter than contractual minimum
- No process to handle controller objections to sub-processor changes
- Records of sub-processor changes and approvals not retained
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.