Papers
PAPER21 pages, open access

A systematic approach for the protection of personal data and privacy

Miguel AzevedoQity
Download the PDF
TL;DR
  • 01The GDPR requires measures that stay effective as circumstances change, and the ability to demonstrate what was done. A shelf of privacy documents does not meet that.
  • 02ISO/IEC 27701:2025 states the same problem as a privacy information management system, which small organisations often read as disproportionate.
  • 03The proposed framework holds processing activities, risks, controls, requests, incidents, and evidence as controlled records and decisions instead of scattered artifacts.
  • 04That separates three distinct claims: what the platform provides, what the organisation concludes about its own compliance, and what a certification body determines.

Abstract

The General Data Protection Regulation does not merely require organisations to possess privacy documents. It requires controllers and processors to implement appropriate measures, keep those measures effective as circumstances change, and be able to demonstrate what they have done.

ISO/IEC 27701:2025 expresses the same operational problem as a privacy information management system: context, leadership, planning, support, operation, performance evaluation, and improvement must work as a coherent system. For a young company this can look disproportionate to its resources. For an experienced data protection officer the difficulty is different but related, because facts, decisions, risks, controls, requests, incidents, and evidence are distributed across people, spreadsheets, tickets, contracts, and documents.

Contents

  • Why privacy compliance resists checklist treatment
  • Normative and research foundations
  • A systematic framework for privacy accountability
  • Controlled entity and relationship model
  • Risk, controls, DPIA, and evidence
  • Operational rights, incidents, processors, and transfers
  • ISO/IEC 27701 management-system integration
  • Demonstrability, assurance, and change

Built for regulated industries

ISO 9001ISO 13485ISO 27001EU MDR / IVDRGDPRFDA