BS 10012 Personal Information Management Systems (PIMS)
Receive a quote tailored to your needs
What is BS10012?
BS 10012:2017 is the British Standard for Personal Information Management Systems (PIMS). It offers a structured approach for organizations to develop and maintain policies, procedures, and controls covering the collection, storage, use, and deletion of personal data.
Updated in 2017, the standard aligns with the General Data Protection Regulation (GDPR) and is designed to integrate smoothly with ISO 27001 – Information Security Management. This integration allows organizations to embed data protection practices within their broader information security and business continuity management systems
Why Choose Kiwa?
Kiwa is recognized as an independent authority in testing, inspection, and certification, supporting organizations in safeguarding their data, reputation, and stakeholder relationships. With a deep understanding of the connections between privacy, compliance, and security, Kiwa’s experts offer clear, practical guidance throughout the BS 10012 certification process.
This approach ensures that certification delivers tangible improvements to an organization’s management system. Choosing Kiwa means partnering with a trusted expert dedicated to helping organizations enhance compliance, drive performance, and build lasting confidence among stakeholders
Benefits of the Service
Stronger GDPR compliance
Improved risk management
Increased stakeholder trust
Legal and regulatory assurance
Integrated information protection
Resilient business operations
The certification process with Kiwa
Gap Analysis
An initial review is conducted to assess current data protection practices and identify areas for improvement before starting the certification process.
Stage 1 Audit
Documentation, policies, and alignment with GDPR are examined to evaluate the organization’s readiness for certification.
Stage 2 Audit
The effectiveness of the Personal Information Management System is assessed in practice through an on-site evaluation.
Certification Issuance
Following successful assessment, the BS 10012 certificate is issued to confirm compliance.
Surveillance Audits
Regular annual audits are performed to ensure ongoing compliance and the continued effectiveness of the management system.
Recertification Audit
A comprehensive reassessment is carried out every three years to maintain certification and address any regulatory changes.
Why is BS 10012 important to have?
Managing personal data properly is not only a legal requirement but also a question of trust and integrity.
BS 10012 helps you:
- Identify and manage data protection risks
- Strengthen security and compliance measures
- Increase transparency and accountability
- Protect your reputation and build customer confidence
- Prevent data breaches and misuse
BS 10012 and GDPR
The General Data Protection Regulation (GDPR) defines how organisations must protect and process personal data.
BS 10012 provides the management framework to achieve and maintain this compliance, with clear roles for:
Data controllers – deciding how and why personal data is processed
Data processors – managing and protecting data on behalf of controllers
Certification to BS 10012 helps ensure that both roles are fulfilled responsibly and transparently, with systems in place for continual improvement.