PIMS GRC
A privacy management system workspace on ISO/IEC 27701, with the DPDP Act and Rules and the GDPR articles cross walked to the control set, the processor register, and the DPIA register.
What it does
- Gap assessment against ISO/IEC 27701:2025, the DPDP Act and Rules, and the GDPR, with conformity per control and a roadmap.
- Statement of applicability and control effectiveness, with the framework library and the cross walk between the three.
- Policy and procedure library with the authored Pricoris document set, version control and review dates.
- Evidence register with SHA-256 integrity hashes and an exportable manifest.
- Processor and vendor register: every processor from the RoPA, a questionnaire based assessment, a risk score, the contract and data processing agreement on file, obligations, review dates and alerts, and the propagation acknowledgements from Consent and Rights shown against each processor as evidence.
- DPIA register: the assessments produced in PII Discovery, listed, approved and reviewed here.
- Management review and internal audit records; gap assessment register, report and results deck generated in house style.
How it maps to the standard and the law
| Obligation | Where | What the product does | Status |
|---|---|---|---|
| PIMS controls and the DPDP obligations in one place | ISO/IEC 27701, DPDP Act | Cross walk, SoA, effectiveness, evidence. | In build, October 2026 |
| Processor engagement under a valid contract | Section 8(2), Rule 6 | Processor register with agreements, assessments and alerts. | In build, October 2026 |
| Periodic DPIA and audit for a Significant Data Fiduciary | Section 10(2), Rule 13 | DPIA register and audit records. | In build, October 2026 |
| Document control and evidence integrity | ISO/IEC 27701 clause 7.5 | Hashed evidence and document library. | Built |
Honest limits
PIMS GRC is the newest of the privacy products and its pages carry "in build" dates for that reason. The evidence and document machinery is shared with AISIA and is in production; the processor register and the DPIA register are the pieces being completed.
Bring your last audit report
The demo takes the findings and shows where each one lands in the control set and what evidence closes it.