
Win trust. Meet the APPs.Prove Privacy.
Going it alone eats months of internal effort. We take the whole build off your plate — gap analysis to certification.
ISO 27701 is the international standard for managing personal information — a Privacy Information Management System that shows customers, regulators and partners you handle data the right way. Done-for-you, fixed fee, dedicated Australian consultant.
Part of the global IMSM network
1 fee
fixed and agreed upfront — no hourly billing
13 APPs
the Australian Privacy Principles your PIMS is built to meet
JAS-ANZ
accredited certification recognised across Australia and abroad
3 years
certification valid for three years, with annual surveillance audits
What a Privacy Information Management System puts in place
A single source of truth for personal data
Every category of personal information you hold, mapped to its purpose, lawful basis, retention and data flows — so you always know what you have and why.
Defined privacy roles and accountability
Clear ownership of privacy across the business, with controller and processor duties spelled out and someone accountable for keeping the system running.
Transparent notices, consent and rights handling
Privacy notices, consent records and processes for access and correction requests that stand up to scrutiny from customers and the OAIC alike.
A tested breach-response plan
A documented process to detect, contain and report a data breach, including notifiable-breach assessment, so you act quickly and correctly under pressure.
Tell us your situation and headcount, we'll scope your fixed fee within 24 hours.
Get my fixed-fee quote →What ISO 27701 certification involves
ISO 27701 sets out a Privacy Information Management System (PIMS) — the privacy layer that sits alongside ISO 27001's information-security controls and turns good intentions into a system you can prove. IMSM builds it around how your business actually collects, uses and shares personal information, then takes you through to certification by a JAS-ANZ-accredited third-party body. One fixed fee, agreed upfront.
Builds on your security foundation
ISO 27701 works hand-in-hand with ISO 27001's information-security controls, extending them to privacy. If you already hold ISO 27001 much of the groundwork is done; if not, we put the necessary security controls in place alongside the privacy system.
Privacy controls that fit your business
We implement the PIMS controls in plain English and shape them around how your team actually works — no jargon-heavy manual that sits on a shelf.
Your role: controller, processor or both
We define whether you act as a PII controller, a processor, or both, and set the right obligations for each so nothing falls through the gaps.
Personal-information inventory and data flows
We map what personal information you hold, where it comes from, where it goes and who can access it — the backbone of any credible privacy system.
Privacy notices and consent
We put clear privacy notices, lawful-basis records and consent handling in place so collection and use of personal information is transparent and defensible.
Subject rights and breach response
We build simple processes for handling access and correction requests and for responding to a data breach, including notification to affected people and the OAIC where required.
What ISO 27701 does for your business
Alignment with the Privacy Act and APPs
ISO 27701 maps neatly to the Australian Privacy Principles under the Privacy Act 1988, giving you a documented, repeatable way to meet your obligations rather than hoping you've covered them.
Ready for privacy reform
Australia's privacy landscape is tightening, with tougher penalties, a statutory tort for serious invasions of privacy and further reforms on the way. A PIMS gives you a structure that adapts as the rules change instead of a scramble each time they do.
Passes enterprise and government due diligence
Procurement teams, primes and government buyers increasingly ask how you protect personal data. Certification answers that question up front and keeps you on the shortlist instead of stuck in a questionnaire.
Lower breach and notification risk
By mapping your data flows and tightening controls, you reduce the chance of a notifiable data breach to the OAIC — and the reputational and financial damage that comes with one.
Clear controller and processor obligations
Whether you decide how personal information is used, handle it for clients, or both, ISO 27701 sets out exactly what each role must do — so responsibilities are defined, not assumed.
Customer and partner trust
Certification is independent proof that privacy is managed properly, giving customers, suppliers and partners confidence to share data and do business with you.
Ready for your fixed-fee quote?
Tell us where to send it — your exact ISO 27701 fixed fee, back within 24 hours. No obligation.
Who ISO 27701 is for in Australia
Not sure if ISO 27701 fits your sector? Tell us what you do, we'll tell you straight, no pressure.
Get my fixed-fee quoteWhat does ISO 27701 certification cost?
Your fee depends on one thing: the size of your organisation. Tell us your headcount and we'll send a single fixed fee covering gap analysis, documentation, consultancy and your certification audit, agreed upfront, no hourly billing, no surprises.
Get your ISO 27701 fixed fee
One number, agreed upfront — gap analysis, documentation, implementation and audit. Sent within 24 hours.
Five steps to certified
One dedicated Australian consultant from quote to certificate, we do the heavy lifting.
- 01
Quick quote & scope
Tell us your standard and headcount, your quote arrives within 24 hours, agreed before we start.
- 02
Gap analysis
Your dedicated consultant maps what you already have against the standard, so you only build what's missing.
- 03
System build
We write the policies, procedures and records with you, tailored to how your business actually operates.
- 04
Implementation & internal audit
We embed the system, train your team and run the internal audit to confirm you're ready.
- 05
Certification audit
We prepare and support you through the audit, independent or JAS-ANZ accredited, your choice.


EFQM 5★ Recognised for Excellence
Fewer than 400 organisations worldwide hold it, IMSM is one of them
Think of it as ISO certification for our own business, we hold ourselves to the same standard we hold you to.
It's an independent assessment of our own quality management against the European Foundation for Quality Management framework.
ISO 27701, common questions
How long does ISO 27701 certification take?+
It depends on the size and complexity of your business and how much you already have in place — particularly whether you already hold ISO 27001, which does much of the heavy lifting. Because every business is different, we don't quote a generic timeframe. At the gap-analysis stage your dedicated consultant maps your current position and agrees a realistic timeline with you before any work begins.
How does ISO 27701 relate to ISO 27001?+
ISO 27701 is the privacy standard that works alongside ISO 27001's information-security standard. It began life as an extension to ISO 27001, and the current edition can now be certified on its own — but it is still most powerful implemented together, because a privacy system relies on strong underlying security. If you already hold ISO 27001, you're well on the way; if not, we put the necessary security controls in place as part of the project.
Does ISO 27701 help us comply with the Australian Privacy Act and the APPs?+
Yes. ISO 27701 gives you a structured operating model that maps to the Australian Privacy Principles under the Privacy Act 1988 — covering collection, use, disclosure, access, correction, retention and breach handling. It doesn't replace legal advice, but it's a recognised, auditable way to demonstrate you're taking reasonable steps to meet your obligations and to prepare for ongoing privacy reform.
Do we need ISO 27701 if we already handle privacy carefully?+
Handling privacy carefully and being able to prove it are two different things. Certification gives you independent, third-party evidence that your practices meet an international standard — the kind of assurance customers, procurement teams and regulators increasingly ask for, and something an internal policy alone can't provide.
Are we a PII controller or a PII processor?+
You may be either or both. You're a controller when you decide how and why personal information is used, and a processor when you handle it on behalf of another organisation — for example a client. Many businesses do both. As part of the project we define your role for each activity and apply the right obligations, so nothing is left unclear.
Who certifies us, and is it recognised in Australia?+
Certification is issued by an independent, JAS-ANZ-accredited certification body — not by IMSM. We build your Privacy Information Management System and prepare you fully for the audit; the accredited body carries out the assessment and issues the certificate, which is recognised across Australia and internationally.
Ready to get ISO 27701 certified?
Most clients have their quote within 24 hours. Let's see what certification looks like for your business.