Extend ISO 27001 into a certified privacy programme
Comply turns your existing ISO 27001 ISMS into an ISO 27701 privacy information management system — PII controls, roles and evidence mapped to the work you have already done.
Typical readiness: 4–8 weeks on top of an existing ISO 27001 ISMS
What it is
ISO/IEC 27701 is the privacy extension to ISO 27001. It defines a Privacy Information Management System (PIMS) by adding privacy-specific requirements and controls for organisations acting as PII controllers and PII processors. Because it builds directly on an existing ISO 27001 ISMS, it cannot be certified in isolation — you certify the two together or extend an existing ISO 27001 certificate.
Who needs it
Organisations that already hold or are pursuing ISO 27001 and want to demonstrate strong privacy governance — useful for showing alignment with GDPR, DPDP and other privacy laws to customers and regulators.
Get ISO 27701-ready, then stay that way
Connect your stack, map controls once, and let continuous monitoring keep evidence fresh — across every framework you run.
Built on your ISMS
Comply layers the ISO 27701 PIMS requirements directly onto your ISO 27001 ISMS, so you extend what exists rather than building a parallel system.
PII controller & processor controls
The Annex A and Annex B controls for controllers and processors are pre-loaded and mapped to automated evidence from your connected stack.
Maps to GDPR and DPDP
ISO 27701 controls line up with GDPR and India's DPDP obligations, so one privacy control set supports your certification and your regulatory compliance at once.
Privacy roles & documentation
Capture controller and processor roles, processing records and privacy policies as living documentation an auditor can follow.
Continuous evidence
Pull live evidence from 30+ connectors, with a no-code builder for custom systems, so your PIMS stays audit-ready rather than point-in-time.
One audit, two standards
Certify ISO 27001 and ISO 27701 together from a single evidence room, then maintain both through the same surveillance cycle.
Privacy certification, built on what you have
If you have done the hard work of an ISO 27001 ISMS, ISO 27701 should be an extension, not a restart. Comply makes it exactly that:
- Layer the PIMS requirements onto your existing ISO 27001 management system.
- Implement controller and processor controls as automated, evidenced checks.
- Map every privacy control to GDPR and DPDP so certification advances compliance too.
- Certify both standards from one evidence room and maintain them on one cycle.
Because ISO 27701 shares Comply’s evidence engine, your security and privacy programmes finally run as one — not two teams chasing overlapping artefacts.
ISO 27701 questions, answered
No — ISO 27701 is an extension that requires an ISO 27001 ISMS as its foundation. You either certify both together or add 27701 to an existing 27001 certificate. Comply manages both from one control set so the extension is straightforward.
ISO 27701 is a certifiable framework whose controls map closely to GDPR and DPDP obligations. It does not replace those laws, but demonstrating 27701 is strong evidence of privacy governance. Comply maps all three so your certification work also advances regulatory compliance.
Much less than starting fresh. Because the PIMS sits on top of your ISMS, Comply reuses your existing controls and evidence and adds only the privacy-specific pieces — most teams reach readiness in 4 to 8 weeks.
Comply gets you audit-ready and hands your certification body a clean, mapped evidence room covering both ISO 27001 and ISO 27701. The certificate itself is issued by the accredited body.
Yes for most teams — a separate privacy tool means a separate control set and duplicate evidence. Comply runs ISO 27701 alongside your security frameworks, GDPR and DPDP in one platform, so privacy is part of the same programme, not a silo.
One platform, every framework
Comply maps a single control set across all of these — add a framework without adding work.
Start your ISO 27701 program free
Start free in minutes, or get a guided demo. No credit card, no per-seat surprises.
Free tier: 1 framework · 10 workers · 2 connectors. Upgrade only when you grow.