What is ISO/IEC 27701?
ISO/IEC 27701 is the international standard for a privacy information management system, PIMS for short. It does not certify that you comply with a particular privacy law. It certifies that you run a working system for protecting personally identifiable information: you know which PII you process and why, on which lawful basis, with which processors and in which countries, you assess the risks to the people behind the data, you answer their requests, you notify breaches, and you audit and improve all of it.
The standard uses its own vocabulary, taken from ISO/IEC 29100. PII is personally identifiable information, the PII principal is the person the data is about, the PII controller decides purposes and means, and the PII processor processes PII on a controller’s behalf. If you know the GDPR, read personal data, data subject, controller and processor.
2019 versus 2025
The first edition, ISO/IEC 27701:2019, was an extension to ISO/IEC 27001 and 27002. You could only certify it on top of an ISO 27001 certificate, and its control numbering still referred to the 2013 edition of ISO 27002. The second edition, ISO/IEC 27701:2025, published in October 2025, rebuilt it as a standalone management system standard with the harmonized clause structure, aligned it with ISO 27001:2022 and ISO 27002:2022, and consolidated the two former control annexes into one Annex A split by role. You can now certify a PIMS on its own, though most organizations still integrate it with their ISMS.