// Privacy
ISO 27701 Compliance Software
Privacy extension to ISO 27001/27002 for managing PII as data controller and processor.
Framework at a glance
Short name
ISO 27701
Version
—
Category
Privacy
Controls
49
What ISO 27701 covers
49 controls across 31 domains — every one tracked, owned and evidenced in Cyber Horizon.
Privacy Management
6 controls- P.5.1 Policies for information security
- P.5.2 Information security roles and responsibilities
- P.5.3 Segregation of duties
- P.5.4 Management responsibilities
- P.5.5 Contact with authorities
Threat Intelligence
1 controls- P.5.7 Threat intelligence
Privacy by Design
2 controls- P.5.8 Privacy in project management
- P.8.12 Privacy by default
Data Inventory
1 controls- P.6.1 PII inventory
Lawful Basis
1 controls- P.6.2 PII processing purposes
Data Minimisation
1 controls- P.6.3 PII minimisation
Data Quality
1 controls- P.6.4 PII accuracy
Retention
1 controls- P.6.5 PII retention and disposal
Transparency
1 controls- P.6.6 Privacy notices
Consent
1 controls- P.6.7 Consent management
Data Subject Rights
1 controls- P.6.8 Data subject rights
Automated Processing
2 controls- P.6.9 Automated decision making
- P.8.22 Profiling controls
Special Categories
2 controls- P.6.10 Children's data
- P.6.11 Special category data
Risk Assessment
1 controls- P.6.12 Privacy impact assessment
Third-Party Management
3 controls- P.7.1 Third-party contracts
- P.7.2 Processor due diligence
- P.7.3 Sub-processor management
Governance
3 controls- P.7.4 Joint controller arrangements
- P.8.10 DPO appointment
- P.8.17 Processor instructions
Data Transfers
4 controls- P.8.1 Cross-border transfers
- P.8.2 Transfer impact assessments
- P.8.3 Standard contractual clauses
- P.8.4 Binding corporate rules
Incident Management
3 controls- P.8.5 Data breach notification
- P.8.6 Data subject breach notification
- P.8.24 Privacy incident management
Monitoring
1 controls- P.8.7 Privacy monitoring
Audit
1 controls- P.8.8 Privacy audit
Documentation
1 controls- P.8.9 Records of processing activities (ROPA)
Training
1 controls- P.8.11 Privacy training
Cryptography
2 controls- P.8.13 Encryption of PII
- P.8.14 Pseudonymisation
Access Control
1 controls- P.8.15 Access control for PII
Logging
1 controls- P.8.16 PII logging
Development
1 controls- P.8.18 Privacy in system development
Testing
1 controls- P.8.19 Privacy testing
Web Privacy
1 controls- P.8.20 Cookie and tracking compliance
Marketing
1 controls- P.8.21 Marketing communications
Data Management
1 controls- P.8.23 Anonymisation
Regulatory
1 controls- P.8.25 Supervisory authority cooperation
How Cyber Horizon automates ISO 27701
Every ISO 27701 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is ISO 27701?
Privacy extension to ISO 27001/27002 for managing PII as data controller and processor.
How many controls does ISO 27701 have?
ISO 27701 has 49 controls in Cyber Horizon's catalogue, organised across 31 domains.
How does Cyber Horizon help with ISO 27701?
Cyber Horizon maps ISO 27701 into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 27701 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Privacy frameworks
See ISO 27701 mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 27701 in Cyber Horizon.