{"id":12561,"date":"2020-01-10T23:03:54","date_gmt":"2020-01-10T22:03:54","guid":{"rendered":"https:\/\/www.riskinsight-wavestone.com\/?p=12561"},"modified":"2020-01-31T16:32:59","modified_gmt":"2020-01-31T15:32:59","slug":"iso-27701-international-framework-privacy","status":"publish","type":"post","link":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/","title":{"rendered":"ISO 27701: one more compliance text or the long-awaited international framework for privacy protection?"},"content":{"rendered":"<p>Facebook (<a href=\"https:\/\/www.forbes.com\/sites\/mnunez\/2019\/07\/24\/ftcs-unprecedented-slap-fines-facebook-5-billion-forces-new-privacy-controls\/#483c82275668\">$5 billion<\/a>), Cambridge Analytica, Equifax (<a href=\"https:\/\/www.wired.com\/story\/equifax-fine-not-enough\/\">$700 million<\/a>), British Airways (<a href=\"https:\/\/ico.org.uk\/about-the-ico\/news-and-events\/news-and-blogs\/2019\/07\/ico-announces-intention-to-fine-british-airways\/\">\u20ac204 million<\/a>), Marriott (<a href=\"https:\/\/ico.org.uk\/about-the-ico\/news-and-events\/news-and-blogs\/2019\/07\/intention-to-fine-marriott-international-inc-more-than-99-million-under-gdpr-for-data-breach\/\">\u20ac110 million<\/a>)&#8230; there is no doubt that these record cases and fines contribute to making the following observation increasingly obvious and shared: cybersecurity and privacy protection are new structuring and non-negotiable pillars for companies and organizations. Apple CEO Tim Cook even recently referred to the subject as a &#8220;crisis&#8221; that needs to be addressed.<\/p>\n<p>&nbsp;<\/p>\n<h2>But what exactly is ISO 27701?<\/h2>\n<p>The International Standard Organisation (ISO) published in August 2019 its standard ISO 27701, which is an extension of ISO 27001 and is intended to specify and define the processes, objectives and measures to be implemented for the protection of personal data and privacy.<\/p>\n<p>&nbsp;<\/p>\n<h2>Creating and maintaining a Privacy Protection Management System<\/h2>\n<p>Like ISO 27001 standard (the reference for IT security), which aims to create an Information Security Management System (ISMS), its extension ISO 27701 aspires to create a System of Privacy Protection Management.<\/p>\n<p>To do this, the standard amends and supplements the processes, requirements and security measures of ISO 27001 and ISO 27002 with specific recommendations for the processing of personal data.<\/p>\n<p>However, it does not only expand the ISO 27001 and ISO 27002 but also adds specific new requirements that are well known to privacy stakeholders (consent management, transparency, minimization, etc.).<\/p>\n<figure id=\"post-12566 media-12566\" class=\"align-none\">\n<figure id=\"post-12572 media-12572\" class=\"align-none\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-12572\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2020\/01\/SChema-1-1.png\" alt=\"\" width=\"1022\" height=\"488\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2020\/01\/SChema-1-1.png 1022w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2020\/01\/SChema-1-1-400x191.png 400w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2020\/01\/SChema-1-1-71x34.png 71w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2020\/01\/SChema-1-1-768x367.png 768w\" sizes=\"auto, (max-width: 1022px) 100vw, 1022px\" \/><\/figure>\n<\/figure>\n<p>In this context, being ISO 27001 certified is a prerequisite for obtaining ISO 27701 certification.<\/p>\n<p>This parameter mechanically narrows down potential candidates for certification, and makes the effort to provide more consistent: review of existing documents, necessary collaboration between the initial WSIS teams and the new PIMS actors, etc.<\/p>\n<p>Despite this effort, the application of this standard offers an excellent opportunity for organizations to further intertwine processes and teams related to cybersecurity and privacy (e.g. linking the processes of Security Integration in Projects and Privacy by Design).<\/p>\n<p>&nbsp;<\/p>\n<h2>ISO 27701 certified does not mean GDPR compliant<\/h2>\n<p>It is important to note that an ISO 27701 certification is not synonymous with GDPR compliance. Indeed, the main purpose of the standard is to establish worldwide principles and rules around Privacy, in a common language. That said, it should be recalled that national authorities (such as the CNIL) participated in the development of the standard and welcomed its publication.<\/p>\n<p>But then, what are the adherences between the ISO 27701 content and the GDPR content?<\/p>\n<p>Regarding the fundamental principles of the GDPR (consent, rights, legality, etc.), the new standard develops a set of requirements covering all the GDPR topics. As the standard is intended to be international, it remains by nature less precise than the GDPR on some topics (i.e. no precision of the deadline to be respected for notifying the authority). It is therefore the responsibility of PIMS to carry out a gap analysis in order to understand what adjustments need to be made to comply with applicable laws.<\/p>\n<p>In addition, concerning personal data security, the adaptations of the requirements of ISO 27001 and ISO 27002 provide a comprehensive repository for organizations that can be used as a basis for compliance with article 32 of the GDPR (dedicated to data security).<\/p>\n<p>&nbsp;<\/p>\n<h2>\u2026 but it can become the strongest credibility mark in personal data protection and privacy on the market.<\/h2>\n<p>The main stake for a company in seeking ISO 27701 certification is to give credibility to its Privacy management system and give confidence to stakeholders (business partners, customers, suppliers, employees, authorities&#8230;) that the fundamental principles of privacy protection are considered.<\/p>\n<p>The 27701 &#8220;stamp&#8221; could quickly become a known and internationally recognized pledge of trust. Like ISO 27001, this new standard ISO 27701 could become an essential criterion in tendering phases.<\/p>\n<p>In this perspective, Matthieu Grall of the National Commission for Data Protection (CNIL) states that with \u201c(\u2026) the increase in the number of complaints and sanctions related to confidentiality and data protection, it is obvious that such a standard was necessary. In addition, organizations must demonstrate to the authorities, and their partners, customers and collaborators that they are trustworthy. However, this standard will greatly contribute to inspiring this <a href=\"https:\/\/www.iso.org\/news\/ref2419.html\">confidence<\/a>. &#8221;<\/p>\n<p>&nbsp;<\/p>\n<h2>Concretely, for whom and why?<\/h2>\n<p>The publication of this standard represents an opportunity for several types of organizations:<\/p>\n<ul>\n<li><strong>In a B2B relationship:<\/strong> a strong pledge of trust vis-\u00e0-vis business partners in the context of a collaboration involving the processing of personal data (i.e. a company managing payroll or carrying out communication or marketing operations on behalf of large organizations).<\/li>\n<li><strong>In a B2C relationship:<\/strong> the certification of a key perimeter of a company that processes the personal data of its customers en masse (i.e. a distributor in the context of its loyalty program, an insurer in the context of its contractual activities\u2026) can eventually become a significant vector of trust vis-\u00e0-vis the customers themselves but also vis-\u00e0-vis the authorities.<\/li>\n<li><strong>Within companies:<\/strong> the standard represents a new benchmark that companies can use to develop a clear and shared audit framework. ISO 27701 certification can also represent a way for DPOs and Privacy teams to make tangible the efforts made with their top management.<\/li>\n<\/ul>\n<figure id=\"post-12568 media-12568\" class=\"align-none\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-12568\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2020\/01\/Schema-2.png\" alt=\"\" width=\"1307\" height=\"311\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2020\/01\/Schema-2.png 1307w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2020\/01\/Schema-2-437x104.png 437w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2020\/01\/Schema-2-71x17.png 71w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2020\/01\/Schema-2-768x183.png 768w\" sizes=\"auto, (max-width: 1307px) 100vw, 1307px\" \/><\/figure>\n<p>While there is still uncertainty about its widespread adoption (particularly due to the 27001 certification barrier), there is no doubt that it can quickly establish itself as a confidence-building measure as well as a new standard for internal audit and control.<\/p>\n<p>The fact remains that the emergence of this standard is a new leap forward with regard to the protection of personal data, on an international scale.<a href=\"#_ftnref1\" name=\"_ftn1\"><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Facebook ($5 billion), Cambridge Analytica, Equifax ($700 million), British Airways (\u20ac204 million), Marriott (\u20ac110 million)&#8230; there is no doubt that these record cases and fines contribute to making the following observation increasingly obvious and shared: cybersecurity and privacy protection are&#8230;<\/p>\n","protected":false},"author":1338,"featured_media":11476,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"page-templates\/tmpl-one.php","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2777,3271],"tags":[3383,3151,3453,3454,3150,3425],"coauthors":[3096,3276],"class_list":["post-12561","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-digital-trust","category-digital-compliance-en","tag-digital-privacy-en","tag-gdpr-en","tag-isms","tag-iso-27701-en","tag-privacy-en","tag-standard"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ISO 27701: an international framework for privacy? - Risk Insight<\/title>\n<meta name=\"description\" content=\"ISO published in August 2019 its standard ISO 27701, extension of ISO 27001 for the protection of personal data and privacy.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ISO 27701: an international framework for privacy? - Risk Insight\" \/>\n<meta property=\"og:description\" content=\"ISO published in August 2019 its standard ISO 27701, extension of ISO 27001 for the protection of personal data and privacy.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/\" \/>\n<meta property=\"og:site_name\" content=\"RiskInsight\" \/>\n<meta property=\"article:published_time\" content=\"2020-01-10T22:03:54+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-01-31T15:32:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/12\/Fotolia_85992681_Subscription_Monthly_M.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1378\" \/>\n\t<meta property=\"og:image:height\" content=\"1378\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Alexandre Bianchi, Jordan Lisotti\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alexandre Bianchi, Jordan Lisotti\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/\"},\"author\":{\"name\":\"Alexandre Bianchi\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/14e7fc161d716aa0ac638552de081cf9\"},\"headline\":\"ISO 27701: one more compliance text or the long-awaited international framework for privacy protection?\",\"datePublished\":\"2020-01-10T22:03:54+00:00\",\"dateModified\":\"2020-01-31T15:32:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/\"},\"wordCount\":894,\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/12\/Fotolia_85992681_Subscription_Monthly_M.jpg\",\"keywords\":[\"digital privacy\",\"GDPR\",\"ISMS\",\"ISO 27701\",\"privacy\",\"standard\"],\"articleSection\":[\"Cybersecurity &amp; Digital Trust\",\"Digital Compliance\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/\",\"name\":\"ISO 27701: an international framework for privacy? - Risk Insight\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/12\/Fotolia_85992681_Subscription_Monthly_M.jpg\",\"datePublished\":\"2020-01-10T22:03:54+00:00\",\"dateModified\":\"2020-01-31T15:32:59+00:00\",\"description\":\"ISO published in August 2019 its standard ISO 27701, extension of ISO 27001 for the protection of personal data and privacy.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#primaryimage\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/12\/Fotolia_85992681_Subscription_Monthly_M.jpg\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/12\/Fotolia_85992681_Subscription_Monthly_M.jpg\",\"width\":1378,\"height\":1378},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ISO 27701: one more compliance text or the long-awaited international framework for privacy protection?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"name\":\"RiskInsight\",\"description\":\"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants\",\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\",\"name\":\"Wavestone\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"width\":50,\"height\":50,\"caption\":\"Wavestone\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/14e7fc161d716aa0ac638552de081cf9\",\"name\":\"Alexandre Bianchi\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/author\/alexandre-bianchi\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ISO 27701: an international framework for privacy? - Risk Insight","description":"ISO published in August 2019 its standard ISO 27701, extension of ISO 27001 for the protection of personal data and privacy.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/","og_locale":"en_US","og_type":"article","og_title":"ISO 27701: an international framework for privacy? - Risk Insight","og_description":"ISO published in August 2019 its standard ISO 27701, extension of ISO 27001 for the protection of personal data and privacy.","og_url":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/","og_site_name":"RiskInsight","article_published_time":"2020-01-10T22:03:54+00:00","article_modified_time":"2020-01-31T15:32:59+00:00","og_image":[{"width":1378,"height":1378,"url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/12\/Fotolia_85992681_Subscription_Monthly_M.jpg","type":"image\/jpeg"}],"author":"Alexandre Bianchi, Jordan Lisotti","twitter_misc":{"Written by":"Alexandre Bianchi, Jordan Lisotti","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#article","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/"},"author":{"name":"Alexandre Bianchi","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/14e7fc161d716aa0ac638552de081cf9"},"headline":"ISO 27701: one more compliance text or the long-awaited international framework for privacy protection?","datePublished":"2020-01-10T22:03:54+00:00","dateModified":"2020-01-31T15:32:59+00:00","mainEntityOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/"},"wordCount":894,"publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/12\/Fotolia_85992681_Subscription_Monthly_M.jpg","keywords":["digital privacy","GDPR","ISMS","ISO 27701","privacy","standard"],"articleSection":["Cybersecurity &amp; Digital Trust","Digital Compliance"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/","url":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/","name":"ISO 27701: an international framework for privacy? - Risk Insight","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#primaryimage"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/12\/Fotolia_85992681_Subscription_Monthly_M.jpg","datePublished":"2020-01-10T22:03:54+00:00","dateModified":"2020-01-31T15:32:59+00:00","description":"ISO published in August 2019 its standard ISO 27701, extension of ISO 27001 for the protection of personal data and privacy.","breadcrumb":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#primaryimage","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/12\/Fotolia_85992681_Subscription_Monthly_M.jpg","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2018\/12\/Fotolia_85992681_Subscription_Monthly_M.jpg","width":1378,"height":1378},{"@type":"BreadcrumbList","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2020\/01\/iso-27701-international-framework-privacy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.riskinsight-wavestone.com\/en\/"},{"@type":"ListItem","position":2,"name":"ISO 27701: one more compliance text or the long-awaited international framework for privacy protection?"}]},{"@type":"WebSite","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","name":"RiskInsight","description":"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants","publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization","name":"Wavestone","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","width":50,"height":50,"caption":"Wavestone"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/14e7fc161d716aa0ac638552de081cf9","name":"Alexandre Bianchi","url":"https:\/\/www.riskinsight-wavestone.com\/en\/author\/alexandre-bianchi\/"}]}},"_links":{"self":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/12561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/users\/1338"}],"replies":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/comments?post=12561"}],"version-history":[{"count":9,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/12561\/revisions"}],"predecessor-version":[{"id":12611,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/12561\/revisions\/12611"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media\/11476"}],"wp:attachment":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media?parent=12561"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/categories?post=12561"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/tags?post=12561"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/coauthors?post=12561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}