PIMS Implementation Roadmap
Stage Primary Deliverable Time Line
Activity
Stage Gap Analysis ISO 27701 GAP Analysis 3-4 Days
1 and Awareness ISO 27701 End user awareness
training
Stage PIMS PIMS Manual 50 Days
2 Documentation PIMS Scope Definition
Procedure for Control of
Documents
Process for Risk Management
Information Security Policies
Privacy by Design and by Default
Policy
Privacy Objectives and Planning
Process for Internal Audit and
Management Review
Process for Access Control
Management
Process for Organization of
Information Security
Policy for Teleworking and Mobile
Device Policy
Policy for Human Resource
Security
Policy for Asset Management
Policy for Information Classification
Policy for Information Governance
Firewall Policy
Password Policy
Physical and Environment Security
Policy
Operation Security Policy
Communication Security Policy
Internet & Email Use Policy
Policy for System Acquisition
Development & Maintenance
Policy for information Security in
Project Management Policy
Supplier Relationship Policy
Incident Response Policy
Business Continuity Policy
Compliance Policy
Procedure for Collecting and
Processing Personal Data
Procedure for Contracted PII
Processing
Data Protection and Privacy Policy
Procedure for PII Disclosure
Procedure for Privacy Impact
Assessment
Procedure for Processing Contracts
Procedure for Records of
Processing
Procedure for Subcontracted
Processing
Procedure for Subject Access
Request
Procedure for Transmission of PII
Policy for Data Retention
Procedure for Cross-border
processing or transfers of personal
data
Cookies Policy
Procedure for Obligations to PII
Principals
Data Protection Officer Job
Description
PII Disclosure Record
PII Processing Activity Record
Privacy by Design Principles
Privacy Impact Assessment Tool
Procedure for Privacy Notice
Procedure for Obtaining Valid
Consent
Procedure for Subject Access
Request
Procedure for Data Breach
notification & handling
Procedure for handling Data
Subject Rights
Inter Company Agreement
Stage Internal Audit & Conducting PIMS internal audit 10-15 Days
3 MRM Conducting PIMS management
review meeting
Assistance during certification
body audit
Closure of reported findings
Stage ISO 27701 Stage 1 Audit 10-15 Days
4 Certification Closure of Observation of Stage 1
Audit Stage 2 Audit
Closure of Observation of Stage 2
Audit
GDPR Implementation Roadmap
Phases Purpose Timeline
To create a project plan to implement GDP
Preparing GDPR To conduct a readiness assessment to find
project. out what tasks you need to perform.
2 Days
To create an internal Data Protection Policy
Defining for personal data.
Personal Data To create other top-level policies as
Policy and other needed – e.g., the Data Retention Policy.
top-level To create awareness among employees
documents. about key GDPR requirements.
To make a decision with regard to the 10 Days
assignment of a Data Protection Officer,
and make sure the decision is
documented.
To appoint a Data Protection Officer and
communicate their name to the
Supervisory Authority.
To implement data subject rights through
Creating an establishing a legal basis for processing.
inventory of Getting data subjects consent and request 10 Days
processing access.
activities. Generating and Keeping records of data
subject rights requests.
Conducting a DPIA on organizations
Data Protection information systems or a product. 2 Days
Impact
Assessment
(DPIA).
Analyse what personal data is being
Secure personal transferred outside of your company, and
data transfers. when.
Taking necessary legal and security 8 Days
measures to adequately protect personal
data when personal data is transferred
outside of the company.
Amending third-party contracts that
Amending third- include processing of personal data to 5 Days
party contracts. become compliant with the GDPR.
Implement the necessary organisational
Implementing and technical measures to protect the 15-20
security personal data of data subjects. Days
provisions of
personal and
sensitive data.
Setting up the processes to identify and
Implementation handle personal data breaches.
of controls to Preparing process of notifications to the 10 Days
handle data Supervisory Authority and data subjects, if
breaches. required, in the case of a personal data
breach.