Privacy management

Make privacy management systematic.

ISO/IEC 27701 provides requirements for a privacy information management system. The current 2025 edition is a standalone standard. We help build the policies, responsibilities, assessments, and records that make privacy governance operational.

Our implementation focus

Make the requirements operational.

  1. 01

    Define privacy scope, roles, and data flows

  2. 02

    Assess privacy risks and obligations

  3. 03

    Design controls for collection, use, retention, and sharing

  4. 04

    Establish supplier and processor oversight

  5. 05

    Set review, audit, and improvement cycles

Independent assessment

This advisory work supports governance; legal advice and certification assessments are separate services.

Questions we hear

Get the distinctions right.

Is ISO/IEC 27701 a substitute for privacy law?

No. A privacy information management system helps govern personal information, but legal duties depend on processing, roles, and jurisdiction.

Does the 2025 edition require ISO/IEC 27001 certification?

The 2025 edition is a standalone privacy management system standard. Information security controls remain important, and the applicable assessment route should be confirmed with an independent certification body.

Work with Normstone

Build a defensible path to readiness.

Tell us the outcome you need and the markets involved. We’ll help define the work.

Start a conversation