{"id":8642,"date":"2023-02-27T08:40:14","date_gmt":"2023-02-27T08:40:14","guid":{"rendered":"https:\/\/www.imsm.com\/us\/?p=8642"},"modified":"2023-02-27T08:40:14","modified_gmt":"2023-02-27T08:40:14","slug":"what-is-iso-27701-and-do-i-need-a-privacy-extension","status":"publish","type":"post","link":"https:\/\/www.imsm.com\/us\/news\/what-is-iso-27701-and-do-i-need-a-privacy-extension\/","title":{"rendered":"What is ISO 27701, and do I need a privacy extension?"},"content":{"rendered":"

As the digital world transforms before our eyes, so are the ways companies are operating and conducting business. As times change and technology is developed, more and more companies are inquiring about additions to their information security management systems (ISMS) to ensure optimum security of their customers data.<\/p>\n

As protecting data is at the forefront of most businesses, ISO\/IEC 27001<\/a> has gained lots of interest in recent years. Seen as a ‘gold standard’ for security frameworks, ISO\/IEC 27001<\/a> is an excellent foundation for creating an ISMS. However, lately we have seen clients wanting to go a step further and invest in enhanced privacy by adding a privacy extension through ISO\/IEC 27701<\/a>.<\/p>\n

ISO\/IEC 27701<\/a> was published in 2019 and is a privacy extension that allows you to extend your current system to include a privacy information management system (PIMS).<\/p>\n

Do I need a Privacy Information Management System (PIMS)?<\/h2>\n

A survey by Acquia discovered that: “65% of respondents would cease using a company that was dishonest about how it was using their data<\/a>“.<\/p>\n

With so many data breaches and hacker attacks in the news, it’s no wonder customers are growing more aware and concerned about how their personal data is being used. Not to mention with mandatory requirements, such as GDPR<\/a>, protecting personally identifiable information (PII) has never been more critical.<\/p>\n

Adding a privacy extension is the most appropriate way to show clients, regulators, and other stakeholders that you have a robust privacy program. Demonstrating compliance with privacy regulations may boost revenue and increase trust within consumers.<\/p>\n

\"Download<\/a><\/figure>\n

Why was ISO\/IEC 27701 developed?<\/h2>\n

As a type of privacy information management system (PIMS), ISO\/IEC 27701<\/a> creates a framework for privacy controls. This PIMS is an extension to ISO\/IEC 27001<\/a> and can be implemented alongside the ISO\/IEC 27001<\/a> standard or after you are ISO\/IEC 27001<\/a> certified.<\/p>\n

The primary purpose of ISO\/IEC 27701<\/a> is to:<\/p>\n