GDPR, ISO 27001 and 27701
Privacy controls for SaaS companies places privacy governance beside security. GDPR is legislation. ISO/IEC 27701:2025 is an independent privacy information management system (PIMS) standard that can be used alongside ISO 27001. A PIMS does not replace applicable legal obligations. Combine DPAs, processing records, DPIAs and security controls in one narrative.
Processing register and DPIA
Your processing record must match subprocessors in the vendor register. DPIA outcomes belong in the risk register with owners, not a side folder.
SaaS and privacy by design
For SaaS: document data flows, retention and subject rights per feature. Privacy by design means provable decisions in design and release, not only a policy.
Common mistakes
DPO without mandate; stale register; one-off DPIA; privacy and security use different language; no proof of rights handling.
Checklist
- Sync register with vendors
- Link DPIA to risks
- Retention per data type
- Subject rights process
- Clarify privacy vs security roles
Practical next step
For privacy controls SaaS, ISO Ready keeps actions, evidence, risks and vendors aligned toward audit or supervision. Run the readiness scan on iso-ready.nl.
No certification guarantee, you retain ownership of scope, risks and decisions.
More in this cluster
- Iso 27001 Saas
- Demonstrate Privacy By Design
- Iso 27701 Certification
- Cloud Security Iso 27001
- Iso Audit Evidence
- Dora Compliance