This service covers two things that belong together but are not the same. The GDPR is a legal requirement that applies regardless of what the organisation chooses to certify against. ISO/IEC 27701:2025 is a standard that provides structure for systematic privacy governance and makes the work verifiable. The standard can support and document the privacy work. Certification to ISO/IEC 27701 does not, however, automatically guarantee full GDPR compliance. Legal assessments must be made on the basis of the relevant legislation, jurisdiction and the individual processing activity.
Most organisations have done something about privacy. The challenge is that the work often stalled after the first round of records and notices. Processing activities have changed, new systems have been adopted, and nobody can show what applies today.
Who this is for
- Organisations needing a bounded gap assessment of their privacy work.
- Organisations needing a clean-up and expert advice after a period without follow-up.
- Organisations wanting full implementation of a privacy information management system.
- Organisations wanting to become certification-ready for ISO/IEC 27701.
- Organisations acting as processors that must document compliance towards customers.
What Berigo can deliver
- Privacy governance with roles, responsibilities and decision lines, including a data protection officer where relevant.
- Clarification of controller and processor roles, including in complex chains.
- Records of processing that are kept current, not merely created.
- Legal bases, purpose limitation and data minimisation, assessed per processing activity.
- Privacy notices and information to data subjects, written so they can actually be read.
- Procedures for data subject rights, with deadlines and ownership.
- Data processing agreements and follow-up of processors.
- Assessment of international transfers and the basis for them.
- Data protection by design and by default, in projects and procurement.
- Data protection impact assessments and risk assessments.
- Retention and deletion rules, with practical implementation in the systems.
- Handling of personal data breaches, with notification assessment and documentation.
- Supplier management, training, internal control and measurement.
- Internal audit, management review and continual improvement.
- Preparation for certification to ISO/IEC 27701.
How the GDPR and ISO/IEC 27701 relate
The GDPR states what is lawful and what is required. ISO/IEC 27701 states how a privacy information management system can be set up and run, building on an information security management system. The two complement each other: the standard provides structure and documentation, while the regulation provides the requirements to be met. Where a legal assessment is needed, it must be made as a legal assessment rather than replaced by a process diagram.
What you gain
- An overview of your processing activities, with legal basis, purpose and retention period.
- Documentation that can be presented to supervisory authorities, customers and data subjects.
- Procedures that answer data subject requests within the deadlines.
- Control over processors and transfers.
- Privacy work that continues after the project, because it has been built into operations.
TrustAlign in the work
TrustAlign is Berigo's own portal for governance, risk, compliance and audit support. It is used as the working surface through implementation and onwards into operation, so that requirements, work and evidence sit together instead of being scattered across spreadsheets and shared folders.
- Frameworks and requirements, with compliance status per framework.
- Risk register with risk assessment and follow-up of treatment.
- Control register with status, owners and deadlines.
- Statement of Applicability, with justification per control.
- Policies and governance documents.
- Audit programme, audit plans and the running of audits.
- Findings classified as nonconformity, observation or opportunity for improvement, with root cause, corrective action and verified closure.
- Incidents, vulnerabilities, assets and suppliers.
- Evidence and documentation attached to what it belongs to.
- Management review built on the audit programme.
- Reports and exports of risks, controls, findings, incidents, policies, suppliers and vulnerabilities.
- Norwegian and English interface, a separate organisation per client, roles for administrator, manager and viewer, two-factor sign-in and an audit log.
TrustAlign additionally has a dedicated GDPR area covering, among other things, records of processing, data protection impact assessments, data processing agreements and a personal data breach register.
TrustAlign can be used as a standalone portal, and can by agreement and technical clarification be connected to relevant document and data sources. The portal by itself provides neither certification nor regulatory compliance. It structures the work that has to be done, and makes it verifiable.
Who does what
Berigo is an adviser and implementation partner. The certification audit is carried out by an independent certification body that you choose yourselves. We issue no certificates, we do not influence the auditor's judgement, and we do not guarantee a particular outcome. We prepare the organisation as well as we can, and support you through the audit and the work that follows.