Document control is a crucial part of any privacy protection system, or indeed any broader information security policy.
Throughout its various standards, ISO recognises document management as an ongoing process that is used to demonstrate adherence both to ISO standards, and the organisation’s own privacy protection objectives.
ISO asks organisations to not merely view documented information as an administrative function, but instead use it as a recurring means to improve privacy protection adherence through the structured storage of guidelines that provide clear direction on PII-related activities.
ISO 27701 5.5.5 deals with documented information through three sub-clauses. Each deals with a different set of privacy and PII specific guidance points that link back to ISO 27001:
ISO 27701 5.5.5 doesn’t contain any supplementary guidance on PIMS-specific requirements, nor is it particularly relevant to any specific GDPR articles.
The organisation’s PIMS should include documented information that:
Throughout the process of drafting and amending documentation, organisations should:
Organisation’s should exercise adequate levels of control and security over their internal document structure that ensures documents are:
ISO 27701 Control 5.5.5 asks organisations to consider four main activities, when exercising control over privacy protection-related documents:
Alongside the management of internal documents, ISO asks organisations to consider how best to manage their interactions with and control of external documents that are required for the planning and implementation of a PIMS or other privacy/PII-related activities.
ISO 27701 Clause Identifier | ISO 27701 Clause Name | ISO 27001 Requirement | Associated GDPR Articles |
---|---|---|---|
5.5.5.1 | General | 7.5.1 – General Documentation for ISO 27001 | None |
5.5.5.2 | Creating and Updating | 7.5.2 – Creating and Updating Documented Information for ISO 27001 | None |
5.5.5.3 | Control of Documented Information | 7.5.3 – Control of Documented Information for ISO 27001 | None |
In order to achieve ISO 27701 you must build a Privacy Information Management System (PIMS).
With our preconfigured PIMS you can quickly and easily organise and manage customer, supplier and staff information to fully comply with ISO 27701.
See it in action with by booking a demo.
Book a tailored hands-on session
based on your needs and goals
Book your demo