Skip to content
HEM Bilişim
All services

Compliance

ISO 27701 privacy information management system

We add the privacy layer on top of your existing ISO 27001 system and map it to KVKK and GDPR obligations.

  • ISO/IEC 27701
  • KVKK
  • GDPR

ISO 27701 adds the personal data dimension on top of an information security management system. If you already run ISO 27001, you can carry your KVKK compliance through this extension rather than building a separate structure.

Scope

01

Gap analysis against the existing ISO 27001 system

02

Separating controller and processor roles

03

Mapping privacy controls to KVKK and GDPR articles

04

Extending the document set and internal audit

What we deliver

Gap analysis report

Role-based control mapping table

Extended policy and procedure set

A privacy management system ready for certification

How we proceed

The process for this service

1

Gap analysis

The existing ISO 27001 system is reviewed against privacy requirements.

2

Role separation

Where you act as controller and where as processor is written down.

3

Control mapping

Privacy controls are mapped one to one against KVKK and GDPR articles.

4

Documents and internal audit

The document set is extended and verified through internal audit.

Questions about this service

See where you stand in 20 minutes

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation