ISO 27701 to DPDP Act mapping:
what the privacy standard covers, and what it leaves.
Every ISO/IEC 27701 control and DPDP Act section in the TryTrustable control library that is evidenced by the same control, and the DPDP duties with no ISO counterpart.
Last updated Published by TryTrustableNot legal advice
How does ISO 27701 map to the DPDP Act?
In the TryTrustable control library, 5 shared controls are tested against both ISO/IEC 27701 and DPDP Act. Those controls reach 12 of the 16 ISO/IEC 27701 requirements the library models and 12 of the 15 DPDP Act requirements. Each row below is one control and the requirements on each side it is evidence for.
Requirements on each side are mapped to the controls that evidence them, and paired only through a shared control. The ISO side uses the ISO/IEC 27701:2019 clause numbers; the DPDP side is the Act from section 4 to section 17. The ISO 27701 guide explains the 2025 edition.
| Shared control | ISO/IEC 27701 | DPDP Act |
|---|---|---|
| Consent lifecycle managementCTL-CONSENT-MGMT | 7.2.2 Identify lawful basis 7.2.3 Determine when and how consent is obtained | §4 Personal data processed only for lawful purpose with consent or legitimate use §6 Consent free, specific, informed, unconditional and unambiguous; easy withdrawal §9 Verifiable parental consent for children; no tracking or targeted ads to children |
| Data protection impact assessmentCTL-DPIA | 7.2.5 Privacy impact assessments | §10 Significant Data Fiduciary obligations: DPO in India, audits, periodic DPIA |
| Data subject rights fulfilmentCTL-DSAR | 7.3.6 Access, correction and/or erasure 7.3.9 Providing copy of PII processed | §8(7) Erasure of personal data when purpose is served or consent withdrawn §11 Right to access summary of personal data and processing activities §12 Right to correction, completion, updating and erasure of personal data §13 Right to grievance redressal within prescribed time §14 Right to nominate another individual to exercise rights |
| Privacy notice and transparencyCTL-PRIVACY-NOTICE | 7.2.1 Identify and document purpose for processing PII 7.3.1 Determining and fulfilling obligations to PII principals 7.3.2 Information for PII principals 8.2.2 Organization purposes | §5 Notice given to data principal before or at the time of requesting consent §8(9)-(10) Grievance redressal mechanism and contact of designated officer published §13 Right to grievance redressal within prescribed time |
| Vendor due diligence and monitoringCTL-VENDOR-DD | 7.5.1 Identify basis for PII transfer between jurisdictions 8.2.1 Customer agreement (processor) 8.5.1 Basis for PII transfer (processor) | §16 Cross-border transfer of personal data only to non-restricted countries |
Generated from the TryTrustable control library. Requirement descriptions are the library's own short wording of what the control is tested against, not the text of the standard or law. A mapping we could not stand behind on review is left out until it is corrected in the library.
25 rows: one per control and requirement, with the library description. Paste into a spreadsheet.
Which controls does only one side ask for?
A requirement can be reached through a general control and still need a specific one. These controls are mapped to requirements on one side only, so evidence for them does nothing for the other framework.
Only ISO/IEC 27701:
None.
Only DPDP Act:
- Periodic logical access review CTL-ACCESS-REVIEW: §8(5)
- Breach notification to Board and subjects CTL-BREACH-NOTIFY: §8(6)
- Verifiable parental consent for children CTL-CHILD-CONSENT: §9
- Lawful basis and consent capture CTL-CONSENT: §6
- Demonstrable consent and notice CTL-CONSENT-PROOF: §5, §6
- Data retention and disposal CTL-DATA-RETENTION: §8(7), §12
- Encryption of data at rest CTL-ENCRYPT-REST: §8(5)
- Encryption of data in transit CTL-ENCRYPT-TRANSIT: §8(5)
- Incident response plan and exercise CTL-IR-PLAN: §8(6)
- Centralised, tamper-evident logging CTL-LOGGING: §8(5)
- Multi-factor authentication enforced CTL-MFA: §8(5)
- Data Principal nomination CTL-NOMINATION: §14
- Policy review and attestation CTL-POLICY-REVIEW: §4, §10, §17
- Processors engaged under valid contract CTL-PROCESSOR-CONTRACT: §16
- Lawful basis for every purpose CTL-PURPOSE-BASIS: §4, §17
- Rights requests answered within time CTL-RIGHTS-SLA: §8(9)-(10), §11, §13
- Significant Data Fiduciary assurance CTL-SDF-AUDIT: §10
- Withdrawal propagated to processors CTL-WITHDRAW-RELAY: §6, §8(7)
- Cross-border transfer control CTL-XBORDER: §16
Why the DPDP side has so many gaps
ISO/IEC 27701 was written to fit many privacy laws, so it names duties in general terms: identify a lawful basis, determine when consent is needed, provide a copy of the PII. The DPDP Act is specific. It requires proof of the notice shown with each consent, withdrawal passed on to every processor, a ban on tracking children, notification of every breach to the Board, and nomination. Those are separate controls in the library, and none of them has an ISO/IEC 27701 clause mapped to it, which is why the list of controls only the DPDP side asks for is long.
The practical reading: ISO/IEC 27701 gives you the management system, and the DPDP controls have to be added inside it. The DPDP guide sets out each duty, the penalty schedule what each costs, and the DPDP to GDPR mapping shows the same pattern against the GDPR.
The things people ask us
Does ISO 27701 certification mean DPDP compliance?
No. ISO/IEC 27701 certifies a privacy information management system; the DPDP Act imposes specific legal duties. The shared rows show real overlap in purpose, lawful basis, consent, rights and transfers, but DPDP duties such as nomination, verifiable parental consent, breach notification to the Board and the Significant Data Fiduciary regime have no ISO/IEC 27701 control mapped to them.
Which edition of ISO 27701 does this mapping use?
The clause references are to ISO/IEC 27701:2019, the extension to ISO 27001, which the library still uses. ISO/IEC 27701:2025 is a standalone, certifiable management system standard with its own numbering, and 2019 certificates transition to it by October 2028. The control subjects carry over; the numbers do not.
Why are only 16 ISO 27701 requirements shown?
The library models 18 ISO/IEC 27701:2019 controller and processor controls, chosen for their overlap with privacy law; it is a subset, not the whole standard. Two are left off this page because their clause numbers are wrong in the library, and 4 individual mappings are withheld because the control does not evidence the clause. They return when corrected.
Is ISO 27701 useful for an Indian company under DPDP?
It can be. It gives a certifiable structure for the governance the Act assumes: records of processing, purpose and basis, rights handling and processor contracts. It does not answer the Act's specific duties, and the Act does not recognise certification as a defence, so treat it as the management system around your DPDP controls, not a substitute for them.
Can I download this mapping?
Use Copy as CSV below the table. It copies one line per control and requirement with the library's description, ready to paste into a spreadsheet. The mapping is generated from the control library the product uses, so it changes when the library does.
Put DPDP controls inside your privacy management system.
Thirty minutes. We show ISO/IEC 27701 and DPDP requirements answered from one control set, and the DPDP-only controls that sit alongside.