Skip to content

ISO/IEC 27701 — Clauses 4–10 implementation guide

ISO 27701 follows the Annex SL harmonized structure. Clauses 4–10 describe how to run a Privacy Information Management System; PIMS-specific content sits inside the shared backbone — role determination in Clause 4.1, privacy policy in 5.2, privacy risk assessment in 6.1.2, privacy risk treatment in 6.1.3 producing control selection from the Annex A tables (Table A.1 controllers, Table A.2 processors, Table A.3 both roles). This page is the implementation playbook.

Quick decision

  • You already operate ISO 27001 → Clauses 4–10 are mostly in place; focus on the PIMS-specific additions (4.1 role determination, 5.2 privacy policy, 6.1.2/3 privacy risk + treatment, Annex A control tables).
  • You are starting from scratch → stand up the Annex SL backbone and the PIMS-specific work in parallel.
  • You need to write the privacy risk assessment (6.1.2) → define criteria, thresholds, cadence, approval authority. Trigger DPIAs (GDPR Article 35) where the risk threshold is met.
  • You need to determine controller vs processor role → Clause 4.1. Per processing activity, not per organization.

TL;DR

  • Annex SL backbone shared with ISO 27001 / 42001 / 9001 — Clauses 4 (Context), 5 (Leadership), 6 (Planning), 7 (Support), 8 (Operation), 9 (Performance evaluation), 10 (Improvement).
  • PIMS-specific additions inside the shared clauses: 4.1 role determination (controller / joint controller / processor); 5.2 privacy policy; 6.1.2 privacy risk assessment; 6.1.3 privacy risk treatment + SoA selecting from the Annex A tables (Table A.1 controllers, Table A.2 processors, Table A.3 both roles), plus the 27701-only information-security-program documentation.
  • Statement of Applicability is required as part of Clause 6.1.3 risk treatment.
  • Internal audit (9.2) + management review (9.3) + corrective action (10.2) = the operating loop.
  • Modulos models Clauses 4–10 via OFF-12 (28 ORF requirements) and MFF-13 (5 MRF requirements).

Primary source

ISO/IEC 27701:2025Privacy information management — Requirements and guidance, Clauses 4 through 10. Withdrawn prior edition: ISO/IEC 27701:2019. Available via the ISO Online Browsing Platform. © ISO.

Annex SL backbone

ClauseHeadlinePIMS-specific content
4 ContextPIMS boundaries + role determinationController / processor role per processing activity
5 LeadershipAccountability and directionPrivacy policy + privacy responsibilities (DPO / privacy lead)
6 PlanningRisk method, treatment, objectives, change planningPrivacy risk assessment; SoA selecting from the Annex A tables (A.1 / A.2 / A.3); information-security-program documentation
7 SupportPeople, resources, documented informationPrivacy competence + awareness; PII handling training
8 OperationRepeatable privacy operationsAnnex A control execution (Tables A.1 / A.2 / A.3); PII principals' rights handling; breach notification
9 Performance evaluationMeasurement + governance cadencePrivacy metrics; internal audit; management review
10 ImprovementFix and learnNonconformity + corrective action; continual improvement

Clause 4 — Context of the organization

Goal: define the PIMS boundaries and determine the organization's role per processing activity.

What to implement:

  • PIMS scope statement (Clause 4.3) — processing activities, PII categories, PII principals, organization's role per activity.
  • Role determination (4.1) — PII controller (including joint controller under GDPR Article 26) / processor / both, per processing activity.
  • Climate-change relevance (4.1) — determine and document whether climate change is a relevant issue for the PIMS. This determination was added by the 2024 climate-action amendment to the harmonized management-system structure (ISO/IEC 27001:2022/Amd 1:2024 and parallels) — not the originally published Clause 4.1 wording — and the 2025 edition already reflects it. The same control sits under Clause 4.1 of ISO 27001 and ISO 42001.
  • Interested parties (4.2) — PII principals, customers, supervisory authorities, sub-processors.

Common pitfalls:

  • Role determination as a blanket statement ("we are a processor") rather than per-activity.
  • Scope that ignores cross-border processing or sub-processor chains.

Clause 5 — Leadership

Goal: make privacy governance real — privacy policy, defined roles, governance cadence.

What to implement:

  • A privacy policy (5.2) — usable and auditable.
  • Roles and authorities (5.3) — DPO / privacy lead, RACI for the privacy program.
  • Governance cadence and escalation paths — privacy incidents, exceptions, PII principal complaints.

Clause 6 — Planning

Goal: privacy risk discipline, control selection, objectives, change planning.

What to implement:

  • Privacy risk assessment method (6.1.2) — criteria, thresholds, cadence, approval authority. Triggers DPIAs under GDPR Article 35 where the risk threshold is met.
  • Privacy risk treatment (6.1.3) — selecting controls from the Annex A tables: Table A.1 (controllers), Table A.2 (processors) and Table A.3 (both roles). Includes the Statement of Applicability. ISO 27701 adds an obligation the other management-system standards do not: identify and document the information-security program protecting the PII you process (a 27701-only control).
  • Privacy objectives (6.2) — measurable, owned, reviewed.
  • Planning of changes (6.3) — what triggers reassessment (new processing activity, vendor change, regulatory change).

Clause 7 — Support

Goal: people, resources, competence, awareness, documented information.

What to implement:

  • Resource planning — DPO / privacy office, time and expertise.
  • Competence (7.2) — privacy-specific competences for reviewers and approvers.
  • Awareness and training (7.3) — PII handling training; privacy by design awareness for engineers.
  • Communication (7.4) — determine the communication methods and channels (a shared "Communication methods" control completes Clause 7.4 across ISO 27001, 27701 and 42001); internal communication on privacy decisions; external communication to PII principals via privacy notices.
  • Documented information (7.5) — versioning, review cadence, access control.

Clause 8 — Operation

Goal: repeatable privacy operations — control execution, PII principals' rights, breach notification.

What to implement:

  • Operational planning and control (8.1) — executing the selected Annex A controls (Tables A.1 / A.2 / A.3).
  • Periodic privacy risk reassessment (8.2) — as systems, vendors, processing activities and regulatory landscape change.
  • PII principals' rights handling — access, rectification, erasure, portability requests within statutory deadlines (e.g., GDPR's one-month default under Article 12).
  • Personal-data breach notification process — internal escalation; supervisory-authority notification under GDPR Article 33 (typically 72 hours); PII-principal notification under GDPR Article 34 where required.
  • Supplier and sub-processor management — contractual safeguards (DPA, SCCs), monitoring, due diligence.

Clause 9 — Performance evaluation

Goal: prove the PIMS works — monitoring, internal audit, management review.

What to implement:

  • Monitoring and measurement (9.1) — privacy metrics (DSAR turnaround, breach-handling time, sub-processor coverage).
  • Internal audit program (9.2) — scope, cadence, sampling, auditor competence.
  • Management review (9.3) — inputs: audit findings, breach reports, DSAR metrics, supervisory-authority interactions, sub-processor reviews, regulatory change.

Clause 10 — Improvement

Goal: make failures productive — fix nonconformities and continually improve.

What to implement:

  • Nonconformity and corrective action (10.2) — ownership, deadlines, root cause analysis, effectiveness verification.
  • Continual improvement (10.1) — driven by audits, breaches, DSAR friction, stakeholder feedback.

How to operationalize Clauses 4–10 in Modulos

OFF-12 (org-level) mapping:

PIMS elementOFF-12 requirementClause
Organizational context (incl. role determination)ORF-2564.1
Interested partiesORF-2574.2
PIMS scopeORF-2584.3
PIMS itselfORF-2594.4
Leadership commitmentORF-2605.1
Privacy policyORF-2615.2
Roles and responsibilitiesORF-2625.3
Risk and opportunities — generalORF-2636.1.1
Privacy risk assessmentORF-2646.1.2
Privacy risk treatment + SoAORF-2656.1.3
Privacy objectivesORF-2666.2
Planning of changesORF-2676.3
Resources / competence / awareness / communicationORF-268ORF-2717.1–7.4
Documented informationORF-272 / ORF-273 / ORF-2747.5.1–7.5.3
Operational planning and controlORF-2758.1
Monitoring + measurementORF-2769.1
Internal audit + audit programORF-277 / ORF-2789.2.1 / 9.2.2
Management review (process / inputs / outputs)ORF-279 / ORF-280 / ORF-2819.3.1 / 9.3.2 / 9.3.3
Continual improvementORF-28210.1
Nonconformity and corrective actionORF-28310.2

MFF-13 (app-level) mapping:

RequirementClauseTopic
MRF-2438.2Privacy risk assessment (per AI system)
MRF-2448.3Privacy risk treatment (per AI system)
MRF-394Annex A, Table A.1Controls for PII controllers (31)
MRF-395Annex A, Table A.2Controls for PII processors (18)
MRF-396Annex A, Table A.3Controls for both roles (29)

Integrated Management System (IMS) with ISO 27001 / 42001

The PIMS Clauses 4–10 share the Annex SL backbone with ISO 27001 (ISMS) and ISO 42001 (AIMS). In Modulos, the org-level Clauses 4–10 controls are one shared set across ISO 27001, 27701 and 42001 (and reused by NIS2 and DORA), written to read correctly under whichever management system applies. Where one standard imposes work the others do not, that obligation is its own control mapped only to that standard, so it never appears in another framework's checklist. Examples:

  • Shared — a single "Communication methods" control completes Clause 7.4 for all three standards; document control, internal audit, management review and corrective action operate once.
  • ISO 27701-only — the Clause 6.1.3 information-security-program documentation.
  • ISO 27001 + 27701 — risk-owner identification under Clause 6.1.2.
  • ISO 27001-only — determining who is assigned monitoring and measurement under Clause 9.1.
  • ISO 42001-only — AI-policy alignment and AIMS documentation.

Each requirement's detail panel makes this explicit: it shows the exact Standard reference (clause / Annex) and a plain-language "what this clause requires" summary; the shared Clauses 4–10 requirements also carry Harmonized with links to the sibling ISO standards' matching requirements and Related to links where relevant. What stays standard-specific:

  • ISO 27701: privacy risk, controller / processor / joint-controller distinction, Annex A privacy control tables (A.1 / A.2 / A.3).
  • ISO 27001: information-security risk, Annex A (normative) information-security controls.
  • ISO 42001: AI policy, AI risk + impact, AI management-system controls.

Practical pattern: add OFF-9 (27001) + OFF-12 (27701) + OFF-10 (42001) to a single organization project; share the Annex SL processes; keep the standard-specific risk and control work explicit.

Related: Integration with GDPR.

Cross-framework mapping (preview)

ISO 27701 clauseAdjacent provision
Clause 4.1 role determinationGDPR Article 4(7) controller / 4(8) processor / 26 joint controllers
Clause 4.1 climate-change relevanceISO 27001 Clause 4.1 / ISO 42001 Clause 4.1 (2024 climate-action amendment)
Clause 5.2 privacy policyGDPR Article 24 controller obligations; ISO 27001 Clause 5.2 policy
Clause 6.1.2 privacy risk assessmentGDPR Article 35 DPIA; ISO 27001 Clause 6.1.2 information-security risk assessment
Clause 6.1.3 SoAISO 27001 Clause 6.1.3 d SoA (mandatory); ISO 42001 SoA (informative)
Clause 8 PII principals' rightsGDPR Articles 12–22 (DSAR handling)
Clause 8 breach notificationGDPR Article 33; ISO 27001 Annex A.5.24–A.5.28 incident management
Clause 8 sub-processor managementGDPR Article 28

Source attribution

ISO/IEC 27701:2025Privacy information management — Requirements and guidance, Clauses 4 through 10. © ISO/IEC. Available via the ISO Online Browsing Platform.

Disclaimer

This page is for general informational purposes and does not constitute legal or certification advice.