Free Readiness Assessment
ISO 27701 Privacy Readiness Checklist
Score your Privacy Information Management System (PIMS) against ISO 27701 in 15 minutes. Tell us about your environment, answer 17 focused questions, and download a PDF roadmap with your top privacy gaps and recommended next steps.
17 focused questions across 5 PIMS domains, plus a quick environment context block.
Calibrated to the PIMS controls — the same criteria privacy certification auditors sample.
Score breakdown, top privacy gaps, and a prioritised action plan. Emailed copy + instant download.
Tell us about your environment
A few details to tailor your roadmap. Required fields are marked *.
Leadership & Governance
Scope, ownership, policies and measurable targets.
A clear scope statement is the first thing an auditor checks. Vague or missing scope is the most common Stage 1 finding.
View evidence examples ->
- A short scope statement listing systems, products, regions and teams handling personal data
- A clear list of in-scope tools (e.g. CRM, support platform) and out-of-scope items (e.g. retired systems)
- Identification of key PII types such as customer, employee or patient data
Auditors want evidence that privacy is owned at a named level — not just delegated generically to IT or legal.
View evidence examples ->
- A named privacy owner or lead with documented responsibilities
- Clear escalation paths for incidents, complaints and high-risk decisions
- Defined approval roles for privacy assessments and responses
Policies must be version-controlled, dated and demonstrably acknowledged. A policy no one follows is a finding.
View evidence examples ->
- A current privacy notice published on your website or portal
- Internal procedures for handling privacy requests and incidents
- Documented retention, deletion and acceptable use rules
Leadership can see whether privacy is improving or declining — not just whether incidents happened.
View evidence examples ->
- Targets for responding to privacy requests within a set timeframe
- Regular reporting on incidents, complaints or near-misses
- Tracking privacy training completion rates across the organisation
Data Mapping & Risk Assessment
Your ROPA, data flows, and DPIA methodology.
The ROPA is your single source of truth for data processing. Auditors will sample it against your actual systems.
View evidence examples ->
- A register covering support, billing, marketing, product usage and HR processing
- Each entry lists purpose, data types, systems, vendors and retention period
- The register is reviewed when new systems or vendors are introduced
You need to understand how data moves across systems and vendors before you can control it.
View evidence examples ->
- A simple diagram showing data flow from collection to storage to deletion
- A list of third parties receiving personal data and their locations
- Identification of offshore hosting, access or transfers
DPIAs for high-risk processing are mandatory under ISO 27701. Not running them is a common major nonconformity.
View evidence examples ->
- Privacy assessments completed for new features, products or data uses
- Reviews conducted when onboarding new vendors with access to personal data
- Documented risks and agreed mitigations with owner sign-off
Everyday Privacy Controls
Minimisation, retention, consent, SRRs and training.
Controls must actually be configured in your systems, not just stated in policy. Auditors will sample system configuration.
View evidence examples ->
- Defined retention periods for customer and employee data, enforced in systems
- Role-based access restricting sensitive information to authorised staff only
- Automated deletion or anonymisation when data is no longer needed
Consent decisions must be traceable and defensible — a checkbox with no timestamp is not sufficient.
View evidence examples ->
- Records showing when and how consent was captured (with timestamp and mechanism)
- Preference management or opt-out capability connected to your systems
- Audit logs of consent changes visible to the privacy team
SRR handling is one of the most sampled controls in a PIMS audit. You need a ticket trail and response records.
View evidence examples ->
- A workflow or ticket system for privacy requests with SLA tracking
- Identity verification steps before releasing or deleting personal data
- Closed records showing responses were sent on time with evidence
Training awareness is mandatory evidence. Auditors will ask to see completion reports and curriculum scope.
View evidence examples ->
- Mandatory privacy training for all new starters within the first 30 days
- Additional or tailored training for high-risk roles (e.g. support, sales, data teams)
- Completion reports reviewed by management at least annually
Vendors & Overseas Data
Processor due diligence, DPAs and transfer safeguards.
Supply chain privacy risk is heavily scrutinised. A vendor with access to PII and no DPA is a significant finding.
View evidence examples ->
- Vendor risk assessments completed before onboarding any processor with PII access
- Privacy clauses and DPAs included in all relevant supplier contracts
- Annual review of critical processors including SOC reports, certificates or questionnaires
Offshore access or hosting without transfer assessment is a common audit gap — especially for cloud-hosted platforms.
View evidence examples ->
- Identification of all systems with offshore access or hosting (including SaaS vendors)
- Documented assessment of overseas transfer risks and applicable safeguards
- Controls and contractual clauses in place to monitor and manage transfers
Evidence & Monitoring
Evidence management, metrics, internal audit and review.
Evidence is the PIMS backbone. Centralised, structured evidence reduces audit stress significantly.
View evidence examples ->
- Central storage of policies, registers and assessments with version history enabled
- Clear ownership for maintaining each document type
- Retention policies applied to privacy evidence in M365 or equivalent
Metrics support informed decision-making and demonstrate active governance. Auditors will ask to see reporting history.
View evidence examples ->
- Regular reporting on SRR volumes, incidents, DPIAs completed and complaints received
- Trend analysis identifying recurring issues or problem areas
- Metrics reviewed and actioned by leadership at least quarterly
Internal audit is mandatory under ISO 27701. Findings must be owned, dated and verified closed.
View evidence examples ->
- Annual internal audit plan covering ISO 27701 controls and a rotating sample of processing activities
- Audit reports with findings, root cause, corrective actions, owners and due dates
- Evidence that corrective actions are verified closed — not just marked done
Management review minutes are mandatory evidence and one of the first documents auditors request.
View evidence examples ->
- Management review agenda and minutes covering all required ISO 27701 inputs
- Recorded decisions on resourcing, policy changes, risk acceptance and improvement priorities
- Action register with owners, due dates and closure tracking
Available once all questions are answered
Your report is ready
Your PDF has downloaded automatically. A copy of your responses has been sent to our team — we'll follow up if you'd like to discuss the results.