ISO 27701 consulting services

ISO/IEC 27701:2025 Consulting Service

Implementation of a Privacy Information Management System (PIMS)

We provide a comprehensive consulting service for implementing ISO/IEC 27701:2025, the international standard for managing personal data through a Privacy Information Management System (PIMS).

The service is intended for organisations seeking to:

  • manage personal data effectively
  • achieve compliance with the GDPR and other regulations
  • reduce the risk of incidents and penalties
  • successfully complete certification

ISO/IEC 27701:2025 is now a standalone standard and can be implemented independently of other management systems. The previous edition, ISO/IEC 27701:2019, required ISO/IEC 27001 to be implemented first. This is no longer the case with ISO/IEC 27701:2025, which is treated as an independent management system standard.

Evaluation

At this stage, we assess the organisation's current state:

  • analysis of the personally identifiable information (PII) processed
  • definition of roles (controller/processor)
  • assessment of conformity with ISO/IEC 27701:2025
  • gap analysis against the requirements of the standard
  • assessment of privacy-related risks

Objective: identify the gaps and define a clear implementation plan.

Design

We design the PIMS framework:

  • definition of the system scope
  • development of policies and procedures
  • development of a risk assessment methodology
  • selection of controls
  • development of a governance structure and assignment of responsibilities

This stage covers the requirements in Clauses 4-10.

Implementation

We put the developed policies and controls into practice:

  • implementation of personal data management processes
  • application of technical and organisational measures (TOMs)
  • creation of records and registers, such as a RoPA and risk register
  • integration with existing systems
  • delivery of training and awareness activities

Focus: the system must operate in practice, not merely exist as documentation.

Operation

We support the resilience and effectiveness of the system through:

  • ongoing monitoring of controls
  • incident and breach management
  • third-party management
  • ongoing regulatory compliance
  • management of risks and related actions

ISO/IEC 27701:2025 requires the system to operate as a complete, end-to-end process rather than as a one-off implementation project.

Testing and audit preparation

We prepare the organisation for successful certification through:

  • an internal audit
  • management review
  • verification of evidence, including documentation, records and practical implementation
  • preparation for the Stage 1 and Stage 2 audits

The audit is evidence-based. Relevant evidence includes:

policies and procedures records and logs practical application of the processes

Our approach

We work closely with the client and:

  • adapt the system to actual business processes
  • avoid a template-driven approach
  • build an effective and sustainable system
  • prepare the organisation for an actual audit

The result

After implementing ISO/IEC 27701:2025, your organisation will:

  • have an operational PIMS
  • manage personal data effectively
  • demonstrate GDPR compliance
  • be prepared for the certification audit
  • increase the confidence of customers and partners

How can we help?

We provide:

  • end-to-end implementation of ISO/IEC 27701:2025
  • gap analysis and risk assessment
  • development of documentation
  • internal audits
  • preparation for certification
  • ongoing support

How can IS Consult Service help?

We provide audit, training and consulting services, including ISO/IEC 27701 implementation services. We can integrate ISO/IEC 27701:2025 with ISO/IEC 27001:2022 or implement it independently where no ISO/IEC 27001:2022 certificate is in place.

Drawing on extensive international experience in privacy protection, we can support your route to ISO/IEC 27701:2025 certification. Your audit can include a gap assessment and benchmarking. We will assess your information security maturity and advise you on opportunities for continual improvement.

Are you planning to transition from the 2019 edition, or are you starting a new certification process from the beginning?

Get started today by contacting us through the contact form!