Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Governance, Risk & Compliance

ISO 27701: privacy you can put a certificate against.

ISO 27701 privacy information management is the answer to a problem every privacy team eventually hits: data protection law tells you what outcome is required and gives you no certifiable way to prove you achieve it. There is no GDPR certificate. ISO 27701 is the closest thing to one.

It extends ISO 27001:2022 into a privacy information management system, the same governance machinery of scope, risk, objectives, internal audit and management review, applied to personal data, with additional guidance for organisations acting as controllers and for those acting as processors. The mapping annexes to GDPR and other regimes are what make it commercially useful.

In practice it turns privacy from a legal position into an operating system: records of processing that stay current, privacy impact assessments that happen before launch, data subject rights served on a clock, and evidence produced continuously. It sits directly alongside GDPR and DPDP Act programmes rather than replacing them.

Why you need it

01 / 06

Why a privacy management system.

01

Accountability has to be demonstrable.

Both GDPR and the DPDP Act require you to show compliance, not merely achieve it. A management system produces that evidence as a by-product of running, instead of as a reconstruction exercise when a regulator or a customer asks.

02

Privacy work drifts without a cadence.

Records of processing go stale, impact assessments get skipped under delivery pressure, and retention schedules exist as a document nobody executes. The audit and review cycle is what keeps the programme honest between incidents.

03

One system covers several regimes.

The standard maps to GDPR and can be extended to the DPDP Act, and to sector rules. Organisations operating across India, the EU and elsewhere would otherwise run parallel programmes over the same data.

04

Customers ask for privacy assurance specifically.

Security certification does not answer privacy questions. A certified PIMS with a clear scope answers them with a document instead of a lengthy questionnaire.

Instrument

02 / 06

Where privacy and security controls overlap.

A PIMS reuses most of an ISMS. Toggle the regimes you are asked for and see how much of the work is shared.

What we deliver

03 / 06

What we deliver.

01

Privacy gap analysis

Your existing ISMS and privacy practice measured against ISO 27701, with the controller and processor guidance applied according to the roles you actually hold. Delivered as a gap register with effort and sequence.

02

PIMS scope and roles

The boundaries of the privacy management system, and a clear determination of where you act as controller, where as processor and where as both, because the obligations, and the applicable annex, differ substantially.

03

Records of processing and data mapping

A complete inventory of processing activities: what data, from whom, on what lawful basis, for what purpose, shared with whom, held how long, and where it physically sits. Built to be maintained rather than produced once for an audit.

04

Privacy controls implementation

Privacy by design in the delivery process, impact assessments triggered by defined criteria, consent and preference management, retention and deletion actually executed, and the security controls the privacy risk assessment selects.

05

Data subject rights operations

Working procedures for access, correction, erasure, portability, objection and grievance redressal, with identity verification, internal routing, statutory deadlines tracked and responses evidenced.

06

Audit preparation and certification

Internal audit against the extended scope, management review, corrective action, and support through the certification body's assessment alongside your ISO 27001:2022 audit.

How we run it

04 / 06

Six stages.

  1. 01

    Assess current privacy framework

    Gap analysis of the existing ISMS and privacy practice against ISO 27701 requirements, credited against what ISO 27001:2022 already covers so the incremental work is visible.

    Weeks 1-3
  2. 02

    Define scope and privacy objectives

    PIMS boundaries, controller and processor roles per processing activity, interested parties and their expectations, and measurable privacy objectives.

    Weeks 3-4
  3. 03

    Implement privacy controls

    The controls the privacy risk assessment selects, across the lifecycle: collection and lawful basis, minimisation, security, sharing and transfers, retention and deletion.

    Months 1-5
  4. 04

    Develop privacy policies

    Internal policies and procedures, plus the external-facing privacy notices, consent mechanisms and processing agreements that have to be consistent with them.

    Months 2-5
  5. 05

    Training and awareness

    Role-specific training: marketing, engineering, HR, support and procurement each handle personal data differently, and generic privacy training reliably fails to change what any of them do.

    Month 5
  6. 06

    Internal audit and certification

    Internal audit, management review, corrective action, and the certification body's assessment of the extended scope.

    Months 6-8

Key benefits

05 / 06

What changes after.

Privacy becomes evidenced, not asserted

Records of processing, impact assessments, rights requests and retention actions all generate dated evidence as they run, which is exactly what accountability requires.

Several regimes are answered at once

One control set mapped across GDPR, the DPDP Act and customer requirements, so obligations that overlap are satisfied by the same work.

Rights requests stop being a scramble

Defined procedures, routing and deadline tracking mean a data subject request is a process rather than an interruption to someone's week.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Standards

  • ISO/IEC 27701
  • ISO/IEC 27001:2022
  • ISO/IEC 27018
  • ISO/IEC 29100

Privacy operations

  • Records of processing activities
  • DPIA / PIA methodology
  • Consent and preference register
  • Retention schedule

Rights handling

  • Data subject request workflow
  • Identity verification procedure
  • Grievance redressal process

Evidence

  • AphelioNYX Compliance Hub
  • Access review workflows
  • Deletion and disposal logs

Mapping

  • GDPR
  • DPDP Act, 2023
  • ISO 27001:2022 Annex A

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about ISO 27701.

Do we need ISO 27001 before we can do this?
Yes. ISO 27701 is an extension and cannot be certified alone. If you are not certified, run one combined programme building the ISMS and the PIMS together; the overlap in risk assessment, governance, internal audit and management review is large enough that doing them separately roughly doubles the effort. If you are already certified, this is an extension of scope at your next audit.
Does certification make us GDPR compliant?
It gets you a long way and it is not a legal certification of compliance. No such thing exists under GDPR. The standard maps its controls to GDPR articles, so certification demonstrates that the operational machinery for accountability is in place and working. Legal determinations such as lawful basis, legitimate interest assessments and transfer mechanisms still require legal judgement, which we work alongside rather than replace.
Are we a controller or a processor?
Usually both, in different processing activities, and getting this right per activity is one of the more consequential parts of scoping. You are a controller for your own employee and customer data. You decide why and how it is processed. You are a processor for data your customers put into your product, where they decide. The standard has separate guidance for each role, and the obligations differ substantially.
Does it cover the DPDP Act?
Not natively. The annexes map to GDPR and to ISO privacy frameworks, not to Indian law specifically. But the management system is regime-agnostic and extends cleanly: DPDP Act duties around notice, consent, data principal rights, grievance redressal and breach reporting are added as additional control requirements within the same PIMS. Organisations operating in both India and the EU get most of the benefit from one system.
How long does it take?
Four to eight months as an extension to an existing certification, and nine to fifteen months when built together with ISO 27001:2022 from scratch. The single largest variable is the records of processing: organisations that already know what personal data they hold and where it goes move quickly, and those that do not spend most of the programme finding out, which is uncomfortable and is also the most valuable part.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.