• Skip to main content
  • Skip to footer
  • About
    • Leadership
    • Code of Ethics
    • Privacy Commitment
    • PACC Fellows
    • Speaking Invitations & Media Requests
  • Get Involved
    • Join the PACC
      • Advancing the Profession
      • Member Benefits
      • Why Join the PACC
        • Sponsors and Partners
      • Member Contact Update
    • Subscribe
    • Donate
      • Donor Bill of Rights
    • Speak Out
    • Volunteer
  • Certification
    • Guiding the Profession
    • Why Pursue Certification?
    • Benefits of Certification
    • Certificate or Certification?
    • Recertification
    • Certification FAQ
    • Accreditation
  • Careers
    • Current Opportunities
  • Resources
    • Strategic Privacy and Access Resource Center
      • Parents & Teachers
      • Standards
      • International Data Flows
      • SPARC Contribution Guidelines
      • Commissioners & Legislation
    • Reports
    • Recommended Reading
    • Media
    • Reports
  • News & Views
  • Training
    • Events Calendar
    • Privacy & Data Governance Congress 2026
    • Congress 2025 Presentation Resources
    • Past Events
    • Professional Development
    • Suggest a Speaker
  • Bill C-2
  • Login

Privacy and Access Council of Canada

The voice for privacy and access

ISO/IEC FDIS 27701 Review

27/Dec/2024

Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance

The updated version of the Privacy Information Management System, which will replace ISO/IEC 27701:2019, is now in the approval phase. The final version is expected to be published in Q1 of 2025.

The standard specifies requirements for establishing, implementing, maintaining and continually improving a privacy information management system (PIMS), and is applicable to all types and sizes of organizations, including public and private companies, government entities and not-for-profit organizations

In anticipation of the updated version being released, privacy practitioners — including all controllers and processors responsible and accountable for PII processing — would be prudent to review the draft and use it to review and update existing policies, roles and responsibility descriptions, and risk management approaches.

Filed Under: Standards Tagged With: Data Protection, Privacy

Footer

PACC is THE voice for privacy and access.

PACC is Independent  •  Non-profit  •  Non-partisan  •  Non-government

PACC is dedicated to the development and promotion of the access-to-information, information privacy, and data governance profession across the private, non-profit and public sectors.

PACC is the certifying body for access and privacy professionals, and engages in outreach efforts to advance awareness about access, privacy, and data protection.

None of the content herein may be used or reproduced in any manner for the purpose of training AI technologies or systems.

Recent Posts

  • Setting the Standard for Privacy Expertise in Canada
  • Data Governance Standard up for review and comment
  • Combination of legislative bills strips away Canadians’ rights
  • Global Comparative Testing of Responses to FOI Requests
  • PACC Joins the Call to Withdraw Bill C-2
  • Transparency Performance Indicators

ABOUT

MEMBERSHIP

CERTIFICATION

CAREERS

RESOURCES

BLOG

CONTACT

PRIVACY

 

Thanks to QuestionPro’s wide range of free survey templates designed by industry experts. We now know exactly where to improve
…………

© 2025 · Privacy and Access Council of Canada · Maintained by SLIcore Design.

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.