Details

Privacy Information Security Management System Certification

ISO/IEC 27701:2019

01

Service Introduction

Privacy information security management system certification is an authoritative evaluation mechanism for organizations to establish, implement, maintain and continuously improve their privacy information management capabilities. It aims to help organizations systematically manage the privacy risks of personally identifiable information (PII) through a standardized framework and ensure compliance with global privacy regulations. Certification is finally awarded to the organization with a certificate valid for three years, which is usually jointly reviewed with ISO/IEC 27001 and issued with a comprehensive certificate.

Certification core content

The authentication of the information security system of private information revolves around the systematic management of the whole life cycle of PII, with the following dimensions as the core:

Basic information security management system: Establish a complete information security management system (ISMS) according to ISO/IEC 27001, including organizational environment analysis, leadership role and commitment, information security policy, risk assessment and disposal, resource guarantee, internal audit and management review, and continuous improvement mechanism.

Organizational governance: set up a data protection officer (DPO), define the division of privacy protection responsibilities, establish a privacy protection policy framework, and determine the scope of privacy information management system.

Privacy risk management: identify the risks of personal information in the whole life cycle (collection, storage, use, transmission and destruction), carry out data protection impact assessment (DPIA), and establish a supplier privacy risk control mechanism.

Specific requirements for PII handling: PII controller requirements: consent management, data subject rights response (access, correction, deletion, objection), privacy design, data leakage notification, cross-border transmission compliance PII processor requirements: handling according to the controller's instructions, assisting the controller to fulfill its obligations, contract agreement management, and sub-processor control.

Implementation of control measures: covering privacy-specific control measures, including access control, data minimization, storage restriction, encryption and desensitization, privacy policy and notification, and data processing record retention.

Compliance management: identify global privacy laws and obligations (such as GDPR, CCPA and China's Personal Information Protection Law), establish a consent management mechanism, realize the rights flow of data subjects, and standardize the signing of data processing agreement (DPA).

Continuous improvement mechanism: internal audit mechanism, response and rectification of privacy incidents, optimization of management review and dynamic adjustment of control measures.

Certification process

Privacy information security management system certification is usually divided into the following stages:

Pre-preparation stage: Enterprises need to establish an information security management system (ISMS) that meets the requirements of ISO/IEC 27001, and expand the privacy requirements of ISO/IEC 27701 on this basis. The system has been in operation for more than 3 months and completed at least one internal audit and management review.

Application and acceptance: submit application materials (business license, system documents, applicability statement SoA, privacy impact assessment report, internal audit/management review records, etc.), and the certification body will conduct application review to confirm that the organization has the basic conditions for certification.

First-stage audit (document audit): conduct document audit and on-site preparation evaluation, review the compliance of the documents of the privacy information management system with the standard requirements, and confirm the adequacy of the second-stage audit preparation.

The second stage of audit (on-site audit): conduct on-site audit, including personnel interviews, file records inspection, effectiveness verification of privacy control measures (such as consent management, data subject rights response, data leakage emergency mechanism, cross-border transmission compliance, etc.), evaluate the compliance and effectiveness of the system, and identify nonconformities.

Rectification and review: for the nonconformities found in the audit, the organization shall complete the rectification within the specified time limit (usually within 30 days) and submit the evidence, which will be reviewed by the audit team.

Certification decision and certification: Certification certificate will be issued after the technical review, which confirms that the organization meets the requirements of ISO/IEC 27701 standard. The certificate is valid for three years and can be found on the website of CNCA.

Supervision and audit: conduct supervision and audit once a year after obtaining the certificate (the interval shall not exceed 12 months) to confirm that the system continues to meet the certification requirements.

Re-certification audit: Re-certification audit is conducted before the certificate expires, and the certification qualification is extended, usually for three years.

Certification value

Improve the ability of privacy risk management: systematically identify and manage personal information processing risks, establish a sound risk assessment and emergency response mechanism, reduce the probability of privacy leakage incidents and reduce the average cost of data leakage (certified enterprises can reduce the risk of violation by 40%).

Enhance market competitiveness: Certified enterprises can show their commitment and ability in privacy protection to customers and partners, and have obvious advantages in bidding and supply chain access, and the customer acquisition rate can be increased by 27%.

Meet global regulatory compliance requirements: Help organizations meet the requirements of 50+ global privacy regulations such as GDPR, CCPA and China Personal Information Protection Law, reduce the penalty risk of 4% of annual revenue, and reduce the preparation time for regulatory inspection by 65%.

Enhance customer trust and brand reputation: through independent third-party certification, prove to stakeholders that the organization has sound privacy protection measures, and enhance the trust of customers, partners and regulatory agencies.

Reduce operating costs: seamlessly integrate with ISO/IEC 27001 to reduce management complexity and repeated investment; By optimizing resource allocation through systematic management, the average loss related to data leakage was saved by $2.8 million.

Promote business expansion: provide general guidelines covering different countries, remove obstacles to cross-border business compliance, and facilitate business development and the opportunity to be the preferred supplier on a global scale.

Enhance employees' privacy awareness: through training and education, strengthen employees' information security awareness, standardize the organization's information security behavior, and reduce the loss of privacy disclosure caused by human factors.

03

Service Process

04

Rules File

Need this certification?

Contact us