GCSI — Global Cyber Standards Institute, official PECB Partner, Luxembourg.
Privacy & Data Protection
ISO/IEC 27701 extends ISO/IEC 27001 and ISO/IEC 27002 into a full Privacy Information Management System (PIMS), covering both organizations that control personal data and those that process it on another’s behalf. For organizations already operating under the GDPR and supervised in Luxembourg by the CNPD, it is the standard that turns privacy compliance from a legal policy into an operated management system.
Why this matters for your organization
Board & executive leadership
Data protection failures carry direct financial and reputational exposure at board level. A certified PIMS gives a board a concrete answer when asked how the organization operationalizes its GDPR obligations, beyond the privacy policy itself.
Risk, compliance & data protection functions
For DPOs specifically, ISO/IEC 27701 provides the operating structure that GDPR itself does not — a management system to point to, rather than a set of legal obligations without an implementation method.
Operational & technical specialists
For the teams handling personal data day to day — HR, marketing, IT, customer-facing functions — a PIMS defines clearly which controls apply to their specific processing activities, replacing ambiguity with a defined operating procedure.
Certifications offered
ISO/IEC 27701 — Privacy Information Management
The international standard extending ISO/IEC 27001 and ISO/IEC 27002 to build a Privacy Information Management System (PIMS), for both PII controllers and processors.
- ISO/IEC 27701 Foundation (2 days) — fundamental concepts and principles of a PIMS.
- ISO/IEC 27701 Lead Implementer (5 days incl. exam) — plan, deploy and continually improve a PIMS.
- ISO/IEC 27701 Lead Auditor (5 days incl. exam) — plan, conduct and close an ISO/IEC 27701 compliance audit in accordance with ISO 19011 and ISO/IEC 17021-1.
