Mapping · ISO 27701 ↔ DPDP Act

ISO 27701 to DPDP Act mapping:
what the privacy standard covers, and what it leaves.

Every ISO/IEC 27701 control and DPDP Act section in the TryTrustable control library that is evidenced by the same control, and the DPDP duties with no ISO counterpart.

5 shared controlsISO/IEC 27701: 12/16 reachedDPDP Act: 12/15 reachedCopy as CSV

Last updated Published by TryTrustableNot legal advice

01

How does ISO 27701 map to the DPDP Act?

In the TryTrustable control library, 5 shared controls are tested against both ISO/IEC 27701 and DPDP Act. Those controls reach 12 of the 16 ISO/IEC 27701 requirements the library models and 12 of the 15 DPDP Act requirements. Each row below is one control and the requirements on each side it is evidence for.

Requirements on each side are mapped to the controls that evidence them, and paired only through a shared control. The ISO side uses the ISO/IEC 27701:2019 clause numbers; the DPDP side is the Act from section 4 to section 17. The ISO 27701 guide explains the 2025 edition.

Shared controlISO/IEC 27701DPDP Act
Consent lifecycle managementCTL-CONSENT-MGMT
7.2.2 Identify lawful basis
7.2.3 Determine when and how consent is obtained
§4 Personal data processed only for lawful purpose with consent or legitimate use
§6 Consent free, specific, informed, unconditional and unambiguous; easy withdrawal
§9 Verifiable parental consent for children; no tracking or targeted ads to children
Data protection impact assessmentCTL-DPIA
7.2.5 Privacy impact assessments
§10 Significant Data Fiduciary obligations: DPO in India, audits, periodic DPIA
Data subject rights fulfilmentCTL-DSAR
7.3.6 Access, correction and/or erasure
7.3.9 Providing copy of PII processed
§8(7) Erasure of personal data when purpose is served or consent withdrawn
§11 Right to access summary of personal data and processing activities
§12 Right to correction, completion, updating and erasure of personal data
§13 Right to grievance redressal within prescribed time
§14 Right to nominate another individual to exercise rights
Privacy notice and transparencyCTL-PRIVACY-NOTICE
7.2.1 Identify and document purpose for processing PII
7.3.1 Determining and fulfilling obligations to PII principals
7.3.2 Information for PII principals
8.2.2 Organization purposes
§5 Notice given to data principal before or at the time of requesting consent
§8(9)-(10) Grievance redressal mechanism and contact of designated officer published
§13 Right to grievance redressal within prescribed time
Vendor due diligence and monitoringCTL-VENDOR-DD
7.5.1 Identify basis for PII transfer between jurisdictions
8.2.1 Customer agreement (processor)
8.5.1 Basis for PII transfer (processor)
§16 Cross-border transfer of personal data only to non-restricted countries

Generated from the TryTrustable control library. Requirement descriptions are the library's own short wording of what the control is tested against, not the text of the standard or law. A mapping we could not stand behind on review is left out until it is corrected in the library.

25 rows: one per control and requirement, with the library description. Paste into a spreadsheet.

02

Which ISO/IEC 27701 requirements have no shared control with DPDP Act?

These ISO/IEC 27701 requirements are modelled in the library but share no control with any DPDP Act requirement. They are the work that DPDP Act does not cover for you, or places where the library has not linked them yet.

  • 7.2.8 Records related to processing PII
  • 7.4.1 Limit collection
  • 7.4.5 PII de-identification and deletion
  • 8.4.2 Return, transfer or disposal of PII

And the DPDP Act requirements with no shared control on the ISO/IEC 27701 side:

  • §8(5) Reasonable security safeguards to prevent personal data breach
  • §8(6) Intimation of personal data breach to the Board and affected data principals
  • §17 Exemptions applied narrowly and documented (research, enforcement, startups)
03

Which controls does only one side ask for?

A requirement can be reached through a general control and still need a specific one. These controls are mapped to requirements on one side only, so evidence for them does nothing for the other framework.

Only ISO/IEC 27701:

None.

Only DPDP Act:

  • Periodic logical access review CTL-ACCESS-REVIEW: §8(5)
  • Breach notification to Board and subjects CTL-BREACH-NOTIFY: §8(6)
  • Verifiable parental consent for children CTL-CHILD-CONSENT: §9
  • Lawful basis and consent capture CTL-CONSENT: §6
  • Demonstrable consent and notice CTL-CONSENT-PROOF: §5, §6
  • Data retention and disposal CTL-DATA-RETENTION: §8(7), §12
  • Encryption of data at rest CTL-ENCRYPT-REST: §8(5)
  • Encryption of data in transit CTL-ENCRYPT-TRANSIT: §8(5)
  • Incident response plan and exercise CTL-IR-PLAN: §8(6)
  • Centralised, tamper-evident logging CTL-LOGGING: §8(5)
  • Multi-factor authentication enforced CTL-MFA: §8(5)
  • Data Principal nomination CTL-NOMINATION: §14
  • Policy review and attestation CTL-POLICY-REVIEW: §4, §10, §17
  • Processors engaged under valid contract CTL-PROCESSOR-CONTRACT: §16
  • Lawful basis for every purpose CTL-PURPOSE-BASIS: §4, §17
  • Rights requests answered within time CTL-RIGHTS-SLA: §8(9)-(10), §11, §13
  • Significant Data Fiduciary assurance CTL-SDF-AUDIT: §10
  • Withdrawal propagated to processors CTL-WITHDRAW-RELAY: §6, §8(7)
  • Cross-border transfer control CTL-XBORDER: §16
04

Why the DPDP side has so many gaps

ISO/IEC 27701 was written to fit many privacy laws, so it names duties in general terms: identify a lawful basis, determine when consent is needed, provide a copy of the PII. The DPDP Act is specific. It requires proof of the notice shown with each consent, withdrawal passed on to every processor, a ban on tracking children, notification of every breach to the Board, and nomination. Those are separate controls in the library, and none of them has an ISO/IEC 27701 clause mapped to it, which is why the list of controls only the DPDP side asks for is long.

The practical reading: ISO/IEC 27701 gives you the management system, and the DPDP controls have to be added inside it. The DPDP guide sets out each duty, the penalty schedule what each costs, and the DPDP to GDPR mapping shows the same pattern against the GDPR.

Questions

The things people ask us

Does ISO 27701 certification mean DPDP compliance?

No. ISO/IEC 27701 certifies a privacy information management system; the DPDP Act imposes specific legal duties. The shared rows show real overlap in purpose, lawful basis, consent, rights and transfers, but DPDP duties such as nomination, verifiable parental consent, breach notification to the Board and the Significant Data Fiduciary regime have no ISO/IEC 27701 control mapped to them.

Which edition of ISO 27701 does this mapping use?

The clause references are to ISO/IEC 27701:2019, the extension to ISO 27001, which the library still uses. ISO/IEC 27701:2025 is a standalone, certifiable management system standard with its own numbering, and 2019 certificates transition to it by October 2028. The control subjects carry over; the numbers do not.

Why are only 16 ISO 27701 requirements shown?

The library models 18 ISO/IEC 27701:2019 controller and processor controls, chosen for their overlap with privacy law; it is a subset, not the whole standard. Two are left off this page because their clause numbers are wrong in the library, and 4 individual mappings are withheld because the control does not evidence the clause. They return when corrected.

Is ISO 27701 useful for an Indian company under DPDP?

It can be. It gives a certifiable structure for the governance the Act assumes: records of processing, purpose and basis, rights handling and processor contracts. It does not answer the Act's specific duties, and the Act does not recognise certification as a defence, so treat it as the management system around your DPDP controls, not a substitute for them.

Can I download this mapping?

Use Copy as CSV below the table. It copies one line per control and requirement with the library's description, ready to paste into a spreadsheet. The mapping is generated from the control library the product uses, so it changes when the library does.

Book a walkthrough

Put DPDP controls inside your privacy management system.

Thirty minutes. We show ISO/IEC 27701 and DPDP requirements answered from one control set, and the DPDP-only controls that sit alongside.