ISO/IEC 27701:2019
What is ISO/IEC 27701:2019?
ISO/IEC 27701:2019 is a privacy extension to ISO/IEC 27001 and ISO/IEC 27002, providing requirements and guidance for establishing, maintaining, and continually improving a Privacy Information Management System (PIMS).. It comprises 38 controls organised across 3 domains, published by ISO/IEC, and applies in International.
How ISO/IEC 27701:2019 maps to other frameworks
All 38 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 3 domains ISO/IEC 27701:2019 groups its controls into
Where ISO/IEC 27701:2019 overlaps with the standards you already hold
Where to get trained on ISO/IEC 27701:2019
One course in the catalogue covers ISO/IEC 27701:2019 directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What ISO/IEC 27701:2019 means in your sector
What ISO/IEC 27701:2019 means for your job
Questions people ask about ISO/IEC 27701:2019
What is ISO/IEC 27701:2019?
How many controls does ISO/IEC 27701:2019 have?
Where does ISO/IEC 27701:2019 apply?
What frameworks does ISO/IEC 27701:2019 map to?
How do I get started with ISO/IEC 27701:2019 compliance?
Query ISO/IEC 27701:2019 programmatically
ISO/IEC 27701:2019, its 38 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
ISO/IEC 27701:2019 API reference and MCP config →What ISO/IEC 27701:2019 requires, control by control
Each page carries the requirement text for one ISO/IEC 27701:2019 control and what an assessor expects to see as evidence.
- 5-1 General
- 5-2-1 Understanding the organization and its context
- 5-2-2 Understanding the needs and expectations of interested parties
- 5-2-3 Determining the scope of the information security management system
- 5-2-4 Information security management system
- 5-3-1 Leadership and commitment
- 5-3-2 Policy
- 5-3-3 Organizational roles, responsibilities and authorities
- 5-4-1 Actions to address risks and opportunities
- 5-4-2 Information security objectives and planning to achieve them
How much of another standard ISO/IEC 27701:2019 already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- APEC Cross-Border Privacy Rules (CBPR) System to ISO 27701:2019 crosswalk
- APPI to ISO 27701:2019 crosswalk
- Australia Consumer Data Right - Banking (CDR) to ISO 27701:2019 crosswalk
- ISO 27701:2019 to Australian Privacy Principles (APPs) crosswalk
- AWS Well-Architected Security Pillar to ISO 27701:2019 crosswalk
- Azure Security Benchmark to ISO 27701:2019 crosswalk
- C5 (Germany) to ISO 27701:2019 crosswalk
- CCPA/CPRA to ISO 27701:2019 crosswalk
How ready are you for ISO/IEC 27701:2019?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.