Directory Image
This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.

ISO/IEC 27701 and Difference between Data Controller and Data Processor

Author: Dacey Lyle
by Dacey Lyle
Posted: Jun 04, 2022

The International Organization for Standardization is a nongovernmental organization made up of national standards bodies that grows and allocates a wide range of proprietary, industrial, and commercial standards. In August 2019, ISO published ISO/IEC 27701:2019, a new international privacy standard about protecting and managing the processing of personal data. This ISO 27701 standard is a privacy extension to the existing and widespread industry, which were first published by ISO in 2005. They define how to establish and run an Information Security Management System. Audited ISO certifications are awarded to organizations that have been measured by an independent, external auditor to meet a specific, published standard. Auditors are also qualified themselves with the ISO 27000 series of certifications, to published ISO standards. ISO 27701 Internal auditor training will provide training with certification so it can easily perform an internal audit of any privacy information management system in accordance with ISO/IEC 27701:2019 requirements.

The popularity of the terms data controller and data processor has suddenly increased in recent years. In part because of the significant rise of data breach scandals from tech giants, and in part because of the unprecedented media attention given to the enactment of data privacy regimes, nowadays every organization who possesses any type of personal data is should be afraid with data privacy management. Now information is the most valuable asset, as the means of identifying and targeting audiences, and at a time when access to information is unprecedented both in massiveness and comfort, the response from cybersecurity international experts has been also impartially substantial. Part of these efforts is also the newly published ISO/IEC 27701, which is an international standard delivering guidelines for the implementation, maintenance and constant improvement of a Privacy Information Management System.

What is Data Controller?

There are multiple national and federal regulations and laws that signify and define the term Data Controller. During the 90s a handful of developed countries established and implemented data protection regulations as a response to the global scale that the internet was taking. But the regulation that really popularized the term "data controller" was the GDPR. As a legal requirement to define the scopes and limits of Data Controllers. controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, controls the purposes and means of the processing of personal data.

The data controller is the thing that could be a person or organization or a number of them – that decides on the how and why the data is collected. The GDPR considers the data controller as the primary party responsible for the most significant aspects of personal data. The data collector responsibilities are the management of:

  • The collection of the data subject’s consent.
  • Revoke requests from data subjects.
  • The availability of the information from the data subjects based on the right to information.
  • The approval and unequivocal statement of the reason of the collection of the data.

The data controller is almost in all cases held responsible for data breaches or unauthorized access and nonconformity.

What is Data Processor?

processor means a legal person, public authority, agency or other body which processes personal data on behalf of the supervisor. In assessment to previous data privacy regulations and laws, the GDPR extended the responsibilities of data processors and enlarged the number of dimensions where they are to be held accountable.

Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing necessary guarantees to implement appropriate technical and organizational events in such a manner that processing will meet the requirements of this Regulation and confirm the protection of the rights of the data subject. What this means is that, mentioning to the point made above about the collector being the principal responsible party, the controller must choose a processor which is fully obedient with the GDPR. The only way that processors can demonstrate their compliance with the GDPR is complete independent third-party audits, assessments and certification. It is also very significant to mention that the third party itself should be accredited.

What is the Difference Between Data Controller and Data Processor?

The difference between the controller and the processor is straight forward: the former collects the information and delivers the reason and means for it, and the latter is a service provider to the controller, because it processes the data on the controller’s behalf.
About the Author

Dacey Lyle has published so many articles regarding ISO Certification Documentation. As ISO Consultant profession since last many years Dacey has rich experience in preparing such certification documents within ISO guideline to her global clients to

Rate this Article
Leave a Comment
Author Thumbnail
I Agree:
Comment 
Pictures
  • Guest  -  3 months ago

    에그벳슬롯 나는 ... 정말 Fang Jifan의 종파에서 숭배하고 싶습니까?

  • Guest  -  3 months ago

    머니 트레인2 수많은 사람들이 갑판으로 달려갔고 Yang Jian은 이미 울고 있었습니다.

  • Guest  -  3 months ago

    온라인 슬롯 머신 게임 이 말을 들은 왕웬유는 재빨리 절하며 "폐하께서는 현명하십니다."

  • Guest  -  3 months ago

    스포츠 토토 배트맨 이것은 전적으로 그들 자신의 문화 전통에서 비롯된 것입니다.

  • Guest  -  4 months ago

    마종 웨이즈 그러나 현재의 공포는 사실 절망의 숨결을 드러낸다.

  • Guest  -  4 months ago

    잘 터지는 슬롯 Jiao Fang은 그녀의 손을 눌렀습니다. "좋아요, 험담은 그만하세요. 앞으로는 외부인과 이야기해서는 안됩니다."

  • Guest  -  4 months ago

    슈가 러쉬 Baoding은 특히 도로가 건설되었으므로 Xishan에서 멀지 않습니다.

  • Guest  -  4 months ago

    toto 사이트 두 달이 넘는 가뭄은 이미 사람들을 성급하게 만들었다.

  • Guest  -  4 months ago

    슬롯 용가리 Fang Jifan은 계속해서 인내심을 갖고 미소를 지으며 말했습니다. "그래서 당신을 여기에 초대했습니다."

  • Guest  -  4 months ago

    EGGC Zhang Yanling은 몸을 떨었고 갑자기 느꼈습니다.

  • Guest  -  4 months ago

    프라그마틱 슬롯 무료 밑바닥에 있는 사람들은 탈출구가 없고 일단 필사적이라면 반격해야 합니다.

  • Guest  -  4 months ago

    미스터 슬롯 한편 Jin Zhengxing은 걱정스럽게 Xishan으로 호출되었습니다.

  • Guest  -  4 months ago

    토토 사잍 Liu Jin은 Fang Jifan의 명령을 듣 자마자 오를 내뱉고 채찍을 들어 올렸습니다.

  • Guest  -  4 months ago

    슬롯 무료 게임 그는 차창 밖을 내다보며 명령했습니다. "가서 Xiao Jing에게 현을 떠나라고 전하십시오."

  • Guest  -  4 months ago

    스포츠 토토 배트맨 모범으로 가르치신 스승님, 그러한 관용과 관대함은 모든 사람이 마음에 기억하기에 충분합니다.

  • Guest  -  4 months ago

    에그벳300 무슨 악행을 저질러 그런 아들을 낳았느냐.

  • Guest  -  4 months ago

    슬롯 쿠폰 결국 모든 사람들은 내시를 지키는 일을 알고 있습니다.

  • Guest  -  4 months ago

    하이브 슬롯 "아..." 양핑은 의아해했다. "이게 무슨 뜻이야?"

  • Guest  -  4 months ago

    포츈 래빗 사람이 가진 희망이 있는 만큼 실망도 있을 것입니다.

  • Guest  -  4 months ago

    토토 벳 빚을 갚기 위해 이 녀석은 광기까지 갔다.

Author: Dacey Lyle

Dacey Lyle

Member since: Dec 08, 2015
Published articles: 45

Related Articles