Checkpoint · ISO 27701
ISO 27701 privacy software, in your own tenant
Checkpoint runs ISO/IEC 27701:2025 as a privacy information management system in its own right, certifiable alone or alongside ISO 27001, with the personal information records kept where they already are: in your Microsoft 365.
The demo is the real console with sample data. No sign-up.

What Checkpoint holds for ISO 27701
- ISO/IEC 27701:2025 Clauses 4–10 plus all 78 Annex A controls: 31 for PII controllers, 18 for PII processors and 29 shared security controls, each mapped to its ISO 27001 counterpart.
- Privacy documents kept separate from your information security ones.
- The Australian Privacy Principles and Notifiable Data Breaches duties are also available as their own framework, mapped to ISO 27001.
- Breach notification drafts for the OAIC and affected individuals, from the incident record.
Measured from your Microsoft 365
The scan checks that subject rights requests are answered within the statutory deadline (with Microsoft Priva), and that retention and disposal labels are published.
Checkpoint signs in with Microsoft Entra and reads your settings through Microsoft Graph with read-only, delegated permissions. Your records are SharePoint lists in your own tenant, so if you stop using Checkpoint they are still yours. How Checkpoint works.
Questions
- Can ISO 27701 be certified on its own now?
- Yes. The 2025 edition is a standalone management system standard. Earlier editions could only be certified as an extension of ISO 27001.
- Does it cover the Australian Privacy Act?
- Checkpoint carries the Privacy Act (the 13 APPs and the Notifiable Data Breaches scheme, as amended in 2024) as a separate framework, mapped to ISO 27001. Ask us about adding it.
- Where is personal information stored?
- Checkpoint stores its registers as SharePoint lists in your tenant. It does not copy personal information to Compliance365.