Skip to content

ISO 27701 Personal Data Management

This service is linked to the UN Sustainable Development Goals (SDGs).

The international standard ISO/IEC 27701:2019 is an extension of ISO 27001 and ISO 27002 and was designed to strengthen the existing information security management system with additional requirements to develop a comprehensive Information Security and Privacy Management System.

The requirements

ISO 27701 defines the requirements for the management of personal data and provides guidelines for data controllers and processors of personal data.

It applies to all organizations that wish to ensure, in addition to information security, the protection of personal data of their employees, customers and partners. Already, in our country, a relevant institutional framework has been put in place for its mandatory application in the education sector, which is expected to be extended to other sectors of activity.

It is stressed that in order for a company to be certified to ISO 27701, it must already be certified to ISO 27001 or opt for parallel certification to both standards.

The benefits

Certification against the above international standards demonstrates your organisation's commitment:

  • To the implementation of policies that ensure the integrity, confidentiality and availability of information
  • To your full compliance with the current legislative requirements for personal data management (GDPR - General Data Protection Regulation).

TÜV NORD Greece (TÜV NORD), accredited for all its services, with more than 10,000 certified Management Systems, with experienced and qualified inspectors, is able to successfully guide you to ISO 27001 and ISO 27701 certification.

Certification to these international standards demonstrates an organisation's commitment:

  • To implementing policies that ensure the integrity, confidentiality and availability of information; and
  • To full compliance with the current legislative requirements for personal data management (GDPR - General Data Protection Regulation).

It is emphasized that in order for an organization to be certified to ISO 27701, it must already have ISO 27001 certification or choose to be certified to both standards in parallel. It can be combined with all ISO international standards, e.g. for quality (ISO 9001), business continuity (ISO 22301) and organisational resilience (ISO 22316).