{"id":4308,"date":"2024-04-27T06:17:10","date_gmt":"2024-04-27T12:17:10","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=regulations&#038;p=4308"},"modified":"2025-03-05T10:57:06","modified_gmt":"2025-03-05T16:57:06","slug":"iso-27701","status":"publish","type":"regulations","link":"https:\/\/trustarc.com\/regulations\/iso-27701\/","title":{"rendered":"ISO 27701 International Standard"},"content":{"rendered":"\t\t<section id=\"block_f74a16f02570175ccc4fa8d2c79fb67b\" class=\"hero-section-colors text-center bg-navy-gradient\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<span class=\"sub-title block font-bold \">Standard<\/span>\n\t\t\t\t\t\t\t\t\t\t<h1>ISO 27701<\/h1>\n\t\t\t\t\t<p>The ISO 27701 establishes requirements and guidance for developing, managing and improving a Privacy Information Management System (PIMS) for activities in privacy management involving personally identifiable information (PII). ISO 27701 focuses on security techniques and is an extension to ISO\/IEC 27001 and ISO\/IEC 27002 for privacy information management.<\/p>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_0217365dc0c0c1c0f592691b9be2a1a2\" class=\"columns-one text-left\" style=\"\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t<h2 style=\"text-align: center\">Who should use ISO 27701?<\/h2>\n<p style=\"text-align: center\">The requirements of ISO 27701 apply to all types and sizes of data controllers and\/or processors who process <a href=\"\/resource\/personally-identifiable-information\/\">PII<\/a> including private and public entities, government entities, and non-profit organizations.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_abf2a4cee999e49ee21df108a652a563\" class=\"columns-two\" style=\"padding-bottom:0;\">\n\t\t<div class=\"container\">\n\t\t\t\t\t\t\t<div class=\"heading text-center max-width\">\n\t\t\t\t\t\t\t\t\t\t\t<h2>Key requirements of ISO 27701<\/h2>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<div class=\"col-wrap\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Designation of privacy leader<\/h4>\n<p>Organizations should appoint one or more privacy officials to develop, implement and manage an organization-wide privacy governance program\/policy to outline procedures to comply with relevant data protection laws and regulations. Privacy officials shall also be responsible to provide support to all organizational stakeholders on their responsibilities related to data protection tasks.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Prioritize privacy by design and default<\/h4>\n<p>Organizations should apply principles and related tools of privacy by design and default into all layers of the information system for the secure management of PII (e.g. practicing data minimization to collect and process only the necessary PII).<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/section>\n\t\n\n\t<section id=\"block_da5e046f04cd0ffed46426be0ee40346\" class=\"columns-two\" style=\"padding-top:0;padding-bottom:0;\">\n\t\t<div class=\"container\">\n\t\t\t\t\t\t<div class=\"col-wrap\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Mechanisms for data deletion<\/h4>\n<p>Organizations should establish policies and technical mechanisms to permanently delete, de-identify, return and\/or transfer PII when the purpose of processing becomes obsolete or the PII retention period has expired.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Vendor Management<\/h4>\n<p>Where PIMS will be outsourced, organizations should regularly assess the vendor\u2019s privacy and data processing practices for compliance to organizational objectives and relevant data protection laws, verify the vendor\u2019s security posture, and consider applying privacy by design and default principles to the outsourced PIMS.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/section>\n\t\n\n\t<section id=\"block_21c0d1c45c65d1beab8c9cfa0493222a\" class=\"columns-two\" style=\"padding-top:0;\">\n\t\t<div class=\"container\">\n\t\t\t\t\t\t<div class=\"col-wrap\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Implementation of security protocols<\/h4>\n<p>Organizations must implement both organizational and technical security policies and procedures to safeguard confidential PII. This includes access controls to prevent unauthorized copying of PII by terminated employees or contractors and segregating overlapping responsibilities to prevent unauthorized access to sensitive data.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/section>\n\t\n\n\t\t<section id=\"block_7ecb02b3cb0003a1560d43ce35093237\" class=\"cta-section has-gradient-purple color-white\">\n\t\t\t<div class=\"bg\">\n\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue.png\" class=\"attachment-full size-full\" alt=\"\" srcset=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue.png 1440w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue-300x102.png 300w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue-1024x347.png 1024w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue-768x260.png 768w\" sizes=\"(max-width: 1440px) 100vw, 1440px\" \/>\t\t\t<\/div>\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"text-block\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"block h6\">Whitepaper<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<h2 class=\"h1\">Privacy and Data Security in Mergers &amp; Acquisitions<\/h2>\n\t\t\t\t\t\t<p>Data can be a valuable asset or an incredible liability to your business. Proactive data privacy practices are strategically critical in this data economy because of the extreme cost of mistakes today. <\/p>\n\t\t\t\t\t\t<ul class=\"btn-list\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"\/resource\/privacy-and-data-security-in-mergers-acquisitions\/\" class=\"btn\"><span>Learn More<\/span><\/a>\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_3dcd8a04815a6623b880ef797d675c26\" class=\"columns-one text-center\" style=\"padding-bottom:0;overflow:hidden;\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/icon_Update.svg\" class=\"attachment-full size-full\" alt=\"\" \/>\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t<h2 style=\"text-align: center\">Achieve compliance<\/h2>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_bf558f8310ef82a286f2e0f7ebe8ce05\" class=\"cards-block\">\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"cards-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/privacycentral\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>PrivacyCentral<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy program development and compliance management<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Automatically identify gaps and track compliance with PrivacyCentral for PC DSS v4.0, SOC2, ISO standards (e.g., 27701, 31700-01, 27550), NIST, and other privacy and security regulations.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/nymity-research\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>Nymity Research<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Guidance and operational templates<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Get access to expert privacy guidance, compliance alerts, and operational templates to ensure you stay ahead of global privacy framework changes.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/data-inventory-mapping\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>Data Inventory Hub &amp; Risk Profile<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Complete risk management process<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Automate data inventory mapping with TrustArc\u2019s Data Inventory Hub. Save time and mitigate risk with automated data flow mapping, risk analysis, and remediation.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/assessment-manager\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>Assessment Manager<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Mitigate risks for vendor management<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Use pre-built DPIAs, risk assessments, and vendor assessments to effectively mitigate vendor management risks with TrustArc\u2019s Assessment Manager.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_ec266016175da6500e0f3d2296054ce5\" class=\"accordions-section\" style=\"\">\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"max-width\">\n\t\t\t\t\t\t\t\t\t\t  <h2>FAQs<\/h2>\n\t\t\t\t\t\t\t\t\t\t\t<ul class=\"accordion\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"#\" class=\"opener\">How can I be notified if an outsourced vendor experiences a data incident?<\/a>\n\t\t\t\t\t\t\t\t\t<div class=\"slide\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-wrap\">\n\t\t\t\t\t\t\t\t\t\t\t<p>All entities have the responsibility to designate a point of contact for vendors to submit any issues they experience regarding the processing of PII.<\/p>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"#\" class=\"opener\">Is it permitted to backup PII?<\/a>\n\t\t\t\t\t\t\t\t\t<div class=\"slide\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-wrap\">\n\t\t\t\t\t\t\t\t\t\t\t<p>Yes. Entities should have a policy establishing requirements for PII backups, recovery and restoration, and clear information should be provided to individuals about the backup and restoration processes of PII. <\/p>\n<p>However, some jurisdictions may impose specific requirements regarding the frequency of backups, tests of backup, and the restoration procedures for PII. Organizations operating in such jurisdictions should comply with these requirements.<\/p>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"#\" class=\"opener\">Can I continue to use PII for new purposes when an individual has withdrawn their consent to the original purpose of processing?<\/a>\n\t\t\t\t\t\t\t\t\t<div class=\"slide\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-wrap\">\n\t\t\t\t\t\t\t\t\t\t\t<p>No. Once consent has been withdrawn for the initial purpose of processing, the PII cannot continue to be processed for new purposes. For example, if an individual withdraws their consent to profiling, their profile must not be used or consulted.<\/p>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_b43c75c0c897d924bb2f2873b195fa11\" class=\"resource-section bg-light-grey\">\n\t\t\t<div class=\"container\">\n\t\t\t<div class=\"resource-head\">\n\t\t\t\t\t\t\t<h2>Related Resources<\/h2>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<ul class=\"resource-lists \">\n\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/webinar-privacy-in-healthcare-ensuring-data-security\/\" class=\"resource-single has-icon Webinars\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-pink-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Webinars and Videos<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy in Healthcare: Ensuring Data Security<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/webinar-privacy-security-it-the-venn-diagram-of-compliance\/\" class=\"resource-single has-icon Webinars\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-gray-test-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Webinars and Videos<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy, Security, &#038; IT: The Venn Diagram of Compliance<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/what-gdpr-means-cybersecurity-strategy\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-plus-blue-test-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Articles<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>What the GDPR Means for your Cybersecurity Strategy<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_e358021307334ce2c7dafca152d7ae66\" class=\"columns-one text-center bg-light-grey\" style=\"padding-top:0;padding-bottom:0;overflow:hidden;\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t<p style=\"font-size: 80%\"><strong>The information provided does not, and is not intended to, constitute legal advice.<\/strong> Instead, all information, content, and materials presented are for general informational purposes only.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t","protected":false},"excerpt":{"rendered":"<p>ISO standard for managing Privacy Information Management Systems<\/p>\n","protected":false},"template":"","regulation":[97],"topic-regulation":[84,87],"class_list":["post-4308","regulations","type-regulations","status-publish","hentry","regulation-international","topic-regulation-privacy","topic-regulation-standard"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>ISO standard for managing Privacy Information Management Systems | TrustArc<\/title>\n<meta name=\"description\" content=\"The ISO 27701 establishes requirements and guidance for developing, managing and improving a Privacy Information Management System.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/regulations\/iso-27701\/\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/regulations\\\/iso-27701\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/regulations\\\/iso-27701\\\/\",\"name\":\"ISO standard for managing Privacy Information Management Systems | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"datePublished\":\"2024-04-27T12:17:10+00:00\",\"dateModified\":\"2025-03-05T16:57:06+00:00\",\"description\":\"The ISO 27701 establishes requirements and guidance for developing, managing and improving a Privacy Information Management System.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/regulations\\\/iso-27701\\\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"ISO standard for managing Privacy Information Management Systems | TrustArc","description":"The ISO 27701 establishes requirements and guidance for developing, managing and improving a Privacy Information Management System.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/regulations\/iso-27701\/","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/regulations\/iso-27701\/","url":"https:\/\/trustarc.com\/regulations\/iso-27701\/","name":"ISO standard for managing Privacy Information Management Systems | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"datePublished":"2024-04-27T12:17:10+00:00","dateModified":"2025-03-05T16:57:06+00:00","description":"The ISO 27701 establishes requirements and guidance for developing, managing and improving a Privacy Information Management System.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/regulations\/iso-27701\/"]}]},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/regulations\/4308","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/regulations"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/regulations"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=4308"}],"wp:term":[{"taxonomy":"regulation","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/regulation?post=4308"},{"taxonomy":"topic-regulation","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-regulation?post=4308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}