ISO/IEC27701
Privacy Information Management System (PIMS)
ISO 27701 Consulting
Privacy Management for the PDPA
Turn compliance with Thailand’s Personal Data Protection Act from documents written once and forgotten into a management system that can be audited and certified to ISO/IEC 27701.
- Privacy Information Management System
- PIMS
- Latest edition, can stand alone
- 2025
- PDPA breach notification deadline
- 72 h
- Roles: controller / processor
- 2
What is ISO 27701?
ISO/IEC 27701 is the international standard for a Privacy Information Management System (PIMS). It sets out how to manage personal data systematically, both as a data controller and as a data processor.
The 2019 edition is an extension that must be paired with ISO 27001. The 2025 edition can be implemented on its own, but most organisations still pair it with ISO 27001 because they share much of the management structure and security controls.
Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) says what must be done, not how to organise it. ISO 27701 provides the framework that lets an organisation show clear evidence of compliance.
Deliverables
What you get
- Personal data flow map and Records of Processing Activities (RoPA)
- Controller and processor roles for each activity, with the lawful basis
- Privacy notices and consent guidance
- Data subject request procedures that meet the legal time limits
- Breach response and 72-hour notification procedure
- Data protection impact assessments (DPIA) for high-risk processing
- Data processing agreements (DPA) with third-party providers
ISO/IEC 27701
How ISO 27701 maps to the PDPA
Many clauses of the standard match legal duties directly, so one system answers both the auditor and the regulator.
Records of processing
The PDPA requires controllers to keep a RoPA — the same core evidence an ISO 27701 auditor will ask to see.
Data subject rights
Access, correction, erasure, restriction, objection and portability each need a repeatable, traceable procedure.
Breach notification
The PDPA requires notifying the PDPC office within 72 hours of becoming aware of a breach, so the system has to surface incidents in time.
Processors
Using outside providers needs clear agreements and controls, and the standard has controls specific to that role.
An ISO 27701 certificate is not a legal ruling that an organisation complies with every part of the PDPA. It is credible evidence that the organisation runs a management system designed to comply.
Our Process
From day one to the day the auditor walks in
Every project follows these five steps. Timing depends on your size and scope — you’ll get a firm timeline once the readiness assessment is done.
Gap analysis
Compare your current practice with the requirements and define the certification scope.
~2–4 weeksSystem design
Write policies, procedures, forms and a risk register people will actually use.
~1–3 monthsRollout & training
Train your team and build up complete records and evidence.
~1–3 monthsInternal audit
Audit internally, fix nonconformities and hold the management review.
~2–4 weeksCertification audit
We stand beside you through the certification body’s or assessor’s audit until you’re certified.
per auditor schedule
Consultants cannot issue certificates — certificates come from an independent Certification Body. We help you choose one and make sure everything is ready.
FAQ
Frequently asked questions
Do we need ISO 27001 first?
For the 2019 edition, yes — it is an extension of ISO 27001. The 2025 edition can stand alone, but in practice pairing the two saves a lot of duplicated work and audit fees.
We already did PDPA compliance. Do we still need ISO 27701?
It is not legally required. But when customers or partners want third-party evidence that you manage personal data systematically, ISO 27701 certification provides it — and almost all of your existing PDPA work carries over.
We process data for our clients. Does the standard apply?
Yes. The standard has separate controls for controllers and processors; you apply those that match your actual role in each activity, or both.
Contact
Start with a free one-hour ISO 27701 / PDPA readiness assessment
- Phone
- 086-654-0991
- Address
- 42/135 Chit Aree Ville 5, Lampang–Ngao Highway Rd., Chomphu, Mueang Lampang, Lampang 52100, Thailand
Call or email us and tell us where your organisation stands. We’ll tell you which standard to start with, roughly how long it will take, and what you need to prepare.
- Tax ID
- 0525568001095
- Address
- View map ↗