The complete privacy information management system, written to ISO/IEC 27701:2025, the second edition that redrafted the standard as stand-alone. 150 pages across ten editable files plus a nineteen-sheet Excel workbook, including the record of processing, rights request tracker and breach register with the 72-hour clock built in.
The 2025 edition changed one thing that changes everything: ISO 27701 no longer sits on top of ISO 27001. You can now certify to it alone. A great deal of published guidance still describes the old arrangement, and two details in particular are widely wrong: Annex B is normative, not optional, and there are eleven clauses, not ten. This toolkit gets both right.
The clause 5.2 privacy policy, which is not your website notice and assessors will not accept the swap, plus lawful basis and purpose, PII principal rights with the statutory clocks stated precisely, privacy by design, retention and disposal, processing on instructions, subcontracted processors, international transfer, and privacy incident and breach with the 72-hour clock.
All eleven clauses, including clause 11 on the annexes, which most guidance does not know exists. Opens with the decision everything else depends on: whether you are a PII controller, a PII processor or both, and what each answer commits you to.
Privacy risk assessment built around harm to the individual rather than to the organisation, rights request handling with the one-month clock and the extension rules, breach assessment and notification, impact assessment, processor management, international transfers, retention and disposal, plus the management system procedures. Nine sections each.
Rights request forms for each right, breach report and assessment with the awareness timestamp every deadline runs from, impact assessment, processor instructions and audit, transfer risk assessment, plus the audit and review set.
For anyone certified to the first edition. What stays, what changes, where to start with Annex F, and why we state the widely reported October 2028 deadline as expectation rather than fact until your certification body confirms it in writing.
Record of processing for controller and processor roles, the 78-row Statement of Applicability grouped by role, privacy risk register, rights request tracker with deadline countdowns, breach register, processor register, transfer register, retention schedule, plus dashboards that count the commonest findings automatically.
Clause by clause and control section by control section, with the questions that catch a privacy system built by a security team: where is lawful basis, where is retention, where is purpose creep.
The order of work, how the controller and processor sections divide, and how this system shares machinery with an ISMS if you already hold one.
The privacy terms, the confusable pairs, and the audit room phrasebook.
Not a summary. The actual questions an assessor puts about that document, and what to put in front of them. You will not find this in a template bundle, because template bundles are not written by people who have sat in the assessor’s chair.
Certification does not make you legally compliant, and the two are routinely confused. The statutory duties are mapped next to the clauses so neither is being satisfied by accident.
Every document carries a phase number in its header, from appoint through to learn. If you are lost, look at the header of whatever is in front of you and you know where you are.
Where a document must be produced by a competent specialist, such as a fire risk assessment, asbestos survey, legionella or health surveillance, the toolkit says so, explains how to commission one, and tells you how to judge whether what you were handed is any good. Selling you a template for those would be worse than selling you nothing.
Organisations processing personal data whose customers are asking for evidence: software companies acting as processors, HR and payroll providers, marketing and analytics firms, healthcare-adjacent services, and anyone holding ISO 27701:2019 who now has to transition. UK GDPR knowledge is built into the templates rather than assumed.
Drafted for the United Kingdom with notes for Scotland and Northern Ireland, and structured so that the management system requirements carry across unchanged to any jurisdiction. Outside the UK you would replace the legal register entries with your own obligations; everything else holds.
Fully editable Microsoft Word and Excel in one zip. Every placeholder is in [SQUARE BRACKETS] so you can see at a glance what needs your input. Every guidance box is shaded so you know what to delete before you issue the document.
You may use, edit, adapt and rebrand everything within your own organisation, on as many sites and for as many people as you employ, and give completed copies to your certification body, assessor, clients, insurer or regulator.
You may not resell, share or distribute the blank toolkit outside your organisation, or repackage it as your own product.