ISO/IEC 27701 · extension to ISO/IEC 27001
Who processes on whose instruction – and who sits behind them?
ISO/IEC 27701 turns an information security management system into a privacy management system. Clarifying roles along the chain is the most demanding part.
The standard extends ISO/IEC 27001 and 27002 with requirements and guidance on protecting personal data. It distinguishes consistently between the controller role and the processor role and requires distinct measures for each.
For the supply chain that is the decisive point. A provider is rarely only one of the two: they process on instruction, engage their own subcontractors and answer for choosing them. Without mapping that chain, neither the GDPR nor the Swiss FADP can be served cleanly.
Who this concerns
- Providers processing personal data on instruction who must evidence it.
- Companies holding ISO 27001 who want to cover privacy without building a second system.
- Vendors whose customers ask for privacy evidence during procurement.
- Groups with intra-group processing across borders.
What counts for the chain
- Role clarity
- Establish for each processing activity who is controller and who is processor.
- Sub-processing
- Govern, approve and document the use of further processors.
- Instructions
- Process only on documented instruction, with a traceable trail.
- Data subject rights
- Procedures that work when data sits with sub-processors.
- Transfers
- Document cross-border processing and its legal basis.
How SCRM covers it
Role per provider
Controller or processor as a field, not a matter of interpretation.
Sub-processors
Approved sub-processing visible, and so are changes.
Contracts with expiry
Processing agreements with validity and recall dates.
Processing locations
Site and jurisdiction as checked data.
Frequently asked
Does 27701 replace a GDPR assessment?
No. The standard structures the management system; legal assessment remains separate. It does make the evidence considerably easier.
Do we need ISO 27001 first?
Yes, 27701 presumes an existing ISMS and extends it.
What does it give Swiss companies?
The revised FADP requires you to satisfy yourself about a processor’s data security. A provider certificate is a strong, checkable argument for that.