Home / Services / Certification Services / ISO/IEC 27701 Certification
GLI® Secure ISO/IEC 27701 Certification.
Personal data is one of the most valuable and sensitive assets organizations handle today. With growing expectations from individuals, regulators, and business partners, it’s not enough to say you care about privacy — you need to prove it.
Have your privacy information management processes audited against the ISO 27701 standard and obtain certification from GLI Secure.
About the Standard
What is ISO/IEC 27701?
ISO/IEC 27701 is an international standard that sets out requirements for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS).
It also provides guidance to support organisations in putting these requirements into practice.
The standard is designed for personally identifiable information (PII) controllers and processors, who hold responsibility and accountability for processing PII.
Ready to begin
Learn how certification builds trust with customers, partners, and regulators.
Certification
What does it mean to be certified?
Certification to ISO/IEC 27701 is one way to demonstrate to stakeholders and customers that you are committed and able to manage personal information securely and safely. Holding a certificate from an accredited conformity assessment body brings an additional layer of confidence, as an accreditation body has provided independent confirmation of the certification body’s competence.
Who is it for?
Mapped to GDPR
As with other ISO management system standards, companies implementing ISO/IEC 27701 can decide whether they want to go through a certification process. Some organizations implement the standard to benefit from the best practice it contains, while others also get certified to reassure customers and clients.
Requirements
What are the
requirements?
Certification requires organizations to implement the requirements found within the ISO/IEC 27701:2019 standard. Among them are Clauses 4 through 10 (Context of the organization, Leadership, Planning, Support, Operation, Performance Evaluation, and Improvement), PIMS-specific guidance related to ISO/IEC 27002, and Annexes A and B.
Clauses 4–10
Context, Leadership, Planning, Support, Operation, Performance Evaluation, and Improvement of your PIMS.
PIMS Guidance
PIMS-specific guidance related to ISO/IEC 27002 for privacy-focused security controls.
How does the certification process work?
Certification audits are performed through an onsite visit to the organization’s location. The audit consists of a documentation review against the standards requirements, with interviews being performed, observation of activities, as well as control testing to determine the operating effectiveness of the controls.
How GLI Secure approaches your audit
Certification Bodies (CBs) are public and private businesses accredited by the Standards Council of Canada (SCC) who have met the requirements of the SCC. CBs verify that businesses have met all the security controls for certification using assessment criteria developed by the standard’s issuing body, such as the International Organization for Standardization (ISO). GLI Secure is an accredited certification body. As Canada’s national accreditation body, the SCC rigorously assesses the experts who certify organizations.
To access the PDF with full details, please click on the links below:
Ready to simplify compliance and stay audit-ready year-round? With GLI Secure, compliance becomes clear, manageable, and strategic.
Gus Fritschie
SVP Information Security Services