Volg ICTI

Free 27001 – GDPR templates

This is our ‘secret’ free template page. If you found this page, you can use these ISO 27001, GDPR and AI governance templates. Also available on our GitHub repository!

About these templates

The templates on this page are made by the people of ICT Institute. We use these templates in our training sessions and our advisory work. We decided to make our templates available to anyone with hardly any restrictions. They are provided under the Creative Commons license Attribution license. You can do the following with the templates:

  • Share. You can share the templates and any documents made with these templates freely, with any one that you want to share it with.
  • Adapt. You can make new documents based on the templates, make changes, add elements or delete elements as much as you want. You can even do this in commercial organisations of for commercial purposes.

Note that the use of these templates is of course at your own risk. We made an effort to include all required items in the template, but when we use these templates we change them to fit the intended use. Note also that the ISO 27001 norm is copyright protected. You must buy a copy of the norm before you can use it.

Note that we also offer 27001 and GDPR templates in Dutch on page Nederlandse templates AVG en 27001.

Latest updates

YouTube

See the templates in action on our YouTube channel with practical videos on ISO 27001, privacy compliance and cybersecurity, focused on real-world applications.

Vanta

We joined the Vanta partner program to combine hands-on ISMS support with a compliance platform that speeds up your compliance journey.

Notion

Check our Notion ISMS templates on the marketplace and set up a core ISO 27001 risk management process in a practical, collaborative workspace.

GDPR templates

AI & AI Act templates

  • AI policy template – A comprehensive AI policy template that outlines principles and rules for acceptable use of AI systems, including AI Act compliance, approved AI services, training and awareness requirements.
  • FRIA assessment template – A Fundamental Rights Impact Assessment (FRIA) template to identify, assess, and document potential impacts of AI systems on fundamental rights in line with AI Act requirements. Read more about the FRIA.
  • ISO 42001 audit report template – Example internal audit report template for an AI Management System (AIMS) under ISO/IEC 42001, including audit methodology/process, documents/evidence, and control explanations. Read more about how to use it and risk management with AI.

Information security templates

Other resources

Image credit: @rawpixel via Unsplash