GlossaryCompliance operations

ISO 27701

Short answer

ISO 27701 is the international standard for a privacy information management system (PIMS). It sets out how an organisation manages personal data responsibly, as a controller or a processor, and since its 2025 edition it can be certified on its own, without first holding ISO 27001.

What it covers

ISO 27701 brings privacy into the management system approach: identifying the personal data processed, assessing privacy risks, defining roles as controller or processor, and applying controls for each role. Controller controls cover lawful basis, consent, transparency, data subject rights and privacy by design. Processor controls cover acting on the customer's instructions, use of sub processors, international transfers and returning or deleting data at the end of a contract.

The 2025 edition

The 2019 version was an extension of ISO 27001, so certification required both. ISO 27701:2025, published in October 2025, became a standalone standard. It keeps the same structure as other ISO management systems, so it still integrates easily with ISO 27001 and ISO 42001. Companies certified to the 2019 version have a transition period.

ISO 27701 and the GDPR

The standard is not a law and certification does not prove GDPR compliance on its own, but its controls map closely to GDPR obligations such as records of processing, data processing agreements, breach handling and data subject rights. It gives auditors and customers structured evidence of how privacy is managed.

Who uses it

Mostly service providers that process personal data for their customers, such as SaaS companies, payroll and HR providers and outsourcing firms, because it answers a large part of the privacy questions in supplier assessments.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub