Extend your ISO 27001 with a Privacy Information Management System (PIMS) covering DPIAs, ROPA, rights handling, privacy controls and third-party clauses — with audit-ready evidence in Microsoft 365 & SharePoint. No new platform.
ISO 27701 builds on ISO 27001 — it’s like adding a “privacy layer” to your existing information security program. When managed together under one framework, your business gains stronger protection, less duplication, and a clearer story for customers and regulators.
In short — ISO 27001 protects information, ISO 27701 protects personal data. Together they deliver one integrated assurance framework your stakeholders can trust.
ISO 27701 extends your ISMS with a Privacy Information Management System (PIMS). It separates requirements for organisations that act as a Controller (deciding the purposes/means of processing) and a Processor (processing personal data on behalf of a controller).
You determine the why and how of personal data processing, handle data-subject rights, publish notices, and manage third parties.
You process data on a controller’s instructions, with contract-backed safeguards, sub-processor oversight, and breach notification duties.
Many organisations are both controller and processor depending on the dataset or service line. We scope each processing activity in your ROPA and apply the right annex set per activity.
We map each control to Microsoft 365 artefacts so evidence is generated by the process, not after it.
Evidence hub: /Evidence/27701/Controller/Notices/
Artefacts: published privacy notice, collection statements, consent logs.
Evidence hub: /Evidence/27701/Controller/DSR/
Artefacts: request intake, ID verification, fulfilment logs, timelines.
Evidence hub: /Evidence/27701/Controller/DPIA/
Artefacts: screening, DPIA reports, mitigations, approvals in SharePoint.
Contract-backed safeguards, sub-processor management, and notification timelines wired into Microsoft 365.
Evidence hub: /Evidence/27701/Processor/Agreements/
Artefacts: DPAs, SoWs, approved processing instructions, change logs.
Evidence hub: /Evidence/27701/Processor/Sub-processors/
Artefacts: approvals, flow-down clauses, notice history, risk reviews.
Evidence hub: /Evidence/27701/Processor/IR/
Artefacts: notification templates, timelines, post-incident reports.
Templates, thresholds, routing & approvals for privacy impact.
Processing records, retention, deletion and minimisation.
Purpose limitation, lawful basis, rights handling and incidents.
Due diligence, DPA clauses and ongoing monitoring.
Role-based content, onboarding & annual refreshers.
SharePoint evidence mapped to ISO 27701 requirements.
DPIAs and ROPAs embedded in daily workflows.
Evidence generated by the process, not after the fact.
Everything lives in Microsoft 365 where your teams already work.
We’ll extend your ISMS and automate the privacy evidence.