Skip to Content

Security & Compliance

Lynx Compliance - ISO/IEC 27701 (PIMS)

ISO/IEC 27701:2019 Privacy Information Management as a certifiable extension to ISO 27001, with separate controller and processor control sets and cross-references to GDPR and Law 25.

lynx_compliance_iso27701 · v19.0.1.0.0 · Add-on Beta

What this solves

Lynx Compliance - ISO/IEC 27701 (PIMS)

ISO/IEC 27701 is the privacy extension to ISO 27001. It is not a standalone standard: it is certifiable only alongside a valid 27001 certificate, and its two Annex control sets apply according to whether the organisation acts as a PII controller, a PII processor, or both.

This pack keeps that split visible rather than merging the annexes, so a processor is not assessed against controller obligations it does not hold and cannot satisfy.

It also adds the iso_27701_refs cross-reference field to compliance.control. Three manifests in this repo already advertised ISO 27701 cross-references and no such field existed, so those claims were false until now. Unlike some sub-module reference fields, this one is registered in the base propagation tuple, so a reference to it actually crosswalks rather than merely incrementing a coverage count.

Key Features

  • 55 controls - the PIMS requirement clauses plus Annex A (controller) and Annex B (processor), under the standard's own numbering.

  • Controller and processor kept apart - separate functions, so applicability is a structural property rather than a note in the guidance.

  • GDPR and Law 25 references on every control - a privacy programme assessed once against either regime propagates into the PIMS assessment through the crosswalk.

  • The iso_27701_refs field, wired for propagation - added to the base ref_fields tuple and to the cross-framework coverage export, so it behaves like a first-class mapping rather than a decorative column.

  • Evidence guidance naming the privacy registers - DSAR requests, consent records, processing activities, cross-border transfers and the subprocessor map.

  • Annex clause families drive the guidance - because that is how the standard groups obligations and how an auditor samples them.

Integrates With

  • lynx_compliance_certification - 27701 extends ISO 27001; the Annex A controls of 27001 are referenced throughout.

  • lynx_compliance_privacy - the DSAR, consent, PIA and breach registers are the evidence for most of Annex A.

  • lynx_compliance_gdpr and lynx_compliance_law25 - cross-referenced per control, so one privacy programme answers all three.

Try Lynx Compliance - ISO/IEC 27701 (PIMS) on your team.

Free trial, no credit card. Talk to sales when you're ready.