AegentraNew Zealand

Govern / New Zealand

ISO 27701 privacy management

Aegentra supports privacy information management system implementation for New Zealand organisations. We connect data flows, controller and processor responsibilities, risk decisions and operational evidence with the scope of your privacy programme.

On this page

Start with the boundary

Define the work that is needed.

For privacy and security teams needing an organised PIMS, including organisations coordinating privacy work with an existing ISMS.

  • PIMS boundary, information flows and processing roles
  • Privacy responsibilities and risk-assessment arrangements
  • Supplier, access and retention governance
  • Evidence, review and improvement processes

Keep the responsibilities distinct

ISO/IEC 27701:2025 is a standalone PIMS standard. Implementation is separate from a legal determination under the New Zealand Privacy Act and does not guarantee certification or regulator acceptance.

What the engagement can produce

Useful outputs, agreed in advance.

  • A scoped PIMS roadmap
  • Responsibilities and information-flow priorities
  • A control and evidence action plan
  • Integration points with existing management systems

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How we work

From evidence to a practical next step.

Agree

Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.

Examine

Gather the records and context required by the scope. Distinguish what evidence supports from what is still uncertain.

Act or report

Carry out the agreed consulting, audit, assessment or implementation task. Obtain approval before operational changes.

Verify and hand over

Document outcomes, limitations, owners and follow-up. Retesting or ongoing work is included only when expressly scoped.

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

An illustrative starting point

What a useful first decision looks like.

Fictional example to explain the service, not a New Zealand client case study or a promised outcome.

Different teams use the same customer dataset for service delivery and analytics. A privacy programme needs to distinguish the purposes and access arrangements before deciding which policy wording to use.

Questions for the first discussion

  • What personal information is processed and for which purposes?
  • Where are the data and suppliers located?
  • Which existing privacy and security processes should the PIMS incorporate?

Before you begin

Your questions, answered.

Can privacy management be integrated with our ISMS?

Yes. Shared governance, risk and improvement processes can be coordinated where appropriate. Privacy-specific roles and processing responsibilities still need their own treatment. We first agree the applicable standard edition and how the scopes relate.

What can be included in iso 27701 privacy management?

The agreed scope can include pIMS boundary, information flows and processing roles; privacy responsibilities and risk-assessment arrangements; supplier, access and retention governance; evidence, review and improvement processes. We confirm the exact deliverables and exclusions before work begins, rather than treating every organisation as the same project.

How much does this service cost?

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How do you deliver the work in New Zealand?

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

What should we provide before a proposal?

Bring answers to these starting questions: What personal information is processed and for which purposes? Where are the data and suppliers located? Which existing privacy and security processes should the PIMS incorporate? A short initial discussion should establish the boundary and next evidence needed. Do not email secrets or detailed personal records before secure handling has been agreed.

Reference points

Check the underlying guidance.

Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.

Discuss your requirement

Start with your business.

Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.