International

ISO/IEC 27701:2025

117 controls. 0 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

117 controls 0 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

No measured overlap with another framework in the corpus.

Every control

CodeControlAlso in
10.1Continual improvement0
10.2Nonconformity and corrective action0
11Further information on annexes0
4.1Understanding the organization and its context0
4.2Understanding the needs and expectations of interested parties0
4.3Determining the scope of the privacy information management system0
4.4Privacy information management system0
5.1Leadership and commitment0
5.2Privacy policy0
5.3Roles, responsibilities and authorities0
6.1Actions to address risks and opportunities0
6.1.2Privacy risk assessment0
6.1.3Privacy risk treatment0
6.2Privacy objectives and planning to achieve them0
6.3Planning of changes0
7.1Resources0
7.2Competence0
7.3Awareness0
7.4Communication0
7.5Documented information0
7.5.2Creating and updating documented information0
7.5.3Control of documented information0
8.1Operational planning and control0
8.2Privacy risk assessment0
8.3Privacy risk treatment0
9.1Monitoring, measurement, analysis and evaluation0
9.2Internal audit0
9.2.2Internal audit programme0
9.3Management review0
9.3.2Management review inputs0
9.3.3Management review results0
A.1.2Conditions for collection and processing0
A.1.2.2Identify and document purpose0
A.1.2.3Identify lawful basis0
A.1.2.4Determine when and how consent is to be obtained0
A.1.2.5Obtain and record consent0
A.1.2.6Privacy impact assessment0
A.1.2.7Contracts with PII processors0
A.1.2.8Joint PII controller0
A.1.2.9Records related to processing PII0
A.1.3Obligations to PII principals0
A.1.3.10Handling requests0
A.1.3.11Automated decision making0
A.1.3.2Determining and fulfilling obligations to PII principals0
A.1.3.3Determining information for PII principals0
A.1.3.4Providing information to PII principals0
A.1.3.5Providing mechanism to modify or withdraw consent0
A.1.3.6Providing mechanism to object to PII processing0
A.1.3.7Access, correction or erasure0
A.1.3.8PII controllers' obligations to inform third parties0
A.1.3.9Providing copy of PII processed0
A.1.4Privacy by design and privacy by default0
A.1.4.10PII transmission controls0
A.1.4.2Limit collection0
A.1.4.3Limit processing0
A.1.4.4Accuracy and quality0
A.1.4.5PII minimization objectives0
A.1.4.6PII de-identification and deletion at the end of processing0
A.1.4.7Temporary files0
A.1.4.8Retention0
A.1.4.9Disposal0
A.1.5PII sharing, transfer and disclosure0
A.1.5.2Identify basis for PII transfer between jurisdictions0
A.1.5.3Countries and international organizations to which PII can be transferred0
A.1.5.4Records of transfer of PII0
A.1.5.5Records of PII disclosures to third parties0
A.2.2Conditions for collection and processing0
A.2.2.2Customer agreement0
A.2.2.3Organization’s purposes0
A.2.2.4Marketing and advertising use0
A.2.2.5Infringing instruction0
A.2.2.6Customer obligations0
A.2.2.7Records related to processing PII0
A.2.3Obligations to PII principals0
A.2.3.2Comply with obligations to PII principals0
A.2.4Privacy by design and privacy by default0
A.2.4.2Temporary files0
A.2.4.3Return, transfer or disposal of PII0
A.2.4.4PII transmission controls0
A.2.5PII sharing, transfer and disclosure0
A.2.5.2Basis for PII transfer between jurisdictions0
A.2.5.3Countries and international organizations to which PII can be transferred0
A.2.5.4Records of PII disclosures to third parties0
A.2.5.5Notification of PII disclosure requests0
A.2.5.6Legally binding PII disclosures0
A.2.5.7Disclosure of subcontractors used to process PII0
A.2.5.8Engagement of a subcontractor to process PII0
A.2.5.9Change of subcontractor to process PII0
A.3.10Addressing information security within supplier agreements0
A.3.11Information security incident management planning and preparation0
A.3.12Response to information security incidents0
A.3.13Legal, statutory, regulatory and contractual requirements0
A.3.14Protection of records0
A.3.15Independent review of information security0
A.3.16Compliance with policies, rules and standards for information security0
A.3.17Information security awareness, education and training0
A.3.18Confidentiality or non-disclosure agreements0
A.3.19Clear desk and clear screen0
A.3.20Storage media0
A.3.21Secure disposal or re-use of equipment0
A.3.22User endpoint devices0
A.3.23Secure authentication0
A.3.24Information backup0
A.3.25Logging0
A.3.26Use of cryptography0
A.3.27Secure development life cycle0
A.3.28Application security requirements0
A.3.29Secure system architecture and engineering principles0
A.3.3Policies for information security0
A.3.30Outsourced development0
A.3.31Test information0
A.3.4Information security roles and responsibilities0
A.3.5Classification of information0
A.3.6Labelling of information0
A.3.7Information transfer0
A.3.8Identity management0
A.3.9Access rights0

Tell me when ISO/IEC 27701:2025 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Nonconformity and corrective action records with cause analysis
  • Effectiveness reviews of corrective actions
  • Changes to the ABMS resulting from corrective action
  • Changes to the PIMS resulting from corrective action
  • Evidence the register considers climate-related expectations
  • Register of interested parties with their anti-bribery requirements
  • Decision on which requirements the ABMS addresses
  • Register of interested parties with the privacy requirement each imposes
  • PII principals listed as an interested party with their rights and expectations recorded
  • Decision on which requirements the PIMS addresses

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 27701:2025, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition