What is ISO/IEC 27701?
ISO/IEC 27701 specifies requirements and guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS). The 2019 edition was designed as an extension of ISO/IEC 27001 and ISO/IEC 27002: an organisation takes its working Information Security Management System and adds the personal data protection dimension — from risk assessment that considers harm to individuals, through lawful bases for processing, to fulfilling data subject rights.
In October 2025 a new edition, ISO/IEC 27701:2025, was published — a standalone standard based on the harmonised management system structure (Annex SL) that can be certified independently of ISO/IEC 27001. Certificates issued against the 2019 edition have a transition period until October 2028. In practice most certifications today are still based on the 2019 edition as an extension of an ISO 27001 certificate, and that is the structure the Guardiso module reflects.
Who is it for?
The standard is voluntary and can be implemented by any organisation processing personal data — regardless of size, industry or jurisdiction. The most common adopters are companies for which trust in personal data processing is a business prerequisite: SaaS and cloud service providers, technology companies handling their customers’ customer data, the financial and healthcare sectors, shared service centres, and organisations processing large volumes of employee and consumer data.
A distinguishing feature of ISO/IEC 27701 is the role-based split of requirements: Annex A of the 2019 edition contains controls for PII controllers, and Annex B for PII processors. An organisation applies the annex (or both) matching its actual role in each processing activity. Certification against the 2019 edition requires an existing or simultaneously implemented ISO/IEC 27001 — the PIMS does not exist separately from the ISMS.
Structure of the requirements
The 2019 edition consists of four main blocks of requirements and guidance. Clause 5 extends the ISO/IEC 27001 management system requirements (context, leadership, planning, support, operation, evaluation and improvement) with the privacy dimension — including the obligation to consider harm to data subjects in risk assessment. Clause 6 extends the ISO/IEC 27002 security controls with guidance specific to personal data protection.
Annex A defines control objectives and controls for PII controllers: identifying the purpose and lawful basis of processing, consent management, data protection impact assessments (DPIA), the record of processing activities, privacy notices, fulfilment of data subject rights, minimisation, retention and transfer control. Annex B defines controls for PII processors: processing only on the customer’s documented instructions, supporting the controller, breach notification, return or deletion of data at the end of the service, a disclosure register, and oversight of sub-processors.
ISO 27701 and the GDPR
ISO/IEC 27701 does not replace the GDPR and is not a formal certification mechanism under Article 42 GDPR — the certificate is not legal proof of compliance with the regulation. It is, however, one of the strongest available accountability tools (Article 5(2) and Article 24 GDPR): an independent, annually verified privacy management system makes it much easier to demonstrate that controller or processor obligations are met systematically rather than ad hoc.
The standard was designed with the GDPR in mind — its requirements correspond to the regulation’s key obligations: lawful bases (Article 6), consent (Article 7), information duties (Articles 13-14), data subject rights (Articles 15-22), the record of processing activities (Article 30), security of processing (Article 32), breach notification (Articles 33-34), DPIAs (Article 35), processing agreements (Article 28) and transfers (Chapter V). Annex D of the 2019 edition contains an official mapping table to GDPR articles, and Guardiso reflects these relationships in its control cross-mapping.
What does certification look like?
The ISO/IEC 27701 certificate is issued by an accredited certification body — under the 2019 edition always in conjunction with ISO/IEC 27001 certification (as an extension of an existing certificate or a combined audit of both standards). The audit has two stages: Stage 1 reviews the PIMS documentation (scope, controller/processor roles, record of processing activities, DPIAs, policies), and Stage 2 verifies implementation through sampling — the auditor will trace, for example, the handling of real data subject requests, consent records and breach handling.
The certification cycle is three years, with annual surveillance audits and recertification before the end of the cycle — synchronised with the ISO 27001 cycle. Organisations planning certification should account for the transition to the 2025 edition: new certifications against the 2019 edition will be phased out, and existing certificates must transition by October 2028.
What are the benefits?
Implementing a PIMS consolidates personal data protection into one managed system instead of scattered "GDPR paperwork", and delivers tangible business benefits.
- Independently verified proof of GDPR accountability — a strong argument with corporate customers, supervisory authorities and in due diligence questionnaires.
- Shorter data processing agreement negotiations: a certified PIMS answers most customer questions about data protection at a processor.
- One coherent set of documentation instead of duplication: risk assessment, incidents, suppliers and training shared between information security and privacy.
- Lower risk of breaches and fines through a systematic approach to minimisation, retention and individual rights — instead of reacting only after a complaint or inspection.
- A competitive edge in tenders and sales to regulated sectors where data protection is a supplier selection criterion.
How does Guardiso help?
Guardiso guides you through the ISO/IEC 27701 implementation as a natural extension of the work already done for ISO 27001 and GDPR — without duplicating documentation.
- The full set of 70 PIMS controls (clauses 5-6, Annex A for controllers, Annex B for processors) seeded automatically when you enable the standard — with descriptions, statuses and owners.
- Cross-mapping to ISO 27001 and GDPR: work done in the ISMS and GDPR modules automatically counts towards overlapping PIMS requirements, and gaps are clearly visible.
- Privacy registers in one place: the record of processing activities, DPIAs, consents, data subject requests and breaches — linked to controls and evidence.
- Data protection policies and procedures generated from templates and tailored to the controller or processor role.
- Compliance evidence collection (training records, access reviews, breach procedure tests) with recurring tasks and automation.
- An auditor portal with controlled access to the PIMS documentation — no files emailed around.
