Skip to content

GDPR and ISO 27001

Practical guidance for ISO 27001: scope, risk, controls, and evidence that matches how your organisation really works. Use the takeaways and FAQ below as a checklist; then deep-link into your registers and change records.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Run the ISO 27001 readiness scan

What this page covers

Practical guidance for ISO 27001: scope, risk, controls, and evidence that matches how your organisation really works. Use the takeaways and FAQ below as a checklist; then deep-link into your registers and change records.

Practical next steps

Assign owners, set review dates, and collect artefacts that match production reality. Use internal audits to rehearse the story before the external certification audit.

Common pitfalls

Avoid scope drift, ownerless actions, and documentation that does not match live configuration. Prefer short maintained records over one-off project dumps.

Dutch version: read the Dutch page (same topic, different URL).

Primary sources for this topic

Key takeaways

  • Link controls to risk treatment and your Statement of Applicability, avoid policy-only boxes.
  • Assign owners, review cadence, and measurable acceptance criteria for every material action.
  • Use sampling and KPIs to show controls work in operations, not only that they were planned.
  • Align incidents and vendor changes with privacy/legal where personal data or chain risk is involved.

Frequently asked questions

Which privacy questions remain outside an ISO 27001 certificate?
A security management-system certificate does not settle the lawful basis, transparency, retention or international-transfer conditions for a particular processing activity. Identify the actual personal data, purposes and parties, then assess the relevant GDPR obligations. Security controls may support that work, but the organisation must retain the separate privacy decisions and evidence rather than treating certification as a blanket approval.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)