EDIH, EEN, Interreg: the platform for European programmes.Find out more

ISO 27701 Maturity · Privacy protection and the extension of GDPR to information privacy management systems

Your privacy management measured against ISO 27701, turned into a costed action plan.

13 themes, 144 questions, a 5-level scale. And the action that moves each level to the next.

The framework’s 13 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

ISO 27701 Maturity · Privacy protection and the extension of GDPR to information privacy management systems

PIMS governanceN1 → N5
Scope and processing rolesN1 → N5
Record and mapping of processing activitiesN1 → N5
Impact assessments and privacy by designN1 → N5

13 themes, 144 questions, 5-level scale.

Nordhavn Industries

53 / 100

PIMS governance6484
Scope and processing roles5379
Record and mapping of processing activities6182
Impact assessments and privacy by design3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • Caisse des Dépôts
  • Chambre de commerce et d'industrie
  • Docaposte
  • Enterprise Europe Network
  • EDIH Network
  • KPMG

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One ISO/IEC 27701:2019 (revised as ISO/IEC 27701:2025) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 13 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

This mechanism (one level, the level above, and the action that links the two) is what turns an observation into a trajectory.

Are data subject rights requests handled through a defined and tracked process?

  1. N1

    No identified process. Requests arrive through various channels and are handled by whoever receives them, with no record kept.

  2. N2

    A single point of entry exists and a procedure is written, but its application depends on the team and response times are not measured.

  3. N3

    The process is rolled out and applied: centralised intake, requester authentication, response within the regulatory deadline, traceability of every request.

  4. N4

    Requests are tracked through indicators (volume, type, turnaround time, rate of late responses), reviewed periodically, and the processing activities concerned are identified for each request.

  5. N5

    Gaps and recurring causes feed corrective action on the processing activities themselves, with documented tracking of process revisions.

Action to move from L2 to L3

Centralise the intake of requests on a single channel, open a tracking register with date received, due date and date of response, and add the review of open requests to the monthly personal data governance meeting.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon ISO 27701.

What this framework covers

ISO 27701 extends ISO 27001 and ISO 27002 to privacy protection. It describes a PIMS, a privacy information management system, and adds two distinct sets of controls: one for the data controller, one for the data processor. It builds on the principles of ISO 29100: consent, minimisation, purpose limitation, accuracy, transparency, data subject participation. It is not audited on its own: it is certified as an extension of an ISO 27001 certification, over a defined scope.

It is a demanding framework to steer, because it covers practices spread across legal, security, business functions and procurement. Does the record of processing activities reflect actual activity, or activity declared three years ago? Are impact assessments triggered by a written criterion, or by the data protection officer’s judgement? Are data subject rights requests tracked end to end, with a measured turnaround time? Are processor clauses checked after signature, or simply filed away?

One confusion comes up repeatedly: ISO 27701 is not a GDPR certification. It does not pronounce compliance with the regulation. It attests that a privacy information management system is in place and operating. The published mapping between the standard’s controls and the GDPR articles remains indicative, and the certified scope can be narrower than the organisation’s actual processing scope. The revision of the standard, which detaches it from ISO 27001 to make it a self-standing set of requirements, makes this clarity about what is actually covered even more necessary.

A maturity assessment asks a different question from a compliance audit. An audit concludes with compliant or non-compliant, against a given requirement, on a given date. The assessment places each practice on a progressive scale, theme by theme, and points to the action that moves it up to the next level. The result is not an opinion, it is a costed trajectory, comparable across business units and over time.

In Datamensio, the framework is ready to use. You can also adapt it: the AI adjusts the themes, questions and levels to your sector and your role, data controller or data processor, or builds a variant from your existing data protection policy, your record of processing activities and your existing procedures.

Reference standard: ISO/IEC 27701:2019 (revised as ISO/IEC 27701:2025)

The themes assessed

  • PIMS governance

    Privacy policy, appointment and positioning of the DPO, roles and responsibilities, allocated resources, alignment with the existing ISMS.

  • Scope and processing roles

    Determination of the role of controller, joint controller or processor, system scope, context and interested parties, extended statement of applicability.

  • Record and mapping of processing activities

    Completeness of the record, purposes, legal bases, categories of data and data subjects, retention periods, update frequency.

  • Impact assessments and privacy by design

    Criteria for triggering a DPIA, assessment method, integration of requirements into projects and procurement, minimisation and pseudonymisation by design.

  • Consent and information of data subjects

    Collection and proof of consent, withdrawal, information notices, transparency on purposes and recipients, cases involving minors and sensitive data.

  • Data subject rights

    Process for receiving and authenticating requests, access, rectification, erasure, portability, objection, traceability and monitoring of response times.

  • Processors and the processing chain

    Selection and assessment of processors, contracts and documented instructions, sub-processing, audits and evidence obtained, reversibility.

  • Transfers outside the European Union

    Identification of data flows, transfer mechanisms used, transfer impact assessments, actual location of data and remote access.

  • Security of personal data

    Technical and organisational measures tied to processing activities, access management, encryption, logging, environment segregation.

  • Data breaches and incidents

    Detection and qualification, notification procedure to the authority and to data subjects, timelines, breach register, lessons learnt.

  • Retention, archiving and deletion

    Actual application of retention periods, automated purging, interim archiving, deletion at processors, proof of destruction.

  • Awareness and culture

    Training for exposed teams, integration into onboarding, internal communication, ownership by business functions rather than legal alone.

  • Monitoring, audit and improvement

    Steering indicators, internal PIMS audits, management review, handling of non-conformities, comparison over time.

A short version of the framework, with 40 questions, is available for the online self-assessment. The full version covers 13 themes and 144 questions.

Frequently asked questions

Does ISO 27701 amount to GDPR certification?

No. The standard attests that a privacy information management system is in place and operating over a defined scope. It does not pronounce compliance with the regulation, which is a matter for supervisory authorities. Datamensio measures your maturity and prepares you for the milestone, without replacing the certification body.

Do you need to be ISO 27001 certified first?

In the 2019 version, the ISO 27701 extension builds on an existing ISO 27001 certification or one conducted at the same time. The revision of the standard moves this towards a self-standing set of requirements. The assessment covers both cases and flags the controls that rely on the information security management system.

What is the difference between this assessment and a compliance audit?

An audit checks for the presence of requirements and concludes with a gap or a compliance finding. The assessment places each practice on a maturity scale and points to the action that moves it up to the next level. The two are complementary: the assessment prepares, the audit validates.

How long does the assessment take?

The short version takes 20 to 30 minutes to complete. The full version, run collaboratively, involves the DPO, security, legal and procurement: most of the time goes into gathering input from these contributors. Each question can be assigned to the right person.

Can the framework be adapted to our role and sector?

Yes. The questions, levels and themes can be changed, and you can isolate the controls specific to the controller or the processor. The AI generates a variant from your own documents: policy, record of processing activities, procedures. You retain full control of the framework.

How do you compare several entities within the group?

The same framework is rolled out to each business unit, with a score per theme and a common target. The benchmark compares entities against each other and each one against its own previous assessments. A cross-entity roadmap consolidates action plans without duplicating shared work.

How is the action plan costed?

The gap between the score and the target generates the actions. The AI groups them into a prioritised roadmap, and the service catalogue matches a solution to each item, with cost, timeline and expected impact on the score. You decide based on comparable options.

Where is the data hosted?

In France, with OVH, backed up at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurementon ISO 27701.