ISO/IEC 27701 readiness for how we handle PII
ISO 27701 extends an ISO 27001 ISMS into a Privacy Information Management System (PIMS). We track both processor duties (your employee simulation data) and controller duties (our marketing leads and admin accounts). This page is readiness only — not a certificate.
Honest claim language
This PIMS Statement of Applicability is an internal readiness draft. It is NOT an ISO 27701 certificate. Certification requires an accredited body after operating a PIMS (typically with ISO 27001).
Combined score
68.4%
Avg of controls + PIMS clauses
Privacy controls
76.4%
49 applicable of 51
PIMS clauses
60.4%
24 requirements
Status mix
How we show up under privacy law
Processor
For customer Google Workspace users and phishing simulation/analytics data, the customer organization is the controller (or public-body custodian) and PhishGuard is the processor / service provider.
Controller
For marketing leads, website form submissions, and PhishGuard admin accounts of customer operators, PhishGuard is the controller.
Privacy information management for PhishGuard: (1) processing of customer employee data for phishing simulations and reporting under customer instructions; (2) processing of business contact and admin account data for sales, onboarding, and product administration; primarily serving Canadian organizations on Google Workspace.
PII we may process
- ·Business contact data (name, work email, org, role) from marketing/pilot forms
- ·Customer admin account identifiers
- ·Customer employee directory attributes used for targeting (email, name, OU/department as provided)
- ·Simulation interaction events (sent/open/click/report) linked to users
- ·Support communications
What we never collect
- ·Employee passwords or credentials from simulations
- ·Personal consumer email content unrelated to authorized simulations
Laws we design for
- ·PIPEDA
- ·Provincial public-sector privacy (e.g. FOIP/FIPPA)
- ·Québec Law 25 (when serving QC)
- ·Customer employment/privacy policies
PIMS management requirements
Privacy-specific management-system requirements that extend your ISO 27001 ISMS.
| ID | Requirement | Group | Status | Notes |
|---|---|---|---|---|
| 5.2.1 | Understanding the organization and its context — privacy | Context | Implemented | Privacy context in PIMS SoA + policy |
| 5.2.2 | Understanding needs of interested parties — privacy | Context | Implemented | Interested parties documented |
| 5.2.3 | Determining the scope of the PIMS | Context | Implemented | PIMS scope in privacy SoA |
| 5.2.4 | PIMS and ISO 27001 ISMS integration | Context | Implemented | Integrated with ISO 27001 evidence pack |
| 5.3.1 | Leadership and commitment — privacy | Leadership | Implemented | Founder commitment via approved policies |
| 5.3.2 | Policy — privacy | Leadership | Implemented | Privacy policy live |
| 5.3.3 | Roles, responsibilities and authorities — privacy | Leadership | Implemented | privacy@ contact as privacy lead channel |
| 5.4.1 | Actions to address risks and opportunities — privacy | Planning | In progress | Privacy risks via SoA + remediation |
| 5.4.1.2 | Information security risk assessment — PII | Planning | In progress | PII included in program risk docs |
| 5.4.1.3 | Information security risk treatment — PII | Planning | Implemented | PIMS SoA draft |
| 5.4.2 | Privacy objectives and planning | Planning | Implemented | Privacy objectives: no passwords, consent on leads, deletion SLAs |
| 5.5.1 | Resources — privacy | Support | Implemented | Resources for PIMS documented |
| 5.5.2 | Competence — privacy | Support | In progress | Competence via playbooks for privacy lead |
| 5.5.3 | Awareness — privacy | Support | In progress | Awareness via AUP for anyone with data access |
| 5.5.4 | Communication — privacy | Support | Implemented | Public privacy/security/subprocessor pages |
| 5.5.5 | Documented information — privacy | Support | Implemented | Documented PIMS evidence set |
| 5.6.1 | Operational planning and control — privacy | Operation | Implemented | Operational privacy controls in product + policies |
| 5.6.2 | Information security risk assessment — operational privacy | Operation | In progress | Privacy risk review with access reviews |
| 5.6.3 | Information security risk treatment — operational privacy | Operation | In progress | Treatment via SoA controls in force |
| 5.7.1 | Monitoring, measurement, analysis and evaluation — privacy | Performance | Implemented | Readiness metrics + compliance CI |
| 5.7.2 | Internal audit — privacy | Performance | Planned | Internal audit includes PIMS |
| 5.7.3 | Management review — privacy | Performance | Planned | Management review includes privacy |
| 5.8.1 | Nonconformity and corrective action — privacy | Improvement | Planned | Corrective action for privacy issues |
| 5.8.2 | Continual improvement — privacy | Improvement | Planned | Continual improvement log |
Privacy controls (controller & processor)
Annex-style controls for PII controllers and processors. Titles are for readiness tracking; full normative text is in the official ISO/IEC 27701 standard.
Controller controls (our leads & admin data)
76.4% · 31 controls
| ID | Control | Status | Notes |
|---|---|---|---|
| A.7.2.1 | Identify and document purpose | Implemented | Purposes documented in privacy policy + RoPA |
| A.7.2.2 | Identify lawful basis | Implemented | Role and basis summary in privacy policy |
| A.7.2.3 | Determine when/how consent is obtained | Implemented | Lead form privacy consent checkbox |
| A.7.2.4 | Privacy impact assessment / risk | Implemented | PIA template for customer programs |
| A.7.2.5 | Contracts with PII processors | Implemented | DPA pilot addendum template |
| A.7.2.6 | Joint controller arrangements | N/A | No joint controller model planned for core SaaS |
| A.7.2.7 | Records of processing | Implemented | RoPA draft v0.1 |
| A.7.2.8 | Privacy by design and by default | Implemented | Privacy by design: dry-run, no password capture, isolation |
| A.7.3.1 | Consent and choice | Implemented | Consent/notice on marketing lead form |
| A.7.3.2 | Purpose legitimation and specification | Implemented | Purpose limitation in policy + terms |
| A.7.3.3 | Collection limitation | Implemented | Collection limitation described in privacy policy |
| A.7.3.4 | Data minimization | Implemented | Minimization in product design + policy |
| A.7.3.5 | Accuracy and quality | In progress | Accuracy via customer directory as source of truth |
| A.7.3.6 | Use, retention and disclosure limitation | Implemented | Retention schedule v0.1 |
| A.7.3.7 | Temporary files | In progress | Temp files covered under classification + deletion |
| A.7.3.8 | Disposal | Implemented | Deletion runbook v0.1 |
| A.7.3.9 | PII transfer controls | Implemented | Transfer posture in privacy + DPA |
| A.7.3.10 | Transfer to third parties | Implemented | Subprocessor list published |
| A.7.4.1 | Privacy notices | Implemented | Privacy policy published |
| A.7.4.2 | Enabling exercise of rights | Implemented | DSAR playbook v0.1 |
| A.7.4.3 | Access requests | Implemented | Access requests via privacy@ |
| A.7.4.4 | Correction requests | Implemented | Correction via privacy@ |
| A.7.4.5 | Deletion / withdrawal | Implemented | Deletion/opt-out process documented |
| A.7.4.6 | Objection / restriction | In progress | Objection handling via privacy@ in DSAR playbook |
| A.7.4.7 | Automated decision making | N/A | No automated legal/ similarly significant decisions about individuals |
| A.7.4.8 | Complaints | Implemented | privacy@phishguard.ca published |
| A.7.4.9 | Sharing obligations with processors | Implemented | Relay processor requests in DSAR playbook |
| A.7.5.1 | Security safeguards for PII | Implemented | Security safeguards + IR + policies |
| A.7.5.2 | Breach notification — authorities | Implemented | Authority notification path in IR plan |
| A.7.5.3 | Breach notification — principals | Implemented | Principal notification criteria in IR plan |
| A.7.5.4 | Disclosure of breaches to processors/controllers | Implemented | Customer breach coordination in IR + DPA |
Processor controls (your employee program data)
76.5% · 20 controls
| ID | Control | Status | Notes |
|---|---|---|---|
| B.8.2.1 | Customer agreement — processing instructions | Implemented | Process under customer instructions — terms + product admin |
| B.8.2.2 | Customer agreement — purpose limitation | Implemented | Purpose limitation in terms/privacy |
| B.8.2.3 | Customer agreement — marketing / secondary use | Implemented | No use of customer employee PII for PhishGuard marketing |
| B.8.2.4 | Customer agreement — subcontractors | Implemented | Subprocessor list + notification process with 10-business-day objection window per DPA |
| B.8.2.5 | Customer agreement — security | Implemented | Security measures documented publicly |
| B.8.2.6 | Customer agreement — breach notice | Implemented | Breach-to-customer target in IR plan (≤72h) |
| B.8.2.7 | Customer agreement — return/deletion | Implemented | Return/delete runbook |
| B.8.2.8 | Customer agreement — audit/assistance | Implemented | Audit/questionnaire assistance via FAQ + evidence pack |
| B.8.3.1 | Obligations to PII principals | Implemented | Controller/processor roles in privacy policy |
| B.8.3.2 | Marketing and advertising | Implemented | No secondary marketing on customer tenant data |
| B.8.3.3 | Infringing instruction handling | In progress | Unlawful instruction handling noted in DPA customer obligations framing |
| B.8.4.1 | Temporary files | In progress | Temp artifact handling via classification/deletion |
| B.8.4.2 | Return, transfer or disposal of PII | Implemented | Deletion runbook |
| B.8.4.3 | PII transmission controls | Implemented | TLS + crypto policy |
| B.8.5.1 | Records of processing (processor) | Implemented | Processor activities in RoPA |
| B.8.5.2 | Security of processing | Implemented | Security of processing — policies + product controls |
| B.8.5.3 | Data breach response cooperation | Implemented | Breach cooperation in IR + DPA |
| B.8.5.4 | Sub-processor register | Implemented | Subprocessor register page |
| B.8.5.5 | Assistance with principal rights | Implemented | Assist with principal rights — DSAR playbook |
| B.8.5.6 | Assistance with privacy impact assessments | Implemented | PIA template for customers |
How this fits your Canadian program
You stay the custodian
For employee simulation data, your organization remains controller/custodian. We process under your instructions and contract.
Product safeguards
No password capture, dry-run defaults, tenant isolation — privacy by design, not only policy paper.
Builds on ISO 27001
27701 extends the ISMS. See our ISO 27001 tracker for security controls that protect PII.
Evaluating privacy for a pilot?
We share the PIMS SoA draft, subprocessors, and deletion posture — without claiming a certificate we do not hold.
Related: ISO 27001 · SOC 2 readiness