What it covers
ISO 27701 brings privacy into the management system approach: identifying the personal data processed, assessing privacy risks, defining roles as controller or processor, and applying controls for each role. Controller controls cover lawful basis, consent, transparency, data subject rights and privacy by design. Processor controls cover acting on the customer's instructions, use of sub processors, international transfers and returning or deleting data at the end of a contract.
The 2025 edition
The 2019 version was an extension of ISO 27001, so certification required both. ISO 27701:2025, published in October 2025, became a standalone standard. It keeps the same structure as other ISO management systems, so it still integrates easily with ISO 27001 and ISO 42001. Companies certified to the 2019 version have a transition period.
ISO 27701 and the GDPR
The standard is not a law and certification does not prove GDPR compliance on its own, but its controls map closely to GDPR obligations such as records of processing, data processing agreements, breach handling and data subject rights. It gives auditors and customers structured evidence of how privacy is managed.
Who uses it
Mostly service providers that process personal data for their customers, such as SaaS companies, payroll and HR providers and outsourcing firms, because it answers a large part of the privacy questions in supplier assessments.




