Regulated Customer Contract Checker
Regimes · ISO 27701

ISO/IEC 27701:2025, your own certification as a processor

Reaches every agreement whose row names personal data, when the certification is yours: the customer agreement (A.2.2.2), return, transfer or disposal at the end (A.2.4.3), the basis for transfers (A.2.5.2), subcontractor disclosure, engagement and change (A.2.5.7 to A.2.5.9), supplier agreements (A.3.10), breach response and its time limits (A.3.12) and confidentiality (A.3.18).

On the register, tick "ISO/IEC 27701:2025 (yours)" (every regime is ticked by default) and these rows attach where the customer's sector and country reach it. Source framework: ISO/IEC 27701:2025.

What it expects, term by term

processor termsA.2.2.2Where the row names personal data the supplier handles
subcontractorsA.2.5.7 · A.2.5.8 · A.2.5.9Where the supplier handles personal data
exit and return of dataA.2.4.3On an ICT service arrangement, or where processor terms are expected
security scheduleA.3.10On an ICT service arrangement
audit rightA.3.10On an ICT service arrangement, or where processor terms are expected
breach clockA.3.12Where the row names personal data, or on an ICT service arrangement
transfer termsA.2.5.2Where personal data leaves the EEA and the United Kingdom for the supplier's home
confidentialityA.3.18On a confidentiality agreement

The clauses, quoted

9

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.

ISO 27701 A.2.2.2 Customer agreement

Where relevant, the contract to process personal data must address the organization's role in assisting the customer with the customer's own obligations, taking account of the nature of processing and the information available to it, covering as relevant privacy by design and by default, achieving security of processing, notifying breaches to a supervisory authority and to customers and individuals, conducting privacy impact assessments, and assuring assistance where prior consultation with a protection authority is needed, with some jurisdictions also requiring the contract to state the subject matter and duration of processing, its nature and purpose, the type of data and the categories of individuals.

Evidence an auditor accepts: Customer contracts carrying the assistance provisions relevant to the engagement; Where the jurisdiction requires it, contract terms stating subject matter, duration, nature, purpose, data types and categories of individuals; Operational capability behind each assistance commitment, not the commitment alone
Where it usually falls short: Assistance promised in contract with no operational capability behind it, discovered only when the customer first asks
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.4.3 Return, transfer or disposal of PII

The organization must provide the ability to return, transfer or dispose of personal data securely and must make its policy available to the customer, managing the capability securely whether the outcome is return to the customer, transfer to another organization or controller, deletion, destruction, de-identification or archiving, providing the assurance the customer needs that data processed under the contract is erased by the organization and its subcontractors from wherever it is stored including backup and business continuity copies as soon as it is no longer necessary for the customer's identified purposes, and covering in the policy the retention period before disposal after contract termination so the customer is protected from losing data through an accidental lapse.

Evidence an auditor accepts: Documented return, transfer and disposal policy, made available to customers; Assurance evidence that erasure reaches backups, continuity copies and subcontractors; Stated post termination retention period before disposal, with its rationale
Where it usually falls short: Erasure certified for primary systems while backups retain the data for the full backup cycle, which the customer is not told
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.2 Basis for PII transfer between jurisdictions

The organization must inform the customer in a timely manner of the basis for transfers of personal data between jurisdictions and of any intended changes, so the customer can object or terminate, documenting compliance with the legislation and regulation that applies depending on origin and destination, informing the customer of transfers to suppliers, other parties and other countries or international organizations, giving advance notice of changes within an agreed timeframe, setting the limits of any contractual allowance to make changes without informing the customer, and identifying the instruments relied on for international transfer together with the countries involved and the circumstances in which they apply.

Evidence an auditor accepts: Documented transfer basis per route, disclosed to the customer; Notification records for changes, with the agreed advance timeframe; Contract terms setting the limits of any change made without notification
Where it usually falls short: Change notification given after the change took effect, removing the ability to object
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.7 Disclosure of subcontractors used to process PII

The organization must disclose to the customer any use of subcontractors to process personal data before that use, with provisions included in the customer contract, disclosing that subcontracting is used and the names of the relevant subcontractors, the countries and international organizations to which they can transfer data, and the means by which they are obliged to meet or exceed the organization's own obligations, and where public disclosure of subcontractor information would increase security risk beyond acceptable limits, making the disclosure under a non disclosure agreement or on request while making the customer aware the information is available, the list of countries always being disclosed so the customer can inform the individuals concerned.

Evidence an auditor accepts: Current subcontractor list with names, the countries they can transfer to, and how their obligations are secured; Evidence of disclosure before use, not after; Contract provisions covering subcontractor disclosure
Where it usually falls short: Subcontractors disclosed only on request, with customers never told the information exists
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.8 Engagement of a subcontractor to process PII

The organization must engage a subcontractor to process personal data only according to the customer contract, obtaining written authorization from the customer before the subcontractor processes the data, whether through appropriate clauses in the customer contract or a specific one off agreement, holding a written contract with every such subcontractor that addresses implementation of the appropriate processor controls, requiring the subcontractor to implement them in light of the risk assessment and the scope of processing, with all such controls assumed relevant by default and any exclusion justified, responsibilities being allocable differently provided every control is considered and documented.

Evidence an auditor accepts: Written customer authorization for each subcontractor, whether general or specific; Written contract with every subcontractor carrying the processor control obligations; Justification for any processor control not required of a subcontractor
Where it usually falls short: Subcontractor engaged on the strength of a general authorization that does not in fact cover it
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.9 Change of subcontractor to process PII

Where it holds a general written authorization, the organization must inform the customer of any intended change involving the addition or replacement of a subcontractor that processes personal data, giving the customer the opportunity to object, and where it changes the subcontractor carrying out some or all of the processing, written authorization from the customer is required before the new subcontractor processes the data, whether through appropriate clauses in the customer contract or a specific one off agreement.

Evidence an auditor accepts: Change notification procedure with the notice period and the objection route; Records of notifications given and objections received, with outcomes; Evidence that new subcontractors did not begin processing before authorization
Where it usually falls short: Notification given at the point of change or after, so the objection right is theoretical
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.3.10 Addressing information security within supplier agreements

Agreements with suppliers shall specify whether PII is processed and the minimum technical and organizational measures the supplier must meet for the organization to meet its information security and PII protection obligations, shall clearly allocate responsibilities between the organization, its partners, suppliers and applicable third parties taking account of the type of PII processed, shall provide a mechanism for ensuring the organization supports and manages compliance with applicable legislation and regulation, and shall call for independently audited compliance acceptable to the customer. When the organization is a PII processor, its contracts with suppliers shall specify that PII is processed only on its instructions.

Evidence an auditor accepts: Supplier agreements stating whether PII is processed and the minimum measures required; Responsibility allocation clauses by type of PII; Audit or assurance clause and the independent evidence obtained under it
Where it usually falls short: Supplier contracts silent on PII while the supplier processes it
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.3.12 Response to information security incidents

For a PII controller, an incident that involves PII shall trigger a review to determine whether a breach involving PII requiring a response has occurred, an event alone not necessarily triggering it; when a breach has occurred the response shall include the relevant notifications and records, jurisdictions defining when the supervisory authority and PII principals must be notified, and a record with sufficient information for regulatory or forensic reporting shall be kept covering the incident, the period, the consequences, the reporter, to whom it was reported, the resolution steps and data recovered, whether it caused unavailability, loss, disclosure or alteration of PII, the PII compromised, and the notifications made. For a PII processor, the contract with the customer shall cover breach notification, how the organization will provide the information the customer needs to notify authorities, the exclusion of breaches caused by the customer or PII principal or within components they are responsible for, and the expected and externally mandated limits on notification response times; some jurisdictions require the processor to notify the controller without undue delay and some require direct notification of a regulatory authority.

Evidence an auditor accepts: Breach determination records for incidents involving PII; Breach register carrying every field the standard names; Notifications made to authorities, PII principals or customers with timing against the legal limit
Where it usually falls short: Incidents closed as security events with no PII breach determination
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.3.18 Confidentiality or non-disclosure agreements

Individuals operating under the organization's control with access to PII shall be subject to a confidentiality obligation, the agreement, whether part of a contract or separate, specifying the length of time the obligation lasts; when the organization is a PII processor, the confidentiality agreement in whatever form between the organization, its employees and its agents shall ensure they comply with the policy and procedures on data handling and protection.

Evidence an auditor accepts: Confidentiality clauses or agreements covering everyone with access to PII, with duration stated; Evidence agents and contractors are bound as well as employees; Processor agreements binding staff to the data handling policy
Where it usually falls short: Confidentiality obligation that ends at termination when the PII obligation does not
ISO/IEC 27701:2025 in The Art of Service standards library

See what it expects of your list

Paste the list of customer agreements and every row this regime reaches carries these terms, ticked or open. Eight agreements free, no account.

Check my contract list