Certification planner / ISO 27701
How do you get ISO 27701 certification?
Privacy information management system: personal data protection built on ISO 27001. Answer the questions, and we'll map out the stages, timeline and documents you need to prepare for your business, with the reasoning behind each one.
ISO 27701 certification steps
- Scope and gap analysisDefine the certification scope and locations, and identify the gaps between your current practices and the standard.
- Leadership, policy and objectivesTop management commitment, policy, roles and measurable objectives.
- Risks and standard-specific analysesRisks and opportunities; depending on the standard, environmental aspects, information security risks or business impact analysis.
- DocumentationPrepare, approve and publish procedures, work instructions, forms and lists tailored to your business.
- Implementation and recordsOperate the system; build up records such as training, calibration, suppliers and corrective actions.
- Internal audit and management reviewAudit the system yourself, close the findings and conduct the management review.
- Certification auditStage 1 (documentation) and Stage 2 (implementation) audits by an accredited body, followed by the certificate.
Documents required for ISO 27701
The mandatory set from the KaliteGO library. Each one is generated as docx/xlsx, filled in with your company details.
DD.2Scope and Boundaries DocumentFR.13Destruction ReportFR.45Data Subject Application FormFR.46Employee Privacy NoticeFR.72Customer, Visitor and Website Privacy NoticeFR.73Privacy Impact Assessment FormFR.74Explicit Consent Statement and Withdrawal FormGT.EK.5PII Controller / PII Processor Role and Responsibility DefinitionLS.26Personal Data Processing InventoryLS.27Personal Data Transfer and Third-Party Disclosure Record ListLS.28Sub-processor List and Approval/Change Notification RecordPO.23Information Deletion and Data Masking PolicyPO.26Personal Data Protection and Processing PolicyPO.27Personal Data Retention and Destruction PolicyPO.34Information Security PolicyPR.2Risk and Opportunity Management ProcedurePR.35Data Subject Request Response ProcedurePR.36Personal Data Breach Response ProcedurePR.62Privacy Impact Assessment (PIA/DPIA) ProcedurePR.63Consent Management ProcedureSOZ.2Data Processor Agreement (Personal Data Processing and Transfer Contract Annex)
Frequently asked questions
How long does ISO 27701 certification take?
For most SMEs, 4–9 months. The timeline depends on your headcount, locations and current practices. The system needs to run long enough to generate records (usually 2–3 months), followed by an internal audit, a management review and the certification body's Stage 1 and Stage 2 audits.
Which documents are required for ISO 27701?
The standard explicitly requires certain documented information: scope, policy, objectives, procedures and records. The KaliteGO library has 21 document templates for ISO 27701; the planner explains which of them your business needs, and why.
Does KaliteGO issue the certificate?
No. The certificate is issued by an accredited certification body following the audit. KaliteGO gets you ready for the audit: documents, records, internal audit and management review.
Can I prepare without a consultant?
Yes. Most small and medium-sized businesses can prepare with a guided roadmap and ready-made templates. Consultants also use KaliteGO to manage multiple clients.