Skip to content
PIMS · privacy extension · not a certificate

ISO/IEC 27701 readiness for how we handle PII

ISO 27701 extends an ISO 27001 ISMS into a Privacy Information Management System (PIMS). We track both processor duties (your employee simulation data) and controller duties (our marketing leads and admin accounts). This page is readiness only — not a certificate.

Honest claim language

This PIMS Statement of Applicability is an internal readiness draft. It is NOT an ISO 27701 certificate. Certification requires an accredited body after operating a PIMS (typically with ISO 27001).

Combined score

68.4%

Avg of controls + PIMS clauses

Privacy controls

76.4%

49 applicable of 51

PIMS clauses

60.4%

24 requirements

Status mix

Implemented: 44In progress: 5Planned: 0N/A: 2

How we show up under privacy law

Processor

For customer Google Workspace users and phishing simulation/analytics data, the customer organization is the controller (or public-body custodian) and PhishGuard is the processor / service provider.

Controller

For marketing leads, website form submissions, and PhishGuard admin accounts of customer operators, PhishGuard is the controller.

Privacy information management for PhishGuard: (1) processing of customer employee data for phishing simulations and reporting under customer instructions; (2) processing of business contact and admin account data for sales, onboarding, and product administration; primarily serving Canadian organizations on Google Workspace.

PII we may process

  • ·Business contact data (name, work email, org, role) from marketing/pilot forms
  • ·Customer admin account identifiers
  • ·Customer employee directory attributes used for targeting (email, name, OU/department as provided)
  • ·Simulation interaction events (sent/open/click/report) linked to users
  • ·Support communications

What we never collect

  • ·Employee passwords or credentials from simulations
  • ·Personal consumer email content unrelated to authorized simulations

Laws we design for

  • ·PIPEDA
  • ·Provincial public-sector privacy (e.g. FOIP/FIPPA)
  • ·Québec Law 25 (when serving QC)
  • ·Customer employment/privacy policies

PIMS management requirements

Privacy-specific management-system requirements that extend your ISO 27001 ISMS.

IDRequirementGroupStatusNotes
5.2.1Understanding the organization and its context — privacyContextImplementedPrivacy context in PIMS SoA + policy
5.2.2Understanding needs of interested parties — privacyContextImplementedInterested parties documented
5.2.3Determining the scope of the PIMSContextImplementedPIMS scope in privacy SoA
5.2.4PIMS and ISO 27001 ISMS integrationContextImplementedIntegrated with ISO 27001 evidence pack
5.3.1Leadership and commitment — privacyLeadershipImplementedFounder commitment via approved policies
5.3.2Policy — privacyLeadershipImplementedPrivacy policy live
5.3.3Roles, responsibilities and authorities — privacyLeadershipImplementedprivacy@ contact as privacy lead channel
5.4.1Actions to address risks and opportunities — privacyPlanningIn progressPrivacy risks via SoA + remediation
5.4.1.2Information security risk assessment — PIIPlanningIn progressPII included in program risk docs
5.4.1.3Information security risk treatment — PIIPlanningImplementedPIMS SoA draft
5.4.2Privacy objectives and planningPlanningImplementedPrivacy objectives: no passwords, consent on leads, deletion SLAs
5.5.1Resources — privacySupportImplementedResources for PIMS documented
5.5.2Competence — privacySupportIn progressCompetence via playbooks for privacy lead
5.5.3Awareness — privacySupportIn progressAwareness via AUP for anyone with data access
5.5.4Communication — privacySupportImplementedPublic privacy/security/subprocessor pages
5.5.5Documented information — privacySupportImplementedDocumented PIMS evidence set
5.6.1Operational planning and control — privacyOperationImplementedOperational privacy controls in product + policies
5.6.2Information security risk assessment — operational privacyOperationIn progressPrivacy risk review with access reviews
5.6.3Information security risk treatment — operational privacyOperationIn progressTreatment via SoA controls in force
5.7.1Monitoring, measurement, analysis and evaluation — privacyPerformanceImplementedReadiness metrics + compliance CI
5.7.2Internal audit — privacyPerformancePlannedInternal audit includes PIMS
5.7.3Management review — privacyPerformancePlannedManagement review includes privacy
5.8.1Nonconformity and corrective action — privacyImprovementPlannedCorrective action for privacy issues
5.8.2Continual improvement — privacyImprovementPlannedContinual improvement log

Privacy controls (controller & processor)

Annex-style controls for PII controllers and processors. Titles are for readiness tracking; full normative text is in the official ISO/IEC 27701 standard.

Controller controls (our leads & admin data)

76.4% · 31 controls

IDControlStatusNotes
A.7.2.1Identify and document purposeImplementedPurposes documented in privacy policy + RoPA
A.7.2.2Identify lawful basisImplementedRole and basis summary in privacy policy
A.7.2.3Determine when/how consent is obtainedImplementedLead form privacy consent checkbox
A.7.2.4Privacy impact assessment / riskImplementedPIA template for customer programs
A.7.2.5Contracts with PII processorsImplementedDPA pilot addendum template
A.7.2.6Joint controller arrangementsN/ANo joint controller model planned for core SaaS
A.7.2.7Records of processingImplementedRoPA draft v0.1
A.7.2.8Privacy by design and by defaultImplementedPrivacy by design: dry-run, no password capture, isolation
A.7.3.1Consent and choiceImplementedConsent/notice on marketing lead form
A.7.3.2Purpose legitimation and specificationImplementedPurpose limitation in policy + terms
A.7.3.3Collection limitationImplementedCollection limitation described in privacy policy
A.7.3.4Data minimizationImplementedMinimization in product design + policy
A.7.3.5Accuracy and qualityIn progressAccuracy via customer directory as source of truth
A.7.3.6Use, retention and disclosure limitationImplementedRetention schedule v0.1
A.7.3.7Temporary filesIn progressTemp files covered under classification + deletion
A.7.3.8DisposalImplementedDeletion runbook v0.1
A.7.3.9PII transfer controlsImplementedTransfer posture in privacy + DPA
A.7.3.10Transfer to third partiesImplementedSubprocessor list published
A.7.4.1Privacy noticesImplementedPrivacy policy published
A.7.4.2Enabling exercise of rightsImplementedDSAR playbook v0.1
A.7.4.3Access requestsImplementedAccess requests via privacy@
A.7.4.4Correction requestsImplementedCorrection via privacy@
A.7.4.5Deletion / withdrawalImplementedDeletion/opt-out process documented
A.7.4.6Objection / restrictionIn progressObjection handling via privacy@ in DSAR playbook
A.7.4.7Automated decision makingN/ANo automated legal/ similarly significant decisions about individuals
A.7.4.8ComplaintsImplementedprivacy@phishguard.ca published
A.7.4.9Sharing obligations with processorsImplementedRelay processor requests in DSAR playbook
A.7.5.1Security safeguards for PIIImplementedSecurity safeguards + IR + policies
A.7.5.2Breach notification — authoritiesImplementedAuthority notification path in IR plan
A.7.5.3Breach notification — principalsImplementedPrincipal notification criteria in IR plan
A.7.5.4Disclosure of breaches to processors/controllersImplementedCustomer breach coordination in IR + DPA

Processor controls (your employee program data)

76.5% · 20 controls

IDControlStatusNotes
B.8.2.1Customer agreement — processing instructionsImplementedProcess under customer instructions — terms + product admin
B.8.2.2Customer agreement — purpose limitationImplementedPurpose limitation in terms/privacy
B.8.2.3Customer agreement — marketing / secondary useImplementedNo use of customer employee PII for PhishGuard marketing
B.8.2.4Customer agreement — subcontractorsImplementedSubprocessor list + notification process with 10-business-day objection window per DPA
B.8.2.5Customer agreement — securityImplementedSecurity measures documented publicly
B.8.2.6Customer agreement — breach noticeImplementedBreach-to-customer target in IR plan (≤72h)
B.8.2.7Customer agreement — return/deletionImplementedReturn/delete runbook
B.8.2.8Customer agreement — audit/assistanceImplementedAudit/questionnaire assistance via FAQ + evidence pack
B.8.3.1Obligations to PII principalsImplementedController/processor roles in privacy policy
B.8.3.2Marketing and advertisingImplementedNo secondary marketing on customer tenant data
B.8.3.3Infringing instruction handlingIn progressUnlawful instruction handling noted in DPA customer obligations framing
B.8.4.1Temporary filesIn progressTemp artifact handling via classification/deletion
B.8.4.2Return, transfer or disposal of PIIImplementedDeletion runbook
B.8.4.3PII transmission controlsImplementedTLS + crypto policy
B.8.5.1Records of processing (processor)ImplementedProcessor activities in RoPA
B.8.5.2Security of processingImplementedSecurity of processing — policies + product controls
B.8.5.3Data breach response cooperationImplementedBreach cooperation in IR + DPA
B.8.5.4Sub-processor registerImplementedSubprocessor register page
B.8.5.5Assistance with principal rightsImplementedAssist with principal rights — DSAR playbook
B.8.5.6Assistance with privacy impact assessmentsImplementedPIA template for customers

How this fits your Canadian program

You stay the custodian

For employee simulation data, your organization remains controller/custodian. We process under your instructions and contract.

Product safeguards

No password capture, dry-run defaults, tenant isolation — privacy by design, not only policy paper.

Builds on ISO 27001

27701 extends the ISMS. See our ISO 27001 tracker for security controls that protect PII.

Evaluating privacy for a pilot?

We share the PIMS SoA draft, subprocessors, and deletion posture — without claiming a certificate we do not hold.

Related: ISO 27001 · SOC 2 readiness