Free consultation

ISO/IEC27701

Privacy Information Management System (PIMS)

ISO 27701 Consulting
Privacy Management for the PDPA

Turn compliance with Thailand’s Personal Data Protection Act from documents written once and forgotten into a management system that can be audited and certified to ISO/IEC 27701.

Privacy Information Management System
PIMS
Latest edition, can stand alone
2025
PDPA breach notification deadline
72 h
Roles: controller / processor
2

What is ISO 27701?

ISO/IEC 27701 is the international standard for a Privacy Information Management System (PIMS). It sets out how to manage personal data systematically, both as a data controller and as a data processor.

The 2019 edition is an extension that must be paired with ISO 27001. The 2025 edition can be implemented on its own, but most organisations still pair it with ISO 27001 because they share much of the management structure and security controls.

Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) says what must be done, not how to organise it. ISO 27701 provides the framework that lets an organisation show clear evidence of compliance.

Deliverables

What you get

  • Personal data flow map and Records of Processing Activities (RoPA)
  • Controller and processor roles for each activity, with the lawful basis
  • Privacy notices and consent guidance
  • Data subject request procedures that meet the legal time limits
  • Breach response and 72-hour notification procedure
  • Data protection impact assessments (DPIA) for high-risk processing
  • Data processing agreements (DPA) with third-party providers

ISO/IEC 27701

How ISO 27701 maps to the PDPA

Many clauses of the standard match legal duties directly, so one system answers both the auditor and the regulator.

Records of processing

The PDPA requires controllers to keep a RoPA — the same core evidence an ISO 27701 auditor will ask to see.

Data subject rights

Access, correction, erasure, restriction, objection and portability each need a repeatable, traceable procedure.

Breach notification

The PDPA requires notifying the PDPC office within 72 hours of becoming aware of a breach, so the system has to surface incidents in time.

Processors

Using outside providers needs clear agreements and controls, and the standard has controls specific to that role.

An ISO 27701 certificate is not a legal ruling that an organisation complies with every part of the PDPA. It is credible evidence that the organisation runs a management system designed to comply.

Our Process

From day one to the day the auditor walks in

Every project follows these five steps. Timing depends on your size and scope — you’ll get a firm timeline once the readiness assessment is done.

  1. Gap analysis

    Compare your current practice with the requirements and define the certification scope.

    ~2–4 weeks
  2. System design

    Write policies, procedures, forms and a risk register people will actually use.

    ~1–3 months
  3. Rollout & training

    Train your team and build up complete records and evidence.

    ~1–3 months
  4. Internal audit

    Audit internally, fix nonconformities and hold the management review.

    ~2–4 weeks
  5. Certification audit

    We stand beside you through the certification body’s or assessor’s audit until you’re certified.

    per auditor schedule

Consultants cannot issue certificates — certificates come from an independent Certification Body. We help you choose one and make sure everything is ready.

FAQ

Frequently asked questions

Do we need ISO 27001 first?

For the 2019 edition, yes — it is an extension of ISO 27001. The 2025 edition can stand alone, but in practice pairing the two saves a lot of duplicated work and audit fees.

We already did PDPA compliance. Do we still need ISO 27701?

It is not legally required. But when customers or partners want third-party evidence that you manage personal data systematically, ISO 27701 certification provides it — and almost all of your existing PDPA work carries over.

We process data for our clients. Does the standard apply?

Yes. The standard has separate controls for controllers and processors; you apply those that match your actual role in each activity, or both.

Contact

Start with a free one-hour ISO 27701 / PDPA readiness assessment

Address
42/135 Chit Aree Ville 5, Lampang–Ngao Highway Rd., Chomphu, Mueang Lampang, Lampang 52100, Thailand

Call or email us and tell us where your organisation stands. We’ll tell you which standard to start with, roughly how long it will take, and what you need to prepare.

Tax ID
0525568001095