Skip to content

ISO/IEC 27701 Standard: Threats and Opportunities for GDPR Certification

Eric Lachaud

DOI https://doi.org/10.21552/edpl/2020/2/7

Keywords: certification, privacy, ISO, self-regulation, standardisation


The paper assesses the possible consequences for Article 42/43 certification of the publication of the ISO/IEC 27701:2019 standard. This new ISO standard establishes a management system that aims to manage ‘the processes for protecting the capture, accountability, availability, integrity, and confidentiality of personal data.’ The conformity with the standard’s requirements is certifiable by the private conformity assessment bodies interested in providing this service to businesses. The paper shows that ISO/IEC 27701:2019 based certification has many assets to dominate the market of data protection certification. It offers operational advantages to businesses that are looking for a readymade solution to streamline information security and data protection. A strong uptake of ISO/IEC 27701:2019 based certification could threaten Article 42/43 certification by creating two competing approaches of data protection compliance. But it could also offer the opportunity to improve the general level of data protection and encourage the European supervisory authorities to clarify the relationships they intend to establish with ISO privacy standards.
Keywords: certification, privacy, ISO, self-regulation, standardisation

Eric Lachaud is a Researcher at the Tilburg Law School, Tilburg University. For correspondence: <mailto:E.Lachaud@tilburguniversity.edu>.

Share


Lx-Number Search

A
|
(e.g. A | 000123 | 01)

Export Citation