TCPTCP OpsPrivacy Management

ISO/IEC 27701 · PRIVACY MANAGEMENT READINESS

Privacy management that works as a system.

TCP Privacy connects PIMS, privacy operations, registers, evidence and continual improvement in one controlled environment for traceable privacy management and ISO/IEC 27701 readiness.

Explore productManual

Sign up with email and password or Google · Essential edition · one month

From requirement to auditable evidenceOne readiness chain
ISO/IEC 27701→PIMS→Operations & registers→Evidence & improvement
GovernanceControlsInternal auditReadiness
Readiness must exist in operation, not only on paper.

TCP Privacy connects the effective PIMS state to day-to-day privacy work, registers, evidence and continual improvement.

PIMSPrivacy operationsRegistersEvidenceContinual improvement

FROM REQUIREMENT TO OPERATION

Build, operate and improve one controlled management system.

Privacy management is not merely a documentation project. Policies, responsibilities, operations, registers, evidence and improvement have to work together. TCP Privacy keeps that chain controlled and traceable.

01

Build your PIMS for ISO/IEC 27701

Turn privacy-management requirements into governed policies, responsibilities, documents and evidence in one versioned Privacy Information Management System.

02

Operate privacy according to the PIMS

Run processing activities, processor reviews, data-subject requests and incidents through structured workflows tied to the effective management-system state.

03

Maintain registers and evidence

Keep registers, decisions and evidence connected to execution so operational records support traceability, review and audit readiness.

04

Improve effectiveness continuously

Use KPIs, findings, measures, control tests, internal audits and management reviews to close gaps systematically and demonstrate continual improvement.

AI ACCELERATES · GOVERNANCE STAYS AUTHORITATIVE

Use AI to accelerate the work without letting AI redefine the management system.

TCP Privacy can support structured PIMS content, operational workflows, translations and analysis while authoritative sources, roles, mappings, reviews and approvals remain binding.

01Authoritative sources

Active PIMS content, requirements, mappings and governance define the controlled context.

02Structured operation

Questions, decisions, registers, actions and evidence follow explicit system contracts.

03Evidence by design

Execution remains traceable so reviews and audits can build on the operating state.

GOVERNANCE & TRACEABILITY

Traceability instead of file chaos.

TCP Privacy is designed for organizations that want to move from isolated privacy documentation to an operated, evidenced and continually improved privacy management system.

DATA SOVEREIGNTY

Keep control of your data.

Tenant administrators can download the full customer-side tenant data as a verifiable ZIP backup. A controlled restore process supports selective restoration of functionally consistent areas.

Verifiable tenant backupsControlled selective restoreRoles & permissionsAuditable history

QUESTIONS & ANSWERS

ISO/IEC 27701 and privacy management explained clearly.

Open a question for a concise explanation. The public manual covers the concrete use of TCP Privacy.

What is ISO/IEC 27701?

ISO/IEC 27701 is an international management-system standard for Privacy Information Management Systems (PIMS). It structures the establishment, operation, maintenance and continual improvement of a privacy management system.

What is the difference between ISO/IEC 27001 and ISO/IEC 27701?

ISO/IEC 27001 addresses information-security management through an ISMS. ISO/IEC 27701 addresses privacy management through a PIMS. The systems can work closely together but have different management objectives and evidence requirements.

What is a PIMS?

A Privacy Information Management System connects privacy requirements with roles, responsibilities, documented rules, operational processes, evidence, review and continual improvement.

Can ISO/IEC 27701 be used without ISO/IEC 27001?

ISO/IEC 27701:2025 is structured as a standalone management-system standard. An organization can therefore establish its PIMS independently while still using interfaces to an existing ISMS.

How do ISO/IEC 27701 and the GDPR relate?

ISO/IEC 27701 provides a management-system framework for organizing privacy obligations, responsibilities and evidence. The specific legal assessment under the GDPR and other privacy laws remains a separate responsibility.

Does ISO/IEC 27701 automatically mean GDPR compliance?

No. A PIMS supports systematic privacy management and accountability, but it does not replace legal assessment or the organization’s responsibility to comply with applicable law.

What is the difference between a controller and a processor?

A controller determines the purposes and essential means of processing personal data. A processor processes personal data on behalf of and under the instructions of the controller. The role affects obligations, contracts and evidence in the PIMS.

Which documents does a PIMS need?

The required documentation depends on the organization, roles, processing activities, risks and governance. TCP Privacy connects structured inputs with versioned PIMS documents instead of assuming one universal document list.

Why are privacy policies alone not enough?

A management system has to operate effectively. Responsibilities, decisions, workflows, registers, evidence, controls and improvements must work together in day-to-day operations and remain traceable.

What role do registers and evidence play?

Registers keep structured privacy facts and current states traceable. Evidence supports statements, decisions, controls and process steps. TCP Privacy connects both to operational work.

What does Privacy Management Readiness mean?

Readiness means that privacy management is not merely documented but actually works and can be reviewed through roles, processes, evidence, reviews and improvement mechanisms.

How does TCP Privacy support ISO/IEC 27701 certification?

TCP Privacy supports establishment, operation, evidence and continual improvement of the PIMS and preparation for reviews and audits. Certification decisions are made solely by the independent certification body.

How do internal audits and management reviews work?

Internal audits assess defined criteria using traceable evidence. Management reviews evaluate the state and effectiveness of the management system. Results can trigger findings, actions and further improvement.

What are CAPA and continual improvement?

Corrective and Preventive Actions structure the handling of identified or potential deviations. The action itself is only one part; ownership, deadline, evidence and effectiveness review are equally important.

How are organizational changes reflected in the PIMS?

Changes to organization, processing, providers or governance can require reassessment and potentially a new PIMS version. TCP Privacy retains prior states and governs changes through versioning.

How does TCP Privacy support DPIAs and risk-related processes?

Relevant cases can be handled through structured workflows with inputs, decisions, evidence and governance steps. The required assessment depends on the specific process and the organization’s applicable requirements.

How are processors and service providers managed?

Provider information, reviews, decisions and evidence can be recorded in a structured way and maintained through operational workflows, keeping governance and execution connected.

How are privacy incidents and data-subject rights handled?

TCP Privacy can govern concrete privacy cases through defined workflows. Steps, responsibilities, evidence and decisions remain bound to the applicable workflow and PIMS state.

Which tasks can AI support and which decisions remain human?

AI can support structured content, drafts, translations and analysis. Authoritative sources, governance, roles, approvals and binding decisions remain controlled and are not replaced by unconstrained AI output.

How are customer data backed up and restored?

Tenant administrators can download the tenant’s customer data as a verifiable ZIP backup. A controlled restore process can return consistent functional areas to the backup state; a safety backup is created before every destructive restore.

Who can access customer data?

Tenant roles and permissions restrict access within the organization. Administrative and functional responsibilities are separated and governed according to required access.

Can TCP Privacy support multiple companies or organizational units?

TCP Privacy uses a tenant-based organization and permission structure. How multiple companies or units are represented depends on the chosen organizational model and edition.

How can TCP Privacy be tested?

The Essential edition can be evaluated for one month through the public trial process. The trial starts through registration on tcpops.com.

EDITIONS

Start with Essential and expand when needed.

Online prices are net in EUR. Enterprise is offered individually.

Essential

99 € per month990 € per year

PIMS and core privacy operations for getting started.

Professional

299 € per month2.990 € per year

Extended operational and continual-improvement capabilities.

Enterprise

Price on request 

Advanced governance, audit and organizational requirements.

Contact

START YOUR PRIVACY MANAGEMENT JOURNEY

Build the evidence behind your readiness.

Start with TCP Privacy Essential for one month and begin with a controlled PIMS, structured operations and traceable evidence.